OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-stix] Proposal - Top Level Relationship Object


What is the use case where someone is asserting something with no information behind it though? I am kind of lost on that. Why would it be being asserted?

-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for Terry MacDonald ---2015/07/29 06:03:11 PM---I think there is a difference: 0 confidence = I have checTerry MacDonald ---2015/07/29 06:03:11 PM---I think there is a difference: 0 confidence = I have checked this information and I do not have any

From: Terry MacDonald <terry.macdonald@threatloop.com>
To: Jason Keirstead/CanEast/IBM@IBMCA
Cc: "Wunder, John A." <jwunder@mitre.org>, Aharon Chernin <achernin@soltra.com>, "Baker, Jon" <bakerj@mitre.org>, "Jordan, Bret" <bret.jordan@bluecoat.com>, "Chris O'Brien" <COBrien@cert.gov.uk>, "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>, JG on CTI-TC <jg@ctin.us>
Date: 2015/07/29 06:03 PM
Subject: Re: [cti-stix] Proposal - Top Level Relationship Object
Sent by: <cti-stix@lists.oasis-open.org>





I think there is a difference:

0 confidence = I have checked this information and I do not have any faith that it is true.
Unknown = There is no information to say if this is true or not true. We have no way to infer anything at present.

---

I'd also say that there is the potential here for using something like the Admiralty code as a replacement for confidence.....https://en.wikipedia.org/wiki/Admiralty_code:

Reliability of Source
A - Completely reliable

B - Usually reliable
C - Fairly reliable
D - Not usually reliable
E - Unreliable
F - Reliability cannot be judged

Accuracy of data (Credibility)
1 - Confirmed by other sources

2 - Probably True
3 - Possibly True
4 - Doubtful
5 - Improbable
6 - Truth cannot be judged

Maybe that makes sense more so than Confidence?

---

I also believe that we need to keep each relationship as a single direction relationship, to enable someone to discern a 'hierarchy' from the relationships they receive, rather than just a 'group' (as highlighted by others on the thread). If we combine all the relationships into a pool, we lose the ability of separating those relationships back out. I would like to keep the Source_ID and Target_ID separation. 

Cheers

Terry MacDonald
| STIX, TAXII, CybOX Consultant

M: +61-407-203-026
E: terry.macdonald@threatloop.com
W: www.threatloop.com



Disclaimer: The opinions expressed within this email do not represent the sentiment of any other party except my own. My views do not necessarily reflect those of my employers.

On 30 July 2015 at 05:25, Jason Keirstead <Jason.Keirstead@ca.ibm.com> wrote:




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]