OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-stix] Proposal - Top Level Relationship Object


JSON object structures are by their nature extensible. Anyone could add other fields to their marking object at will... this would not break any software parsing the data who did not know or care about those markings being present.

-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for "Wunder, John A." ---2015/07/30 04:58:45 PM---I hate to be a downer but I have to point out that this"Wunder, John A." ---2015/07/30 04:58:45 PM---I hate to be a downer but I have to point out that this probably won't work for U.S. government mark

From: "Wunder, John A." <jwunder@mitre.org>
To: "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>
Date: 2015/07/30 04:58 PM
Subject: Re: [cti-stix] Proposal - Top Level Relationship Object
Sent by: <cti-stix@lists.oasis-open.org>





I hate to be a downer but I have to point out that this probably won't work for U.S. government markings, which are much more complex. Whether that's a show-stopper for the TC I don't know. OTOH USG could internally do something more complicated by replacing the "marking" string with an actual object, it just wouldn't work outside of that enclave.

Some industry groups are also working on more complicated marking structures (FIRST, for example). Might be smart to future-proof by supporting structured markings ahead of time, or just wait until they have something usable before doing that.

I'm kind of ambivalent, simpler is always better but I worry that strings are *too* simple.

John

From: <cti-stix@lists.oasis-open.org> on behalf of "Jordan, Bret"
Date:
Thursday, July 30, 2015 at 3:47 PM
To:
Aharon Chernin
Cc:
"cti-stix@lists.oasis-open.org"
Subject:
Re: [cti-stix] Proposal - Top Level Relationship Object

Perfect, I agree a simple string would be good.... Do we need to provide a helper for those things that are not TLP? Something like:

{
ID: "12312312321312",
MarkingType: "TLP",
Marking: "Amber",
etc
}


Thanks,

Bret



Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO
Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."





[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]