OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-users] RE: [cti-stix] [cti-users] MTI Binding


I think you're making a big assumption that most systems used to share CTI will be internet facing and/or publicly accessible, which isn't true.

The odds that CTI System A (originator of STIX Name space "CompanyA.com") can communicate directly with CTI System B (originator of STIX Name space "CompanyB.com") are actually quite low.

This is why the data has to be copied, otherwise there is no way at all to build a knowledge graph.

-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for "Bush, Jonathan" ---2015/10/05 02:48:22 PM---The use-case I had in mind was that instead of tools tra"Bush, Jonathan" ---2015/10/05 02:48:22 PM---The use-case I had in mind was that instead of tools transporting data around the internet, copying

From: "Bush, Jonathan" <jbush@dtcc.com>
To: "'Jordan, Bret'" <bret.jordan@bluecoat.com>
Cc: "Sean D. Barnum" <sbarnum@mitre.org>, Jane Ginn <jane.ginn@gmail.com>, "Wunder, John A." <jwunder@mitre.org>, "cti-users@lists.oasis-open.org" <cti-users@lists.oasis-open.org>, "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>
Date: 2015/10/05 02:48 PM
Subject: [cti-users] RE: [cti-stix] [cti-users] MTI Binding
Sent by: <cti-users@lists.oasis-open.org>





The use-case I had in mind was that instead of tools transporting data around the internet, copying it from one place to another, we could just have the data link to other referenced data that exists somewhere else in the CTI “ecosystem”. Why move all that data around when I can just point to it? And… if that leads me to a place that then points to other data locations, before long I will have a “net” of data that I can use to perform complex analytical analysis to answer questions that would otherwise be very difficult.
(I suppose I’m defining the semantic web here)

… at least that was where my head was at with it.

From: cti-stix@lists.oasis-open.org [mailto:cti-stix@lists.oasis-open.org] On Behalf Of Jordan, Bret
Sent:
Monday, October 05, 2015 1:42 PM
To:
Bush, Jonathan
Cc:
Sean D. Barnum; Jane Ginn; Wunder, John A.; cti-users@lists.oasis-open.org; cti-stix@lists.oasis-open.org
Subject:
Re: [cti-stix] [cti-users] MTI Binding

I have been reading a lot about JSON-LD, and I get how and why it might be interesting in a website context when you are sharing unknown data back and forth. Meaning there is no standard for the data you are sharing. Think user profile between Google, Twitter, Facebook etc. But, unless I am mistaken, the purpose of STIX is to define a standard for CTI so that we all share the same data.

Can someone explain why JSON-LD is needed in the CTI context. I just do not see why anyone that is building an application to use CTI would care since all of the data that will be shared between them is KNOWN and in a standard well known form, aka STIX... Please help me understand this use case.


Thanks,

Bret



Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO
Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."


DTCC DISCLAIMER: This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error, please notify us immediately and delete the email and any attachments from your system. The recipient should check this email and any attachments for the presence of viruses. The company accepts no liability for any damage caused by any virus transmitted by this email.




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]