OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Modified: CTI STIX SC Monthly Meeting


Event Title: CTI STIX SC Monthly Meeting

Date: Wednesday, 21 October 2015, 04:00pm to 05:00pm EDT
Description

Pushed out by 2 hours to the time that was discussed as the best compromise for our members around the globe.

 

.........................................................................................................................................

Join online meeting

https://meet.mitre.org/sbarnum/72KC25YB

 

Join by Phone

+1 (781) 271-2020 

+1 (703) 983-2020 

Find a local number

 

Conference ID: 5034705

 

Forgot your dial-in PIN? First online meeting?

.........................................................................................................................................

 


This meeting counts towards voter eligibility.

Agenda

Agenda:

  • STIX 1.2.1 specs
    • Status and Next Steps
  • STIX 2.0 kickoff
    • Initial administrative steps
    • Begin deliberative process (get stuff done)
      • Setting the stage and navigating the road
        • Use cases
        • Issues
      • Some decisions to make
        • “voting” approach for issues
        • how to start “getting stuff done” as soon as possible
  • Example of Opinion Contribution for an Issue (Aharon Chernin: Sightings)

Minutes

Cyber Threat Intelligence (CTI) Technical Committee (TC) STIX Subcommittee (SC)

Meeting Minutes

October 21, 2015

4:00-5:00PM EDT

 

Agenda

 

Agenda:

  • STIX 1.2.1 specs
    • Status and Next Steps
  • STIX 2.0 kickoff
    • Initial administrative steps
    • Begin deliberative process (get stuff done)
      • Setting the stage and navigating the road
        • Use cases
        • Issues
      • Some decisions to make
        • “voting” approach for issues
        • how to start “getting stuff done” as soon as possible
  • Example of Opinion Contribution for an Issue (Aharon Chernin: Sightings)

 

 

Notes

  • On the “nominating editors” slide, Pat wanted to nominate Sean as the “modeling” perspective
    • Sean said we should send those suggestions to the list
  • On the same slide, John Anderson (Soltra) wondered what Sean meant by something representing an “implementation” perspective…a particular focus (Java, etc) in mind?
    • Sean explained that it just meant somebody building the tools (vendors, etc)
    • John A. then suggested bringing up a user perspective, separate from modeler or implementor
  • On the use cases slide, someone (unsure who) noted that the link on the Github page was wrong. I didn’t follow which page exactly.
  • Discussion on how to support “voting” to decide what to talk about
    • Aharon suggested that it might be a TC issue
      • Sean said they were approaching it first so should find something that works, then maybe bring it broader
    • John Wunder suggested that the co-chairs could propose some topics and see if anybody objects
    • Pat wanted to make sure we maintained some kind of issue tracker
    • Bret suggested Stack Exchange
    • Sean suggested moving the discussion to the list
  • Trey developed a tool to survey usage of STIX/CybOX (works against a TAXII server)
    • Pat had some raw STIX files that he couldn’t get a TAXII server to accept, asked if Trey could get it to work against that
    • He could, asked Pat to send e-mail / file an issue
  • Aharon went through his opinion discussion of the sightings use case
    • John commented that it would be good to show how it would be used
    • Aharon said that might be in the use case
  • Question about using references/TAXII for sightings, I didn’t really follow.
    • Mark answered that TAXII SC was looking into it

 

 

Calls to Action

  • Members: nominate editors on the list for STIX v2.0 work product
  • Members: Review use cases on STIXProject/use-cases github wiki (add missing use cases and flesh out existing ones)
  • Members: Review issue trackers (identify new issues, comment on existing issues, consider prioritization)
  • Members: Offer thoughts on the list for technology approach for issue “voting”
  • Members: Offer thoughts on the list for initial issues to tackle
    • Candidates
      • Sightings
      • Relationships
      • ID format
      • Abstracting constructs (identity, victim, source and asset)
      • In-line vs referencing of content
      • Data Markings
      • Other suggestions?


Owner: Mr. Sean Barnum
Group: CTI STIX Subcommittee
Sharing: This event is shared with the OASIS Open (General Membership), and General Public groups. Public Event Link

Microsoft Outlook users: You will see event notifications requiring further action in your Outlook mail application.
Non-Outlook users: We still recommend subscribing to a Group or organization-wide calendar to keep your calendar updated.

  • Learn more about subscribing here.
  • View the updated Group web calendar here.

Referenced Items
OASIS CTI STIX SC Meeting - Oct 21 2015.ppt (3MB) 2015-10-22 Download | View Details

Attachment: ical_40852.ics
Description: application/ics

BEGIN:VCALENDAR
CALSCALE:GREGORIAN
METHOD:REQUEST
VERSION:2.0
PRODID:-//Kavi Corporation//NONSGML Kavi Groups//EN
X-MS-OLK-FORCEINSPECTOROPEN:TRUE
BEGIN:VTIMEZONE
TZID:America/New_York
BEGIN:STANDARD
DTSTART:20001029T020000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T060000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T020000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T020000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T070000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T020000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
STATUS:CONFIRMED
TRANSP:OPAQUE
DTSTAMP:20151022T154648Z
DTSTART;VALUE=DATE-TIME;TZID=America/New_York:20151021T160000
DTEND;VALUE=DATE-TIME;TZID=America/New_York:20151021T170000
SEQUENCE:6
SUMMARY:CTI STIX SC Monthly Meeting
LAST-MODIFIED:20151022T154648Z
ORGANIZER:workgroup_mailer@lists.oasis-open.org
DESCRIPTION:Pushed out by 2 hours to the time that was discussed as the 
 best compromise for our members around the globe.\n\n \n\n..
 ............................................................
 ............................................................
 ...............\n\nhttps://meet.mitre.org/sbarnum/72KC25YB\n
 \nhttps://meet.mitre.org/sbarnum/72KC25YB\n\n \n\nJoin by Ph
 one\n\n+1 (781) 271-2020 \n\n+1 (703) 983-2020 \n\nhttps://d
 ialin.mitre.org/\n\n \n\nConference ID: 5034705\n\n \n\nhttp
 s://dialin.mitre.org/| http://r.office.microsoft.com/r/rlidO
 C10?clid=1033&p1=4&p2=1041&pc=oc&ver=4&subver=0&bld=7185&bld
 ver=0\n\n...................................................
 ............................................................
 ..........................\n\n \n\nAgenda: Agenda:\n\n\n	STI
 X 1.2.1 specs\n	\n		Status and Next Steps\n	\n	\n	STIX 2.0 k
 ickoff\n	\n		Initial administrative steps\n		Begin deliberat
 ive process (get stuff done)\n		\n			Setting the stage and n
 avigating the road\n			\n				Use cases\n				Issues\n			\n			
 \n			Some decisions to make\n			\n				&ldquo\;voting&rdquo\;
  approach for issues\n				how to start &ldquo\;getting stuff
  done&rdquo\; as soon as possible\n			\n			\n		\n		\n	\n	\n	
 Example of Opinion Contribution for an Issue (Aharon Chernin
 : Sightings)\n\nGroup: CTI STIX Subcommittee\nCreator: Mr. S
 ean Barnum
URL:https://www.oasis-open.org/apps/org/workgroup/cti-stix/event.php?event_id=40852
UID:https://www.oasis-open.org/apps/org/workgroup/cti-stix/event.php?event_id=40852
BEGIN:VALARM
ACTION:DISPLAY
DESCRIPTION:REMINDER
TRIGGER;RELATED=START:-PT00H15M00S
END:VALARM
END:VEVENT
END:VCALENDAR


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]