OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-stix] Proposal to establish Sightings (#306) and Relationships (#291) as our official issue topics under active consideration for STIX v2.0


That is kind of the point - there is no way to go back to these automated systems and ask for more info - they don't have it... they have no systems of record to store it in. This will be true of all kinds of security devices:


* Most endpoints have a system of record of IOCs up on a management console somewhere, but not always

All of these device classes could reasonably directly produce observables and sightings, but none of them have systems of record that can make use of IDs for querying.

-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for "Wunder, John A." ---2015/10/30 03:10:28 PM---But in those cases wouldn’t the consumers want some wa"Wunder, John A." ---2015/10/30 03:10:28 PM---But in those cases wouldn’t the consumers want some way to go back to the producers and ask for more

From: "Wunder, John A." <jwunder@mitre.org>
To: "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>
Date: 2015/10/30 03:10 PM
Subject: Re: [cti-stix] Proposal to establish Sightings (#306) and Relationships (#291) as our official issue topics under active consideration for STIX v2.0
Sent by: <cti-stix@lists.oasis-open.org>




But in those cases wouldn’t the consumers want some way to go back to the producers and ask for more info? Or, when they do, do you think they would just go back with the entire sighting rather than an ID?

It just seems like we have this standard ID mechanism on most things and we should have a very good reason to not follow that pattern here.





[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]