OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-stix] Proposal to establish Sightings (#306) and Relationships (#291) as our official issue topics under active consideration for STIX v2.0


In general, if you design anything with the requirement to scale large, then said system can easily scale down. But the inverse is rarely true.

Lets take this back to root principles.. the debate seems to be around what a sighting is:

a) Is it an edge between an indicator and an observer; or

b) Is it a vertex itself, with an edge each between indicator and to observer


-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for "Wunder, John A." ---2015/11/03 12:01:46 PM---Is that true in all scenarios? Sure, a lot of commodity"Wunder, John A." ---2015/11/03 12:01:46 PM---Is that true in all scenarios? Sure, a lot of commodity indicators will probably have zillions of hi

From: "Wunder, John A." <jwunder@mitre.org>
To: Jason Keirstead/CanEast/IBM@IBMCA
Cc: "Barnum, Sean D." <sbarnum@mitre.org>, Jerome Athias <athiasjerome@gmail.com>, "Jordan, Bret" <bret.jordan@bluecoat.com>, "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>, "Taylor, Marlon" <Marlon.Taylor@hq.dhs.gov>, "Davidson II, Mark S" <mdavidson@mitre.org>, Terry MacDonald <terry@soltra.com>
Date: 2015/11/03 12:01 PM
Subject: Re: [cti-stix] Proposal to establish Sightings (#306) and Relationships (#291) as our official issue topics under active consideration for STIX v2.0





Is that true in all scenarios? Sure, a lot of commodity indicators will probably have zillions of hits. But what about targeted indicators of APT activity that we want to carefully track?

I feel like we’re designing for this one scenario of a ton of sightings when in practice the more valuable activity might be less volume and more specificity. (Not to say we don’t care about the volume use case, just that it’s not the only one).

John





[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]