OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: malware and tool


I support this direction.

 

Sarah Kelley

Senior CERT Analyst

Center for Internet Security (CIS)

Integrated Intelligence Center (IIC)

Multi-State Information Sharing and Analysis Center (MS-ISAC)

1-866-787-4722 (7×24 SOC)

Email: cert@cisecurity.org

www.cisecurity.org

Follow us @CISecurity

 

From: cti-stix@lists.oasis-open.org [mailto:cti-stix@lists.oasis-open.org] On Behalf Of Jordan, Bret
Sent: Wednesday, June 15, 2016 9:56 AM
To: cti-stix@lists.oasis-open.org
Subject: [cti-stix] malware and tool

 

All,

 

We had a discussion today on Slack and I think most of us came to agreement on the following design... I will let everyone voice their own support for it...

 

1) We will have a TLO called "malware" and one called "tool (final word smithed name TBD)".  

 

2) A tool can be related to an incident, campaign, Intrusion Set, threat actor, etc with a relationship object.  This relationship object will have verbs like "used-maliciously" etc.

 

3) There will be no flag or categorization on the actual TLO to say it was used maliciously.  The reason for that is a tool is only used maliciously, at a certain time, by a certain person, in a certain way.  RDP / VNC are good examples of this.  

 

4) Malware will also have relationships to the various places that make sense.  

 

5) The tool TLO will have optional fields / properties to allow it to be used for all the uses cases people need. 

 

If you support this or don't support this, please speak up so we can start closing out this issue and moving on. 

 

 

Bret

 

 


...

This message and attachments may contain confidential information. If it appears that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify the sender immediately and permanently delete the message and any attachments.
. . .


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]