[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: Re: [cti-stix] Labels on STIX TLOs
+1
Providing a generic tag mechanism would allow for a given organization to annotate intelligence specific to their operational workflows and have that context/metadata transmitted via STIX. As a tool developer, being able to consume/maintain that context as an opaque value allows my tool to remain relevant within that operational environment without having to know about it a priori.
$0.02
Ted Bedwell
Principal Engineer
Network Threat Defense
.:|:.:|:. CISCO .:|:.:|:.
From:
cti-stix@lists.oasis-open.org <cti-stix@lists.oasis-open.org> on behalf of Jason Keirstead <Jason.Keirstead@ca.ibm.com>
Sent: Thursday, June 30, 2016 8:57 AM To: Terry MacDonald Cc: John A. Wunder; cti-stix@lists.oasis-open.org Subject: Re: [cti-stix] Labels on STIX TLOs Myself, I would prefer that "tag" or "labels" be added to the base TLO Common Properties instead of having special properties for many TLOs but for some other TLOs we do not have any label / tag method. I don't like the labels field myself. I would prefer the addition of a genetic tag TLO. The community does prefer the labels field however, and so... I would make the label field optional, and leave it applied just to the objects we can make a case for. I would worry about using it everywhere, as that will restrict us in the future if we decide to make it more specific to each object. Having
one list across all objects would worry me that we are restricting our choices later on. Cheers On 30/06/2016 01:24, "Wunder, John A." <jwunder@mitre.org> wrote:
One of the topics that came up across several items on the call yesterday was the “labels” field that currently exists on Indicator, Malware, and Tool. The field is an array of values from an open vocabulary (indicator-label-ov, malware-label-ov, and tool-label-ov respectively).
We have a couple of open questions:
1. Should the labels field be required or optional?
b. Allan also suggested that if we don’t add it across all top-level objects, it should be added to Campaign. Are there other TLOs that we should add it to, even if we don’t add it across all of them? To be honest I don’t really have a strong opinion either way. What do you think?
John |
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]