OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-stix] STIX 2.1 discussion


Presuming licensing issues, if any, could be worked out,  can we provide direct support for the flexible MISP Machine Tags (Triple Tags)?

https://github.com/MISP/misp-taxonomies

I know we've discussed this before, but it's still not clear what the impediments are to subsuming this flexible JSON format and the growing library of community shared taxonomies.

Patrick Maroney
President
Integrated Networking Technologies, Inc.
Desk: (856)983-0001
Cell: (609)841-5104
Email: pmaroney@specere.org

_____________________________
From: Jason Keirstead <jason.keirstead@ca.ibm.com>
Sent: Monday, August 29, 2016 2:30 PM
Subject: RE: [cti-stix] STIX 2.1 discussion
To: Masuoka, Ryusuke <masuoka.ryusuke@jp.fujitsu.com>
Cc: <cti-stix@lists.oasis-open.org>, JG on CTI-TC <jg@ctin.us>


Myself - I would prefer confidence be a numeric code of say 1-100 with an allowed value that maps to "unknown" (perhaps 0 or -1), and leave it up to individual implementers if they want to map that to the admiralty code in their software or not.

A numeric code has this large advantage, that it can be easily adapted to match any labelling regime, and any level of granularity.

Whereas, if the Admiralty code is adopted, we are "stuck" there - and that regime may be too granular for some organizations, and not granular enough for others.

-
Jason Keirstead
STSM, Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for "Masuoka, Ryusuke" ---08/22/2016 09:41:11 PM---Hi, Jane, It seems it is already published in 2014"Masuoka, Ryusuke" ---08/22/2016 09:41:11 PM---Hi, Jane, It seems it is already published in 2014

From: "Masuoka, Ryusuke" <masuoka.ryusuke@jp.fujitsu.com>
To: JG on CTI-TC <jg@ctin.us>, "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>
Date: 08/22/2016 09:41 PM
Subject: RE: [cti-stix] STIX 2.1 discussion
Sent by: <cti-stix@lists.oasis-open.org>





Hi, Jane,

It seems it is already published in 2014

Why Assessing Estimative Accuracy Is Feasible and Desirable
https://www.hks.harvard.edu/fs/rzeckhau/Assessing%20Estimative%20Accuracy.pdf

Regards,

Ryu

From: cti-stix@lists.oasis-open.org [mailto:cti-stix@lists.oasis-open.org] On Behalf Of JG on CTI-TC
Sent:
Tuesday, August 23, 2016 8:00 AM
To:
cti-stix@lists.oasis-open.org
Subject:
Re: [cti-stix] STIX 2.1 discussion

All:

I just wanted to point out this forthcoming article that will be published in Intelligence and National Security that discusses the Admiralty Code.

https://www.hks.harvard.edu/fs/rzeckhau/Evaluating%20Estimative%20Accuracy.pdf

Jane Ginn

On 8/22/2016 12:15 PM, Jordan, Bret wrote:



--
Jane Ginn, MSIA, MRP
CTI-TC Co-Secretary
Cyber Threat Intelligence Network, Inc.
jg@ctin.us




GIF image



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]