OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-taxii message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [cti-taxii] TAXII Use Cases


(and others) have made substantive comments on these topics on the legacy list. As far as inclusion in the ongoing CTI TC/SCs dialogue do we need to resubmit these to the list? 

Or will all of that prior discourse be captured and included in any drafts we put forward?  

Is anyone the CTI TC SCs capturing the current discourse in the GitHub issue tracking list as requested by the MITRE Team in the past?

This question goes out to all of the subcommittees.

Sent from my iPhone using Mail+ for Outlook

From: Ron Williams
Sent: 7/23/15, 2:00 PM
To: Jason Keirstead
Cc: Terry MacDonald, Davidson II, Mark S, Jordan, Bret, cti-taxii@lists.oasis-open.org
Subject: Re: [cti-taxii] TAXII Use Cases

One challenge with +/- on observables is context. A 'known' bad IP for retail may be irrelevant to finance, because the reason it's 'bad' retail targeted malware source, whatever.

+/- on observables (industry targeted malware site, regional campaign, etc. ) may be useful if provided in the context of industry/geography, etc - but by itself?

Cheers!

~r

+1.720.349.2236

"It is much less dangerous to think like a man of action, than to act like a man of thought."
- Nicholas Nassim Taleb


Inactive hide details for Jason Keirstead---07/22/2015 11:42:37---Do you forsee the +/- existing at the Indicator/Observable leJason Keirstead---07/22/2015 11:42:37---Do you forsee the +/- existing at the Indicator/Observable level, or at the CybOX marking level? IE

From: Jason Keirstead/CanEast/IBM
To: Terry MacDonald <terry.macdonald@threatloop.com>
Cc: "Davidson II, Mark S" <Ron.Williams@us.ibm.com>
Date: 07/22/2015 11:42
Subject: Re: [cti-taxii] TAXII Use Cases




Do you forsee the +/- existing at the Indicator/Observable level, or at the CybOX marking level?

IE can I disagree with only part of an indicator? Or do I have to disagree with the whole thing?
-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown



Inactive hide details for Terry MacDonald ---2015/07/21 <a href=''>08:33:22</a> PM---I'd like to add some additional entries to Mark's Use CasTerry MacDonald ---2015/07/21 08:33:22 PM---I'd like to add some additional entries to Mark's Use Cases list: - Sending only the part of an obje

From: Terry MacDonald <terry.macdonald@threatloop.com>
To: Jason Keirstead/CanEast/IBM@IBMCA
Cc: "Davidson II, Mark S" <Ron.Williams@us.ibm.com>
Date: 2015/07/21 08:33 PM
Subject: Re: [cti-taxii] TAXII Use Cases
Sent by: <cti-taxii@lists.oasis-open.org>




I'd like to add some additional entries to Mark's Use Cases list:

- Sending only the part of an object that has changed (increased efficiency)
- Sending just an agreement or disagreement with another organisation's assertion of a relationship (i.e. [+1] or [-1])
- Sending just an agreement or disagreement with another organisation's data in an object i.e. [+1] or [-1])

Cheers

Terry MacDonald
| STIX, TAXII, CybOX Consultant

M: +61-407-203-026
E: terry.macdonald@threatloop.com
W: www.threatloop.com



Disclaimer: The opinions expressed within this email do not represent the sentiment of any other party except my own. My views do not necessarily reflect those of my employers.

On Jason.Keirstead@ca.ibm.com> wrote:




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]