OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-taxii message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [cti-taxii] Question about multiple trust group support


+1 on the entire below message, this is also how I saw things working (federation vs. single silo)

Also, I would say, if there is a use case where a single trust group wants to use many TAXII servers - then they can federate their logins and groups totally outside TAXII if they choose, via LDAP or any other such system. It is really no different than for example, multiple mail servers in an organization or multiple <any other type of server> - the group management and permission management is synchronized outside the core protocol (usually using LDAP or a derivative like AD)

-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for "Davidson II, Mark S" ---2015/09/30 10:30:48 AM---Terry, thank you for the message – great points. I"Davidson II, Mark S" ---2015/09/30 10:30:48 AM---Terry, thank you for the message – great points. I’d like to hone in on what I see a key topic: a tr

From: "Davidson II, Mark S" <mdavidson@mitre.org>
To: Terry MacDonald <terry.macdonald@threatloop.com>, Jason Keirstead/CanEast/IBM@IBMCA
Cc: "Jordan, Bret" <bret.jordan@bluecoat.com>, "Thompson, Dean" <Dean.Thompson@anz.com>, "cti-taxii@lists.oasis-open.org" <cti-taxii@lists.oasis-open.org>
Date: 2015/09/30 10:30 AM
Subject: RE: [cti-taxii] Question about multiple trust group support
Sent by: <cti-taxii@lists.oasis-open.org>





Terry, thank you for the message – great points.

I’d like to hone in on what I see a key topic: a trust group using multiple TAXII servers (or not).

My view of the world has been that each Trust Group would exist on only one TAXII Server (e.g., EX-ISAO uses https://exisao.example.com/taxii/ as it’s API Base). A single trust group spread across multiple servers (e.g., indicators channel is on example.com; logs channel is on mitre.org; but they are the same trust group) seems like it would be fairly complicated to define and implement, and I don’t have a clear understanding of the benefit.

Instead of spreading a Trust Group across TAXII Servers, I’ve envisioned the interaction between trust groups to be something like federation, where a worker from trust group A pushes info to trust group B (regardless of whether they live on the same server or not).

For the sake of taking a side primarily to spur discussion: Is there a scenario that requires a trust group spread across multiple TAXII Servers?

For what it’s worth, I see scalability and locality as implementation specific aspects of a TAXII Server (I call this out specifically so it can be challenged). A high quality TAXII Server would be robust enough to support lots of messages / connections, and ideally would have locally available servers (e.g., if you are in US, you connect to a US server; if you are in EU, connect to an EU server; message passing happens through engineering wizardry in the backend).

Thank you.
-Mark



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]