OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-taxii message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-taxii] Questioning the wisdom of using DNS SRV records for TAXII 2.0 Discovery


However, the problem with the current marking mechanisms is just as you allude to.. "Those who do not honor the data marking/handling conventions...". Relying on "convention" for implementation of a specification is a dangerous course to be on, and it is my biggest gripe against the current TLP data marking. In my opinion, TLP is so ill-defined as to the implications of each level (what defines "organization"?), that it is near useless. The only way TLP can ever make sense is "by convention" within a small group of actors who can all agree on something. This isn't how to formulate a global standard that needs to work among a diverse set of actors. That's why I strongly advocate for a better more robust mechanism for marking in STIX 2.0 and to throw away the ever-confusing TLP.

-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for Patrick Maroney ---2015/10/31 02:46:56 AM---Re: "I guess this is one of my pet peeves with data makinPatrick Maroney ---2015/10/31 02:46:56 AM---Re: "I guess this is one of my pet peeves with data making / data handling. Most of the groups that

From: Patrick Maroney <Pmaroney@Specere.org>
To: "Jordan, Bret" <bret.jordan@bluecoat.com>
Cc: Terry MacDonald <terry@soltra.com>, Trey Darley <trey@soltra.com>, "cti-taxii@lists.oasis-open.org" <cti-taxii@lists.oasis-open.org>
Date: 2015/10/31 02:46 AM
Subject: Re: [cti-taxii] Questioning the wisdom of using DNS SRV records for TAXII 2.0 Discovery
Sent by: <cti-taxii@lists.oasis-open.org>





Re: "I guess this is one of my pet peeves with data making / data handling. Most of the groups that really need this are not going to share with people outside of their group"

Actually it's just the opposite, the more advanced groups are much more likely to share high value actionable intelligence (at least tactical) once we have solid data marking/handling constructs. We know the value of early detection/prevention and criticality of broadly sharing ephemeral IOCs ASAP.

Those who do not honor the data marking/handling conventions in any trust based community will eventually be exposed and isolated from same.

Patrick Maroney
_____________________________
From: Jordan, Bret <
bret.jordan@bluecoat.com>
Sent: Friday, October 30, 2015 6:34 PM
Subject: Re: [cti-taxii] Questioning the wisdom of using DNS SRV records for TAXII 2.0 Discovery
To: Patrick Maroney <
pmaroney@specere.org>
Cc: Terry MacDonald <
terry@soltra.com>, Trey Darley <trey@soltra.com>, <cti-taxii@lists.oasis-open.org>


You hit on a very key point that I have brought up many times before.... Not everyone is going to share nor can everyone share openly. Thanks for re-illustrating that point. We are going to have pockets of CTI within niche eco-systems and various trust groups or groups of interest that share some amount of CTI within their groups. Public and open sharing will be for very low hanging fruit that people often refer to as background noise. The more juicy and cutting edge CTI will be highly restricted and available only under certain out-of-band subscription agreements.


To this end, we need TAXII to be able to work really well within these close networks and niche eco-systems. We also need TAXII to work with ad-hoc groups of interest that need to share some latest greatest threats in a seemingly structured way.

I guess this is one of my pet peeves with data making / data handling. Most of the groups that really need this are not going to share with people outside of their group. Further, it will be impossible to guarantee that an end STIX/TAXII system will honor the data-markings. Also, a lot of the data-markings I am hearing about are so complicated that a human need to read them understand them anyway, it is not like arbitrary software is going to know how to handle them.

The things I want to focus on in TAXII are:

1) How do we make intra-org sharing of CTI amazingly simple and easy to use

2) How do we enable org-to-org sharing of CTI in a secure manner for those orgs that are open to sharing in the first place

3) How do we enable ad-hoc groups to setup a TAXII sharing community on the fly to share information about some new threat they are looking in to.

4) How do we build a relatively secure system so people can selectively share CTI with people.


Thanks,

Bret



Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO
Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."







[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]