OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-users message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: Stix v2 RC3 - Cybox 3b


A quick follow up question also relates to v2 -> v3 Cybox differences.

It also appears that user_agent cannot be represented in v3. Unless one parses the user agent string and then treats each element – browser and os as two ‘software’ Cybox objects. Is this the intention?

Thanks

 

From: Conrad Crampton <conrad.crampton@SecData.com>
Date: Wednesday, 9 November 2016 at 14:09
To: "cti-users@lists.oasis-open.org" <cti-users@lists.oasis-open.org>
Subject: Stix v2 RC3 - Cybox 3b

 

Hi,

I see that the latest draft specification for Stix & Cybox have been merged into the same document set. However, I don’t know as a result of this some fidelity of the objects have been lost in comparison to Cybox v2 or that this happened much earlier. Specifically, I am looking to model an object / graph store using Cybox as the basis for the class structure but when I come to model an HTTP request / response the latter is missing. I can model the HTTP request reasonably well in the http-ext of network-traffic, but what I can’t do is model the response element of the ‘transaction’. I believe this was present in v2 as HTTP_Session object which also had HTTP_Request and HTTP_Response objects.

I don’t suggest moving this model asis into v3 as it seemed a little verbose, but is there any intention of having some representation of the http_response attributes (response_code etc. – thinking about it, this is really only the attribute I’m concerned with at the moment).

 

Of course, I could add this as an extension myself, but just wondering…

 

Thanks

Conrad



SecureData, combating cyber threats


The information contained in this message or any of its attachments may be privileged and confidential and intended for the exclusive use of the intended recipient. If you are not the intended recipient any disclosure, reproduction, distribution or other dissemination or use of this communications is strictly prohibited. The views expressed in this email are those of the individual and not necessarily of SecureData Europe Ltd. Any prices quoted are only valid if followed up by a formal written quote.

SecureData Europe Limited. Registered in England & Wales 04365896. Registered Address: SecureData House, Hermitage Court, Hermitage Lane, Maidstone, Kent, ME16 9NT



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]