OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti] Question Gathering: Relationship Preservation in Versioning (Implicit vs Explicit)


Thanks Sarah - this is precisely my thinking so I am glad I am not crazy :)

To copy/paste/revise something I sent in a Slack earlier today...

To me, you have to go back to the use cases. If I am an analyst, and I have built up a bunch of stuff around some intelligence using Maltego or I2 or whatever… when someone pushes an update, do I expect it to cascade through my model I have spent a week building? Or do I expect to have to go and manually  update eveything? If it was ME, I would want the cascade. And its the same flow for automated tools as well… I set up a rule in a SIEM around STIX.. do I expect that rule to be dynamically updated with new versions? You betcha... If I have a daily report or dashboard running on a campaign, every day I run that report, I want it to show the latest information. I dont want it to be static, showing the same thing day in and day out. The same is true if I have something referencing a watch list, or something referencing a set of TTP.

When I look at the actual use cases for intel.. I think people will usually want the latest. I am at a bit of a loss why everyone assumes that people will essentially want “stale” info by default.


-
Jason Keirstead
STSM, Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for Sarah Kelley ---03/21/2016 12:24:44 PM---I would argue that even as the producer I don’t want to haSarah Kelley ---03/21/2016 12:24:44 PM---I would argue that even as the producer I don’t want to have to update every relationship every time

From: Sarah Kelley <Sarah.Kelley@cisecurity.org>
To: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
Date: 03/21/2016 12:24 PM
Subject: Re: [cti] Question Gathering: Relationship Preservation in Versioning (Implicit vs Explicit)
Sent by: <cti@lists.oasis-open.org>





I would argue that even as the producer I don’t want to have to update every relationship every time I revision something. Let’s say I have 600 indicators linked to a TTP or a Campaign. If I update that TTP or Campaign, I do NOT want to have to update 600 corresponding relationships, even if I do have the ability to do so.

Sarah Kelley
Senior CERT Analyst
Center for Internet Security (CIS)
Integrated Intelligence Center (IIC)
Multi-State Information Sharing and Analysis Center (MS-ISAC)
1-866-787-4722 (7×24 SOC)
Email: cert@cisecurity.org
www.cisecurity.org
Follow us @CISecurity


From: <cti@lists.oasis-open.org> on behalf of "Jordan, Bret" <bret.jordan@bluecoat.com>
Date:
Monday, March 21, 2016 at 11:17 AM
To:
Jason Keirstead <Jason.Keirstead@ca.ibm.com>
Cc:
Trey Darley <trey@soltra.com>, "Marlon.Taylor@us-cert.gov" <Marlon.Taylor@us-cert.gov>, "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
Subject:
Re: [cti] Question Gathering: Relationship Preservation in Versioning (Implicit vs Explicit)

I agree with Jason.... Major things the versioning mini-group needs to know:

1) Relationships will be created by groups other than the producer of the objects.

2) The producer may NEVER have access to those relationships.

3) When the producer updates some content in their object is MUST NOT break all of the relationships in the wild.




Thanks,

Bret



Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO
Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."

This message and attachments may contain confidential information. If it appears that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify the sender immediately and permanently delete the message and any attachments.
. . .





[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]