OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti] Update from STIX Package renaming Mini-Group


If the ID is going to be used in request / response in TAXII, then shouldn't it be part of that layer (transport)? Request/response is not something done in the STIX layer.


-
Jason Keirstead
STSM, Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for Allan Thomson ---05/03/2016 03:36:21 PM---I think an id is useful for retrieval (request/response) anAllan Thomson ---05/03/2016 03:36:21 PM---I think an id is useful for retrieval (request/response) and tracking. 1. For Request/Response ha

From: Allan Thomson <athomson@lookingglasscyber.com>
To: "Jordan, Bret" <bret.jordan@bluecoat.com>, Jason Keirstead/CanEast/IBM@IBMCA
Cc: Mark Davidson <mdavidson@soltra.com>, "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
Date: 05/03/2016 03:36 PM
Subject: Re: [cti] Update from STIX Package renaming Mini-Group
Sent by: <cti@lists.oasis-open.org>





I think an id is useful for retrieval (request/response) and tracking.
In both cases, there’s alternate solutions to solving these problems but it would seem adding an id to the bundle itself by the creator of the bundle is not difficult and helps use bundles.

What exactly would be the problem of having an id in the bundle?

If you don’t care about the id then just ignore it.

allan

From "Jordan, Bret" <bret.jordan@bluecoat.com>
Date:
Tuesday, May 3, 2016 at 10:03 AM
To:
Jason Keirstead <Jason.Keirstead@ca.ibm.com>
Cc:
Allan Thomson <athomson@lookingglasscyber.com>, Mark Davidson <mdavidson@soltra.com>, "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
Subject:
Re: [cti] Update from STIX Package renaming Mini-Group

I agree with Jason... I know the request on the call was about how do you know if you did not get a bundle. That seems to be an implementation / transport level issue, not a language level issue. Allan / Terry? Thoughts? Is there another way of doing what you asked without having an ID field?


Thanks,

Bret



Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO
Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."





[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]