OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Summary of the working call


On today’s working call, we discussed the event object. We didn’t have someone taking full notes, but I’ll try to summarize what was discussed below.

 

  1. The event object should be scoped down to just an IR type of event/incident. This would need to be clarified in the text, but that would then scope out some of our other use cases such as:
    1. An ‘alert’ coming into your system
    2. An ‘event’ such as a threat actor registering a domain
    3. The MISP version of ‘event’
  2. We removed the event_type property, and moved the words “event” and “incident” that were in the event-type-ov vocab to be in the labels field. (basically, we just merged event_type with labels)
  3. We created a relationship from an event to another event, indicating that one event can be part of another event. This should take care of the use case where you have five ‘events’ that then all become part of one ‘incident’. You would have 5 event objects, then create a 6th event object, add the incident label, and link the first 5 events to the 6th.
  4. We agreed we need to revist the property name for “impact_scope” and come up with something better. Also the purpose of this property needs to be clarified/wordsmithed.
  5. Two vocabularies need more work than the others, intended-effect-ov and detection-mechanism-ov. There are three possible ways to proceed:
    1. Remove these two properties and their vocabs
    2. Keep the properties but massively scale back the vocabs to just a few, well-agreed up on terms
    3. Keep the properties and spend the time and effort needed to fix these vocabularies

 

We’re hoping to clean up the proposal soon and maybe spend the next week discussing the “intended-effect-ov” and “detection-mechanism-ov” vocabularies.

 

Thanks,

 

Sarah Kelley

Senior Cyber Threat Analyst

Multi-State Information Sharing and Analysis Center (MS-ISAC)                   

31 Tech Valley Drive

East Greenbush, NY 12061

 

sarah.kelley@cisecurity.org

518-266-3493

24x7 Security Operations Center

SOC@cisecurity.org - 1-866-787-4722

 

                  

This message and attachments may contain confidential information. If it appears that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify the sender immediately and permanently delete the message and any attachments.

. . . . .


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]