OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Working Call - Text Version


CTI TC:

Below is a text-based version of the Working Call notes from today:

Â

Meeting Date:

December 11, 2018

Time:

3:00 p.m. EST

Purpose:

Weekly Working Session


Attendees:

Allan Thomson â Moderator

Trey Darley

Sarah Kelley

Gary Katz

John-Mark Gurney

Richard Struse

Â

Bret Jordan

Sean Barnum

Nicholas Hayden

Tom Vaughn

Taneika Hill

Emmanuelle Vargas-Gonzalez

Â

Jason Keirstead

Chris Ricard

Vivek Jain

Jackie Eun Park

Jane Ginn â Recorder

Â

Agenda:

ÂÂÂÂÂÂÂ Cyber Observables â How handle moving forward

Meeting Notes:


ÂÂÂÂÂÂÂÂÂÂÂ Allan Thomson

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Introduced the work of the Mini-Group on the Cyber Observables issue

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Richard Struse

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ We need to reach resolution on this issue â time is important â Weâll discuss in full TC

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Allan Thomson

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Noted that this is being discussed relative to specific Use Cases â Using Malware SDO

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ It will also affect Infrastructure SDO â But, that is not currently in STIX 2.1

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ If you think we need this extra Use Case, please comment on the Slide

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Gary put this slide in:
ÂÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ [Slide not available in text version]
ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ As it is now (Malware Example):
ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ [Slide not available in text version]
ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ With the proposed solution (Malware Example):
ÂÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂÂ ÂÂ ÂÂÂ Â [Slide not available in text version]


ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Allan asked for comments

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Chris Ricard

 I think it may break some more things than it solves. I wrote up my rationale, but it didnât go out.

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Iâll send it to you, Allan â Can you send out?

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Sarah Kelley

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ I see that this proposal combines some of the features of the two proposals. It is a nice compromise

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Bret Jordan

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ I agree with Sarah â It will require that we write more code, but it is a compromise that appears

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ To solve the problem of the Use Cases we are looking at

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Allan Thomson

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ We need to present this to the full TC, then go to a Ballot

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ For the Minutes â We had almost Unanimity that this approach might work â with one exception

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Also, Jeffrey had raised some issues on the Slack channel

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Does anyone object to going through these issues?

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ [Articulated Jeffâs concerns â offered an approach to resolve the solution]

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Sean Barnum

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ [Gave an example of how SDOs and COs evolve through time â And how could be shared through time.]

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ We feel very strongly about approach to versioningâ. We want to keep all of the old data

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ [Talked about the Modified version]

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ John-Mark Gurney

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ [Talked about core properties issue] [Talked about some other issues that might arise with this approach]

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Jeffrey Mates

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Iâll point out â One issue with a certain Timestamp â it assumes a centralized system from each Producer

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ [Then gave example of sensor-generated IDs â and modifying]

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ I worry about this if we are saying âlatest always winsâ or âmore detailed version always winsâ

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Gary Katz

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ If you want to hash everything â it would be possible by this approach â

I want to go to John-Markâs point

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ [Gave some examples of how issue could be handled]

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ This approach is designed to address that problem

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ John-Mark Gurney

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ It was really related to versioning â if you update, you can lose your data

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Gary Katz

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ We really need to do a good write-up on how to do versioning

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Sean Barnum

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ [Talked about how the various implementations will differ â Discussed what STIX needs to do]

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Allan Thomson

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ [Gave some observations about how different products will respond to the data with these changes.]

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ The context of consuming this data is dependent on the consumer

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ John-Mark Gurney

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ We could make it complicated and add rules â but, I agree, that we donât want to do that

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ One possibility is a SIM link

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ The other point- there is an implicit assumption that the ID is part of the Object

Â

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Chris Ricard

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ I want to make sure that what-ever we come up with will work with TAXII versioning

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Jeffrey Mates

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ We do call this out with TLOs currentlyâ. [Explained how currently handled]

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ In this case â there may be some overlapping because of these rules

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ John-Mark Gurney

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Previously ID was globally unique â Now, we will have some overlapping

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Jeffrey Mates

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ I agree about the globally unique issue

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ John-Mark Gurney

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ This is also tied to how TAXII deals with over-writes

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Sean Barnum

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Iâm never assuming that our solution is right â But, we know that it does work â Others may do it too.

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ This is possible to solve

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Allan Thomson

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Some things are not solved with STIX alone

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ We have 3 minutes left â I want to put a wrap-up on the call

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Weâll use this slide deck on the full TC call later this week

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ If you have additional concerns â please send your concerns to the Mini-Group

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Weâll continue to work on this â if you want to get involved â please join the Slack Channel

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Trey Darley

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ We are coming up to the Holiday season â we should probably do a Doodle Poll â Schedule calls

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Notional deadline of January 31.Â

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Iâll propose that we find some serious time to work through issues and write text â we will need

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Everyone to get together â weâll need to incorporate the Digital Signature updates.

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ That work will start in January â if we donât do the work, weâll revert to earlier version.

Meeting Terminated

*******************************************************************************

-- 
*****************************
Jane Ginn, MSIA, MRP
Secretary, OASIS CTI TC
jg@ctin.us
001 (928) 399-0509
*****************************


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]