OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti] Identity objects in the STIX common object repository


We would need a tool that could automatically run against the data to monitor for duplicates.  It kinds of seems like people should send those identity objects to the stix@mitre email address and have MITRE people vet them and add them. :)


Bret

On Jun 10, 2021, at 12:52 PM, Rich Piazza <rpiazza@mitre.org> wrote:

HI everyone,
 
Both Jason and Allan have proposed storing identity objects for producers and consumers in the STIX common object repository.
 
This sounds like a good idea to me.  The repo could act as a âwhite pagesâ for STIX users. 
 
If you receive some content but it doesnât include the Identity object referred to in the created_by_ref property, not knowing who created the content could be an impediment to trusting/using it.  Additionally, if an extension definition is stored in the repository, you might want contact information of the creator to discuss how to use the extension.
 
Of course, some STIX users will prefer to remain anonymous â so this would not be for them. There is the problem of having a common place to find Identity objects to facilitate spoofing the creator of a submission, although there is nothing to prevent that currently.
 
There would need to be some protocol to vet any Identity object submissions to the repository and there might be multiple identities for an individual/organization, but those details can be worked out.
 
Comments??
 
                Rich P.
 
--
Rich Piazza
Lead Cyber Security Engineer
The MITRE Corporation
781-271-3760
 
<image001.png>



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]