OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

oasis-charter-discuss message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [oasis-charter-discuss] Re: [EXT] [oasis-charter-discuss] Notes from SARIF convener call 31 July 2017


On 01.08.2017 15:14:08, Trey Darley wrote:
> 
> Indeed. We've been working with DC3 on incorporating MWCP [1] into
> the STIX Malware data model. Not to suggest that MWCP addresses all
> of the static analysis metadata that the proposed SARIF TC intends
> to develop a standard for but there's clearly significant overlap
> between our respective efforts.
> 

Hey, y'all -

Apparently I'm not firing on all cylinders today. Ivan Kirillov just
pointed out that SARIF is intended to address static source code
analysis, not static analysis of malware binaries. These are clearly
very different things.

I retract my previous comments and apologize for the spurious mail
traffic. ¯\_(ツ)_/¯

-- 
Cheers,
Trey
++--------------------------------------------------------------------------++
Director of Standards Development, New Context
gpg fingerprint: 3918 9D7E 50F5 088F 823F  018A 831A 270A 6C4F C338
++--------------------------------------------------------------------------++
--
"With sufficient thrust, pigs fly just fine. However, this is not
necessarily a good idea. It is hard to be sure where they are going to
land, and it could be dangerous sitting under them as they fly
overhead." --RFC 1925

Attachment: signature.asc
Description: Digital signature



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]