OASIS Cyber Threat Intelligence (CTI) TC

 View Only
  • 1.  Database Subcommittee

    Posted 06-19-2015 03:12
    About 9 months ago or so we tossed around the idea of setting up a Subcommittee / Working group to look in to database requirements and build photo-type examples for storying STIX and or TAXII data.  I would like to propose that we do that here at OASIS and I would nominate Eric Burger to Chair this committee.  He is after all a professor of computer science that teaches database theory...  I think we would be very lucky to have him run this group. Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg.   Attachment: signature.asc Description: Message signed with OpenPGP using GPGMail


  • 2.  Re: [cti] Database Subcommittee

    Posted 06-19-2015 03:16
    Bret: +1 for that. Should that be a Sub-Sub-Committee to STIX? Or is this an important enough issue that it should constitute a separate Sub-Committee? Jane Quoting "Jordan, Bret" <bret.jordan@bluecoat.com>: About 9 months ago or so we tossed around the idea of setting up a Subcommittee / Working group to look in to database requirements and build photo-type examples for storying STIX and or TAXII data. I would like to propose that we do that here at OASIS and I would nominate Eric Burger to Chair this committee. He is after all a professor of computer science that teaches database theory... I think we would be very lucky to have him run this group. Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."


  • 3.  Re: [cti] Database Subcommittee

    Posted 06-19-2015 03:22
    Dunno, and I do not really care so much as long as it gets done.  I think this will be vital for rapid escalation of STIX and TAXII..  Imagine if open-source developers and app developers could not only grab a set of APIs but they could also grab a basic database or schema for a database.  This could help them go from zero-to-fullspeed in very little time. Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg.   On Jun 18, 2015, at 21:15, jg@ctin.us wrote: Bret: +1 for that. Should that be a Sub-Sub-Committee to STIX? Or is this an important enough issue that it should constitute a separate Sub-Committee? Jane Quoting Jordan, Bret < bret.jordan@bluecoat.com >: About 9 months ago or so we tossed around the idea of setting up a Subcommittee / Working group to look in to database requirements and build photo-type examples for storying STIX and or TAXII data.  I would like to propose that we do that here at OASIS and I would nominate Eric Burger to Chair this committee.  He is after all a professor of computer science that teaches database theory...  I think we would be very lucky to have him run this group. Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg. --------------------------------------------------------------------- To unsubscribe from this mail list, you must leave the OASIS TC thatgenerates this mail.  Follow this link to all your TCs in OASIS at: https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php Attachment: signature.asc Description: Message signed with OpenPGP using GPGMail


  • 4.  Re: [cti] Database Subcommittee

    Posted 06-19-2015 04:46
    How about expanding that database specific idea to a general 'Implementation' one? One that focuses on the best ways to actually create the tools and use the libraries that the STIX / TAXII / CybOX subcommittees output? It would cover database implementations, guidance on how to glue together the different libraries, testing for interoperability, and things like that? Cheers Terry MacDonald STIX, TAXII, CybOX Consultant M: +61-407-203-026 E:  terry.macdonald@threatloop.com W:  www.threatloop.com Disclaimer: The opinions expressed within this email do not represent the sentiment of any other party except my own. My views do not necessarily reflect those of my employers. On 19 June 2015 at 13:21, Jordan, Bret < bret.jordan@bluecoat.com > wrote: Dunno, and I do not really care so much as long as it gets done.  I think this will be vital for rapid escalation of STIX and TAXII..  Imagine if open-source developers and app developers could not only grab a set of APIs but they could also grab a basic database or schema for a database.  This could help them go from zero-to-fullspeed in very little time. Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."  On Jun 18, 2015, at 21:15, jg@ctin.us wrote: Bret: +1 for that. Should that be a Sub-Sub-Committee to STIX? Or is this an important enough issue that it should constitute a separate Sub-Committee? Jane Quoting "Jordan, Bret" < bret.jordan@bluecoat.com >: About 9 months ago or so we tossed around the idea of setting up a Subcommittee / Working group to look in to database requirements and build photo-type examples for storying STIX and or TAXII data.  I would like to propose that we do that here at OASIS and I would nominate Eric Burger to Chair this committee.  He is after all a professor of computer science that teaches database theory...  I think we would be very lucky to have him run this group. Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." --------------------------------------------------------------------- To unsubscribe from this mail list, you must leave the OASIS TC thatgenerates this mail.  Follow this link to all your TCs in OASIS at: https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php


  • 5.  Re: [cti] Database Subcommittee

    Posted 06-19-2015 05:00
    Very interesting idea.  I could go with that.  Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg.   On Jun 18, 2015, at 22:45, Terry MacDonald < terry.macdonald@threatloop.com > wrote: How about expanding that database specific idea to a general 'Implementation' one? One that focuses on the best ways to actually create the tools and use the libraries that the STIX / TAXII / CybOX subcommittees output? It would cover database implementations, guidance on how to glue together the different libraries, testing for interoperability, and things like that? Cheers Terry MacDonald STIX, TAXII, CybOX Consultant M: +61-407-203-026 E:  terry.macdonald@threatloop.com W:  www.threatloop.com Disclaimer: The opinions expressed within this email do not represent the sentiment of any other party except my own. My views do not necessarily reflect those of my employers. On 19 June 2015 at 13:21, Jordan, Bret < bret.jordan@bluecoat.com > wrote: Dunno, and I do not really care so much as long as it gets done.  I think this will be vital for rapid escalation of STIX and TAXII..  Imagine if open-source developers and app developers could not only grab a set of APIs but they could also grab a basic database or schema for a database.  This could help them go from zero-to-fullspeed in very little time. Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg.   On Jun 18, 2015, at 21:15, jg@ctin.us wrote: Bret: +1 for that. Should that be a Sub-Sub-Committee to STIX? Or is this an important enough issue that it should constitute a separate Sub-Committee? Jane Quoting Jordan, Bret < bret.jordan@bluecoat.com >: About 9 months ago or so we tossed around the idea of setting up a Subcommittee / Working group to look in to database requirements and build photo-type examples for storying STIX and or TAXII data.  I would like to propose that we do that here at OASIS and I would nominate Eric Burger to Chair this committee.  He is after all a professor of computer science that teaches database theory...  I think we would be very lucky to have him run this group. Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg. --------------------------------------------------------------------- To unsubscribe from this mail list, you must leave the OASIS TC thatgenerates this mail.  Follow this link to all your TCs in OASIS at: https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php Attachment: signature.asc Description: Message signed with OpenPGP using GPGMail


  • 6.  Re: [cti] Database Subcommittee

    Posted 06-19-2015 08:14
    +1 2015-06-19 6:11 GMT+03:00 Jordan, Bret <bret.jordan@bluecoat.com>: > About 9 months ago or so we tossed around the idea of setting up a > Subcommittee / Working group to look in to database requirements and build > photo-type examples for storying STIX and or TAXII data. I would like to > propose that we do that here at OASIS and I would nominate Eric Burger to > Chair this committee. He is after all a professor of computer science that > teaches database theory... I think we would be very lucky to have him run > this group. > > > Thanks, > > Bret > > > > Bret Jordan CISSP > Director of Security Architecture and Standards Office of the CTO > Blue Coat Systems > PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 > "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can > not be unscrambled is an egg." >


  • 7.  Re: [cti] Database Subcommittee

    Posted 06-19-2015 14:28
    And I would nominate Jerome to Co-Chair this with Eric Burger.   Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg.   On Jun 19, 2015, at 02:14, Jerome Athias < athiasjerome@GMAIL.COM > wrote: +1 2015-06-19 6:11 GMT+03:00 Jordan, Bret < bret.jordan@bluecoat.com >: About 9 months ago or so we tossed around the idea of setting up a Subcommittee / Working group to look in to database requirements and build photo-type examples for storying STIX and or TAXII data.  I would like to propose that we do that here at OASIS and I would nominate Eric Burger to Chair this committee.  He is after all a professor of computer science that teaches database theory...  I think we would be very lucky to have him run this group. Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303 Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg. Attachment: signature.asc Description: Message signed with OpenPGP using GPGMail