OASIS Cyber Threat Intelligence (CTI) TC

 View Only

Minutes from Interop working call

  • 1.  Minutes from Interop working call

    Posted 07-14-2020 20:29
      |   view attached




    Hi, all
     
    Got some good work done today on the working call; lots more to go.

    First, many thanks to everyone who has contributed to the update of the interop docs. It s been a great month. Lots of editing to perform now due to the good reviews. Here s some highlights from today s review.
     
    STIX 2.1 Interoperability Test Document Part 1 V0.1

    [Section 1] Use Case vs Test Case
    As these terms are used interchangeably a lot in the documents, we will use Use Case to refer to the high/top-level sections that cover a domain of interop. We will use Test case to refer to specific and individual cases within the Use Case . [Section 2.1] Re-write Bundle paragraph
    We ve decided to remove the Bundle wrappers from the STIX objects so we focus more on the object interop and less on the Bundle. The assumption for interop for this version is that all STIX objects relevant to a test case are present in the test container
    when needed.
    The STIX 2.1 specification allows object references that are not distributed within the same container (i.e. STIX Bundle, TAXII Envelope). However the current scope of this specification chooses to rely on all data being within the same container. [throughout] What is the right word to suggest all STIX objects are available when referenced? present , accessible ? [throughout] Changing mandatory required [throughout] Changing fields , attributes properties [Sections 2.3, 2.4] Migrating from cyber-observables to SCOs, including a note that cyber-observables are still supported, but deprecated. Rich P volunteered
    for these changes.
     
    Also, we ve agreed to meet more often to get ahead of this work. I ll get a next meeting notice out soon.
     
    Thanks.
    Justin

    Justin Stewart
    Software Engineer

    lookingglasscyber.com
    This electronic message transmission contains information from LookingGlass Cyber Solutions, Inc. which may be attorney-client
    privileged, proprietary and/or confidential. The information in this message is intended only for use by the individual(s) to whom it is addressed.  If you believe that you have received this message in error, please contact the sender, delete this message,
    and be aware that any review, use, disclosure, copying or distribution of the contents contained within is strictly prohibited.