OASIS Cyber Threat Intelligence (CTI) TC

 View Only
  • 1.  Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?

    Posted 08-30-2019 14:34




    Hi Ivan not exactly sure what you mean by type of sponsorship.

    Do you mean what interop profile (i.e. DFP vs TIP vs TM .etc) ?
     
    Or
     
    Do you mean more examples that we want for SCO sponsorship verification?
     
    Maybe we can add this discussion topic to the next weekly meeting.
     

    Allan Thomson
    CTO ( +1-408-331-6646)

    LookingGlass Cyber Solutions
     

    From: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> on behalf of "Kirillov, Ivan" <ikirillov@mitre.org>
    Date: Friday, August 30, 2019 at 7:24 AM
    To: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    That makes sense to me, Allan. Any other thoughts as to the type of sponsorship for the below items?
     
    Thanks,
    Ivan
     

    From: <cti@lists.oasis-open.org> on behalf of Allan Thomson <athomson@lookingglasscyber.com>
    Date: Friday, August 9, 2019 at 11:25 AM
    To: Ivan Kirillov <ikirillov@mitre.org>, "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    Ivan I would suggest that the user of SCO as top-level objects just needs to be conceptually verified.
     
    A couple of real-world examples might suffice.
     

    Malware SDO and/or Malware Analysis SDO referencing SCO artifacts Observed Data referencing SCO artifacts as part of a sighting/observed-data/indicator trifecta.
     
    Those 2 examples might be good enough.
     

    Allan Thomson
    CTO ( +1-408-331-6646)

    LookingGlass Cyber Solutions
     

    From: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> on behalf of "Kirillov, Ivan" <ikirillov@mitre.org>
    Date: Friday, August 9, 2019 at 10:16 AM
    To: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: [cti] STIX 2.1 CSD02 Sponsorship?


     

    All,
     
    Now that STIX 2.1 CSD02 is out the door, we can begin the sponsorship process. However, one of the questions that we (MITRE/DHS) have is with regards to the type of sponsorship expected for each item full
    (code + interop text) or just working code. If you recall from the last sponsorship period, certain things like confidence only required working code while others such as the Opinion & Note objects required interop text as well.
     
    Here s the list of items for sponsorship, along with my own thoughts as to the type of sponsorship:
     

    COA: full Grouping: full Infrastructure: full Malware: full Malware Analysis: full SCOs as top-level objects: full however, the level of detail on this one is quite open. Maybe different sponsors can choose different SCOs to cover? SCO relationships: working code Deterministic IDs: working code
     
    Also, I would suggest that we don t formally start the sponsorship period until we get this question resolved, so that sponsors have a better understanding of what is expected.
     
    -Ivan






  • 2.  Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?

    Posted 08-30-2019 15:22




    Hi Allan,
     
    What I m trying to get at is whether the sponsored item requires interop text (including profile, examples, etc.) and working code or just working code. Some items, like deterministic IDs, seem like they ll
    only require code while others will require both interop + code.
     
    Discussing at the next working call sounds good to me.
     
    Thanks,
    Ivan
     

    From: <cti@lists.oasis-open.org> on behalf of Allan Thomson <athomson@lookingglasscyber.com>
    Date: Friday, August 30, 2019 at 8:34 AM
    To: Ivan Kirillov <ikirillov@mitre.org>, "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    Hi Ivan not exactly sure what you mean by type of sponsorship.

    Do you mean what interop profile (i.e. DFP vs TIP vs TM .etc) ?
     
    Or
     
    Do you mean more examples that we want for SCO sponsorship verification?
     
    Maybe we can add this discussion topic to the next weekly meeting.
     

    Allan Thomson
    CTO ( +1-408-331-6646)

    LookingGlass Cyber Solutions
     

    From: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> on behalf of "Kirillov, Ivan" <ikirillov@mitre.org>
    Date: Friday, August 30, 2019 at 7:24 AM
    To: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    That makes sense to me, Allan. Any other thoughts as to the type of sponsorship for the below items?
     
    Thanks,
    Ivan
     

    From: <cti@lists.oasis-open.org> on behalf of Allan Thomson <athomson@lookingglasscyber.com>
    Date: Friday, August 9, 2019 at 11:25 AM
    To: Ivan Kirillov <ikirillov@mitre.org>, "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    Ivan I would suggest that the user of SCO as top-level objects just needs to be conceptually verified.
     
    A couple of real-world examples might suffice.
     

    Malware SDO and/or Malware Analysis SDO referencing SCO artifacts Observed Data referencing SCO artifacts as part of a sighting/observed-data/indicator trifecta.
     
    Those 2 examples might be good enough.
     

    Allan Thomson
    CTO ( +1-408-331-6646)

    LookingGlass Cyber Solutions
     

    From: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> on behalf of "Kirillov, Ivan" <ikirillov@mitre.org>
    Date: Friday, August 9, 2019 at 10:16 AM
    To: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: [cti] STIX 2.1 CSD02 Sponsorship?


     

    All,
     
    Now that STIX 2.1 CSD02 is out the door, we can begin the sponsorship process. However, one of the questions that we (MITRE/DHS) have is with regards to the type of sponsorship expected for each item full
    (code + interop text) or just working code. If you recall from the last sponsorship period, certain things like confidence only required working code while others such as the Opinion & Note objects required interop text as well.
     
    Here s the list of items for sponsorship, along with my own thoughts as to the type of sponsorship:
     

    COA: full Grouping: full Infrastructure: full Malware: full Malware Analysis: full SCOs as top-level objects: full however, the level of detail on this one is quite open. Maybe different sponsors can choose different SCOs to cover? SCO relationships: working code Deterministic IDs: working code
     
    Also, I would suggest that we don t formally start the sponsorship period until we get this question resolved, so that sponsors have a better understanding of what is expected.
     
    -Ivan






  • 3.  Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?

    Posted 08-30-2019 18:06
    We will talk about this on next week's working call.  But I think it can be what ever we thing it needs to be.  The work MITRE has already done on deterministic IDs has been awesome.  It has found several problems that we were already able to address.  This just goes to show how valuable this sponsorship work is. Bret From: cti@lists.oasis-open.org <cti@lists.oasis-open.org> on behalf of Kirillov, Ivan A. <ikirillov@mitre.org> Sent: Friday, August 30, 2019 9:21 AM To: Allan Thomson <athomson@lookingglasscyber.com>; cti@lists.oasis-open.org <cti@lists.oasis-open.org> Subject: Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?   Hi Allan,   What I’m trying to get at is whether the sponsored item requires interop text (including profile, examples, etc.) and working code or just working code. Some items, like deterministic IDs, seem like they’ll only require code while others will require both interop + code.   Discussing at the next working call sounds good to me.   Thanks, Ivan   From: <cti@lists.oasis-open.org> on behalf of Allan Thomson <athomson@lookingglasscyber.com> Date: Friday, August 30, 2019 at 8:34 AM To: Ivan Kirillov <ikirillov@mitre.org>, "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> Subject: Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?   Hi Ivan – not exactly sure what you mean by ‘type’ of sponsorship. Do you mean what interop profile (i.e. DFP vs TIP vs TM ….etc) ?   Or   Do you mean more examples that we want for SCO sponsorship verification?   Maybe we can add this discussion topic to the next weekly meeting.   Allan Thomson CTO ( +1-408-331-6646) LookingGlass Cyber Solutions   From: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> on behalf of "Kirillov, Ivan" <ikirillov@mitre.org> Date: Friday, August 30, 2019 at 7:24 AM To: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> Subject: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?   That makes sense to me, Allan. Any other thoughts as to the “type” of sponsorship for the below items?   Thanks, Ivan   From: <cti@lists.oasis-open.org> on behalf of Allan Thomson <athomson@lookingglasscyber.com> Date: Friday, August 9, 2019 at 11:25 AM To: Ivan Kirillov <ikirillov@mitre.org>, "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> Subject: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?   Ivan – I would suggest that the user of SCO as top-level objects just needs to be conceptually verified.   A couple of real-world examples might suffice.   Malware SDO and/or Malware Analysis SDO referencing SCO artifacts Observed Data referencing SCO artifacts as part of a sighting/observed-data/indicator trifecta.   Those 2 examples might be good enough.   Allan Thomson CTO ( +1-408-331-6646) LookingGlass Cyber Solutions   From: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> on behalf of "Kirillov, Ivan" <ikirillov@mitre.org> Date: Friday, August 9, 2019 at 10:16 AM To: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> Subject: [cti] STIX 2.1 CSD02 Sponsorship?   All,   Now that STIX 2.1 CSD02 is out the door, we can begin the sponsorship process. However, one of the questions that we (MITRE/DHS) have is with regards to the “type” of sponsorship expected for each item – “full” (code + interop text) or just working code. If you recall from the last sponsorship period, certain things like confidence only required working code while others such as the Opinion & Note objects required interop text as well.   Here’s the list of items for sponsorship, along with my own thoughts as to the type of sponsorship:   COA: full Grouping: full Infrastructure: full Malware: full Malware Analysis: full SCOs as top-level objects: full – however, the level of detail on this one is quite open. Maybe different sponsors can choose different SCOs to cover? SCO relationships: working code Deterministic IDs: working code   Also, I would suggest that we don’t formally start the sponsorship period until we get this question resolved, so that sponsors have a better understanding of what is expected.   -Ivan


  • 4.  Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?

    Posted 08-30-2019 23:25




    Hi Ivan Given that nature of deterministic IDs and the point that 2 vendors (if complying to the spec) should be able to produce the same SCO with the same deterministic ID and then see things merge correctly
    when their intel is shared into a TIP or similar system that would see both intel providers then I think we should have interop rules and tests to verify that.
     
    Similarly, if a vendor chooses to create SCO with their own ID creation algorithm then we need to make sure that this intel would co-exist in a ecosystem where we have both deterministic ID creation of SCO
    with compliant algorithm vs vendor-specific algorithm and then all of those SCO are referenced by the same campaigns/attack patterns .etc.
     
    So I think interop rules needs to be created for all these use cases. I can also think of more that will have a very tangible impact on anyone trying to use SCO from single or multi-vendors.
     

    Allan Thomson
    CTO ( +1-408-331-6646)
    LookingGlass Cyber Solutions

     

    From: "Kirillov, Ivan" <ikirillov@mitre.org>
    Date: Friday, August 30, 2019 at 8:22 AM
    To: Allan Thomson <athomson@lookingglasscyber.com>, "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    Hi Allan,
     
    What I m trying to get at is whether the sponsored item requires interop text (including profile, examples, etc.) and working code or just working code. Some items, like deterministic IDs, seem like they ll
    only require code while others will require both interop + code.
     
    Discussing at the next working call sounds good to me.
     
    Thanks,
    Ivan
     

    From: <cti@lists.oasis-open.org> on behalf of Allan Thomson <athomson@lookingglasscyber.com>
    Date: Friday, August 30, 2019 at 8:34 AM
    To: Ivan Kirillov <ikirillov@mitre.org>, "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    Hi Ivan not exactly sure what you mean by type of sponsorship.

    Do you mean what interop profile (i.e. DFP vs TIP vs TM .etc) ?
     
    Or
     
    Do you mean more examples that we want for SCO sponsorship verification?
     
    Maybe we can add this discussion topic to the next weekly meeting.
     

    Allan Thomson
    CTO ( +1-408-331-6646)

    LookingGlass Cyber Solutions
     

    From: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> on behalf of "Kirillov, Ivan" <ikirillov@mitre.org>
    Date: Friday, August 30, 2019 at 7:24 AM
    To: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    That makes sense to me, Allan. Any other thoughts as to the type of sponsorship for the below items?
     
    Thanks,
    Ivan
     

    From: <cti@lists.oasis-open.org> on behalf of Allan Thomson <athomson@lookingglasscyber.com>
    Date: Friday, August 9, 2019 at 11:25 AM
    To: Ivan Kirillov <ikirillov@mitre.org>, "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    Ivan I would suggest that the user of SCO as top-level objects just needs to be conceptually verified.
     
    A couple of real-world examples might suffice.
     

    Malware SDO and/or Malware Analysis SDO referencing SCO artifacts Observed Data referencing SCO artifacts as part of a sighting/observed-data/indicator trifecta.
     
    Those 2 examples might be good enough.
     

    Allan Thomson
    CTO ( +1-408-331-6646)

    LookingGlass Cyber Solutions
     

    From: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> on behalf of "Kirillov, Ivan" <ikirillov@mitre.org>
    Date: Friday, August 9, 2019 at 10:16 AM
    To: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
    Subject: [cti] STIX 2.1 CSD02 Sponsorship?


     

    All,
     
    Now that STIX 2.1 CSD02 is out the door, we can begin the sponsorship process. However, one of the questions that we (MITRE/DHS) have is with regards to the type of sponsorship expected for each item full
    (code + interop text) or just working code. If you recall from the last sponsorship period, certain things like confidence only required working code while others such as the Opinion & Note objects required interop text as well.
     
    Here s the list of items for sponsorship, along with my own thoughts as to the type of sponsorship:
     

    COA: full Grouping: full Infrastructure: full Malware: full Malware Analysis: full SCOs as top-level objects: full however, the level of detail on this one is quite open. Maybe different sponsors can choose different SCOs to cover? SCO relationships: working code Deterministic IDs: working code
     
    Also, I would suggest that we don t formally start the sponsorship period until we get this question resolved, so that sponsors have a better understanding of what is expected.
     
    -Ivan






  • 5.  Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?

    Posted 08-31-2019 04:07



    Great points Allan


    Bret 

    Sent from my Commodore 128D


    PGP
    Fingerprint:  63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050


    On Aug 31, 2019, at 1:25 AM, Allan Thomson < athomson@lookingglasscyber.com > wrote:







    Hi Ivan Given that nature of deterministic IDs and the point that 2 vendors (if complying to the spec) should be able to produce the same SCO with the same deterministic ID and then see things merge correctly
    when their intel is shared into a TIP or similar system that would see both intel providers then I think we should have interop rules and tests to verify that.
     
    Similarly, if a vendor chooses to create SCO with their own ID creation algorithm then we need to make sure that this intel would co-exist in a ecosystem where we have both deterministic ID creation of SCO
    with compliant algorithm vs vendor-specific algorithm and then all of those SCO are referenced by the same campaigns/attack patterns .etc.
     
    So I think interop rules needs to be created for all these use cases. I can also think of more that will have a very tangible impact on anyone trying to use SCO from single or multi-vendors.
     

    Allan Thomson
    CTO ( +1-408-331-6646)
    LookingGlass Cyber Solutions

     

    From: "Kirillov, Ivan" < ikirillov@mitre.org >
    Date: Friday, August 30, 2019 at 8:22 AM
    To: Allan Thomson < athomson@lookingglasscyber.com >, " cti@lists.oasis-open.org " < cti@lists.oasis-open.org >
    Subject: Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    Hi Allan,
     
    What I m trying to get at is whether the sponsored item requires interop text (including profile, examples, etc.) and working code or just working code. Some items, like deterministic IDs, seem like they ll
    only require code while others will require both interop + code.
     
    Discussing at the next working call sounds good to me.
     
    Thanks,
    Ivan
     

    From: < cti@lists.oasis-open.org > on behalf of Allan Thomson < athomson@lookingglasscyber.com >
    Date: Friday, August 30, 2019 at 8:34 AM
    To: Ivan Kirillov < ikirillov@mitre.org >, " cti@lists.oasis-open.org " < cti@lists.oasis-open.org >
    Subject: Re: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    Hi Ivan not exactly sure what you mean by type of sponsorship.

    Do you mean what interop profile (i.e. DFP vs TIP vs TM .etc) ?
     
    Or
     
    Do you mean more examples that we want for SCO sponsorship verification?
     
    Maybe we can add this discussion topic to the next weekly meeting.
     

    Allan Thomson
    CTO ( +1-408-331-6646)

    LookingGlass Cyber Solutions
     

    From: " cti@lists.oasis-open.org " < cti@lists.oasis-open.org > on behalf of "Kirillov,
    Ivan" < ikirillov@mitre.org >
    Date: Friday, August 30, 2019 at 7:24 AM
    To: " cti@lists.oasis-open.org " < cti@lists.oasis-open.org >
    Subject: [cti] Re: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    That makes sense to me, Allan. Any other thoughts as to the type of sponsorship for the below items?
     
    Thanks,
    Ivan
     

    From: < cti@lists.oasis-open.org > on behalf of Allan Thomson < athomson@lookingglasscyber.com >
    Date: Friday, August 9, 2019 at 11:25 AM
    To: Ivan Kirillov < ikirillov@mitre.org >, " cti@lists.oasis-open.org " < cti@lists.oasis-open.org >
    Subject: [EXT] Re: [cti] STIX 2.1 CSD02 Sponsorship?


     

    Ivan I would suggest that the user of SCO as top-level objects just needs to be conceptually verified.
     
    A couple of real-world examples might suffice.
     

    Malware SDO and/or Malware Analysis SDO referencing SCO artifacts Observed Data referencing SCO artifacts as part of a sighting/observed-data/indicator trifecta.
     
    Those 2 examples might be good enough.
     

    Allan Thomson
    CTO ( +1-408-331-6646)

    LookingGlass Cyber Solutions
     

    From: " cti@lists.oasis-open.org " < cti@lists.oasis-open.org > on behalf of "Kirillov,
    Ivan" < ikirillov@mitre.org >
    Date: Friday, August 9, 2019 at 10:16 AM
    To: " cti@lists.oasis-open.org " < cti@lists.oasis-open.org >
    Subject: [cti] STIX 2.1 CSD02 Sponsorship?


     

    All,
     
    Now that STIX 2.1 CSD02 is out the door, we can begin the sponsorship process. However, one of the questions that we (MITRE/DHS) have is with regards to the type of sponsorship expected for each item full
    (code + interop text) or just working code. If you recall from the last sponsorship period, certain things like confidence only required working code while others such as the Opinion & Note objects required interop text as well.
     
    Here s the list of items for sponsorship, along with my own thoughts as to the type of sponsorship:
     

    COA: full Grouping: full Infrastructure: full Malware: full Malware Analysis: full SCOs as top-level objects: full however, the level of detail on this one is quite open. Maybe different sponsors can choose different SCOs to cover? SCO relationships: working code Deterministic IDs: working code
     
    Also, I would suggest that we don t formally start the sponsorship period until we get this question resolved, so that sponsors have a better understanding of what is expected.
     
    -Ivan