CTI STIX Subcommittee

 View Only
  • 1.  Campaigns

    Posted 05-16-2016 19:41
    Gary, Kyle, Paul, et all, Can you guys help me get some good solid definitions in place for the Motive and Objective in the Campaign properties table?  If possible, it would be good to get some solid examples for people that have a hard time seeing the difference.   https://docs.google.com/document/d/1F1c05GgYaJFV1Z04B8c_T3vEE-LRQTPExF24LvOQAsk/edit#heading=h.vvysvm8mt434 Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050 Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg.   Attachment: signature.asc Description: Message signed with OpenPGP using GPGMail


  • 2.  RE: Campaigns

    Posted 05-16-2016 20:17
    I added some text here. It might be worth referencing some text from VERIS if we feel like people are still uncertain, as a similar distinction exists there. In fact: does it makes sense to import some of the enumerations from VERIS? -- Kyle Maxwell [kmaxwell@verisign.com] iDefense Senior Analyst From: Jordan, Bret [bret.jordan@bluecoat.com] Sent: Monday, May 16, 2016 14:40 To: Gary.Katz.ctr@dc3.mil; Maxwell, Kyle; Paul Patrick; cti-stix@lists.oasis-open.org Subject: Campaigns Gary, Kyle, Paul, et all, Can you guys help me get some good solid definitions in place for the Motive and Objective in the Campaign properties table?  If possible, it would be good to get some solid examples for people that have a hard time seeing the difference.   https://docs.google.com/document/d/1F1c05GgYaJFV1Z04B8c_T3vEE-LRQTPExF24LvOQAsk/edit#heading=h.vvysvm8mt434 Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050 "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." 


  • 3.  RE: Campaigns

    Posted 05-17-2016 13:51
    STIX 1.2 used many, if not most, of the enumerations from VERIS – almost item for item…   From: cti-stix@lists.oasis-open.org [mailto:cti-stix@lists.oasis-open.org] On Behalf Of Maxwell, Kyle Sent: Monday, May 16, 2016 4:17 PM To: Jordan, Bret <bret.jordan@bluecoat.com>; Gary.Katz.ctr@dc3.mil; Paul Patrick <ppatrick@isightpartners.com>; cti-stix@lists.oasis-open.org Subject: [cti-stix] RE: Campaigns   I added some text here. It might be worth referencing some text from VERIS if we feel like people are still uncertain, as a similar distinction exists there. In fact: does it makes sense to import some of the enumerations from VERIS?   -- Kyle Maxwell [kmaxwell@verisign.com] iDefense Senior Analyst From: Jordan, Bret [bret.jordan@bluecoat.com] Sent: Monday, May 16, 2016 14:40 To: Gary.Katz.ctr@dc3.mil ; Maxwell, Kyle; Paul Patrick; cti-stix@lists.oasis-open.org Subject: Campaigns Gary, Kyle, Paul, et all,   Can you guys help me get some good solid definitions in place for the Motive and Objective in the Campaign properties table?  If possible, it would be good to get some solid examples for people that have a hard time seeing the difference.     https://docs.google.com/document/d/1F1c05GgYaJFV1Z04B8c_T3vEE-LRQTPExF24LvOQAsk/edit#heading=h.vvysvm8mt434   Thanks,   Bret       Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050 "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."   


  • 4.  RE: Campaigns

    Posted 05-17-2016 14:34
    As a former contributor to VERIS (and perhaps I should be again), I endorse this ;) -- Kyle Maxwell [kmaxwell@verisign.com] iDefense Senior Analyst From: Piazza, Rich [rpiazza@mitre.org] Sent: Tuesday, May 17, 2016 08:50 To: Maxwell, Kyle; Jordan, Bret; Gary.Katz.ctr@dc3.mil; Paul Patrick; cti-stix@lists.oasis-open.org Subject: RE: Campaigns STIX 1.2 used many, if not most, of the enumerations from VERIS – almost item for item…   From: cti-stix@lists.oasis-open.org [mailto:cti-stix@lists.oasis-open.org] On Behalf Of Maxwell, Kyle Sent: Monday, May 16, 2016 4:17 PM To: Jordan, Bret <bret.jordan@bluecoat.com>; Gary.Katz.ctr@dc3.mil; Paul Patrick <ppatrick@isightpartners.com>; cti-stix@lists.oasis-open.org Subject: [cti-stix] RE: Campaigns   I added some text here. It might be worth referencing some text from VERIS if we feel like people are still uncertain, as a similar distinction exists there. In fact: does it makes sense to import some of the enumerations from VERIS?   -- Kyle Maxwell [kmaxwell@verisign.com] iDefense Senior Analyst From: Jordan, Bret [bret.jordan@bluecoat.com] Sent: Monday, May 16, 2016 14:40 To: Gary.Katz.ctr@dc3.mil ; Maxwell, Kyle; Paul Patrick; cti-stix@lists.oasis-open.org Subject: Campaigns Gary, Kyle, Paul, et all,   Can you guys help me get some good solid definitions in place for the Motive and Objective in the Campaign properties table?  If possible, it would be good to get some solid examples for people that have a hard time seeing the difference.     https://docs.google.com/document/d/1F1c05GgYaJFV1Z04B8c_T3vEE-LRQTPExF24LvOQAsk/edit#heading=h.vvysvm8mt434   Thanks,   Bret       Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050 "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."   


  • 5.  RE: [cti-stix] RE: Campaigns

    Posted 05-18-2016 02:08



    VERIS is amazing






  • 6.  Re: [cti-stix] Campaigns

    Posted 05-18-2016 03:22
    Then lets please use it as much as possible.  Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050 Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg.   On May 17, 2016, at 20:07, Foley, Alexander - GIS < alexander.foley@bankofamerica.com > wrote: VERIS is amazing


  • 7.  RE: [cti-stix] Campaigns

    Posted 05-18-2016 13:35




    VERIS is mainly concerned with reporting what we have called “incidents” – so it should be useful when we start working on that TLO…
     
    Much of the previous design of STIX Incidents came from VERIS – especially the controlled vocabularies.
     


    From: Jordan, Bret [mailto:bret.jordan@bluecoat.com]

    Sent: Tuesday, May 17, 2016 11:22 PM
    To: Foley, Alexander - GIS <alexander.foley@bankofamerica.com>
    Cc: Maxwell, Kyle <kmaxwell@verisign.com>; Piazza, Rich <rpiazza@mitre.org>; Gary.Katz.ctr@dc3.mil; Paul Patrick <ppatrick@isightpartners.com>; cti-stix@lists.oasis-open.org
    Subject: Re: [cti-stix] Campaigns


     
    Then lets please use it as much as possible. 








     


    Thanks,


     


    Bret



     


     


     



    Bret Jordan CISSP

    Director of Security Architecture and Standards Office of the CTO


    Blue Coat Systems



    PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050


    "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." 









     



    On May 17, 2016, at 20:07, Foley, Alexander - GIS < alexander.foley@bankofamerica.com > wrote:

     

    VERIS is amazing