SHARING CYBER THREAT INTELLIGENCE JUST GOT A LOT EASIER www.oasis-open.org SHARING CYBER THREAT INTELLIGENCE JUST GOT A LOT EASIER
STIX 2.0 – Where we are TC has voted to approve a Committee Specification Draft & will open a public review Community is already developing documentation, tooling, and is working on 2.1
STIX 2.0 …is JSON, not XML …has improved patterning …is smaller and more focused …has a complete specification …is explicitly nodes and edges …is true to its roots
Before and After: JSON Before After
Before and After: Patterning
STIX is true to its roots Before After
STIX 2.1: Where we’re going www.oasis-open.org STIX 2.1: Where we’re going Filling in the blanks Malware, Course of Action Expanding to new use cases Incident, Infrastructure Focusing on the community Confidence, Opinion, Intel Notes
…uses native HTTP features …is HTTPS by default www.oasis-open.org TAXII 2.0 …uses native HTTP features …is HTTPS by default …has channels & collections …is built to support trust groups