Presentation is loading. Please wait.

Presentation is loading. Please wait.

CTI CybOX SC Meeting www.oasis-open.org December 17, 2015.

Similar presentations


Presentation on theme: "CTI CybOX SC Meeting www.oasis-open.org December 17, 2015."— Presentation transcript:

1 CTI CybOX SC Meeting www.oasis-open.org December 17, 2015

2 Agenda Recent Discussion Recap Device/System Object Refactoring Discussion Extensions Draft Face to Face Agenda OASIS Work Product Update

3 Recent Discussion Recap I File Object Refactoring File metadata properties More explicit directory characterization FieldTypeMultiplicityDescription is_directoryboolean1 A required flag that indicates whether the file object instance represents a directory (if TRUE) or a file (if FALSE). file_namestring0-1 The name of the file, including its extension (if known) but excluding its path. This field may only be included ONLY IF the is_directory property is set to FALSE. file_pathFilePath0-1 The path to the file on the file system, excluding its name and extension. If this field is included without the file_name field, the file object instance specifies a directory. FieldTypeMultiplicityDescription extension_typestring1 Specifies the type of this extension; required and MUST be set to 'FileMetadataExtension' mime_typestring0-1 The MIME type name from the IANA media type registry (http://www.iana.org/assignments/media-types/media-types.xhtml) specified for the file, e.g., "msword".http://www.iana.org/assignments/media-types/media-types.xhtml

4 Recent Discussion Recap II Capture of Analytical Observations E.g., file masquerading “malware.exe.txt” Is this something that belongs in CybOX? is_masqueraded = true Or should CybOX only support “the facts” that support the analytical observation, and leave the observations to be captured elsewhere? file_name = “malware.exe.txt” mime_type = “vnd.microsoft.portable-executable”

5 Device/Sys. Object Refactoring I Current State (CybOX 2.1) OS Property Device Property

6 Device/Sys. Object Refactoring II Proposed Refactoring (straw man)

7 Face to Face Agenda (draft) Patterning refactoring Object refactoring Focus on any open questions for each CybOX Core Pruning Making a more lightweight, focused CybOX Core CybOX 3.0 “end state” Overlapping STIX/CybOX issues Design philosophy First-class relationships Required IDs Etc.

8 OASIS Work Product Update CybOX 2.1.1 90 specifications out of 94 reviewed and edited https://github.com/CybOXProject/specifications/tree/master/documents ETA: Late December

9 Next Meeting Thursday, January 28 th @ 10:00am ET


Download ppt "CTI CybOX SC Meeting www.oasis-open.org December 17, 2015."

Similar presentations


Ads by Google