Download presentation
Presentation is loading. Please wait.
Published bySandra Norman Modified over 9 years ago
1
CTI CybOX SC Meeting www.oasis-open.org December 17, 2015
2
Agenda Recent Discussion Recap Device/System Object Refactoring Discussion Extensions Draft Face to Face Agenda OASIS Work Product Update
3
Recent Discussion Recap I File Object Refactoring File metadata properties More explicit directory characterization FieldTypeMultiplicityDescription is_directoryboolean1 A required flag that indicates whether the file object instance represents a directory (if TRUE) or a file (if FALSE). file_namestring0-1 The name of the file, including its extension (if known) but excluding its path. This field may only be included ONLY IF the is_directory property is set to FALSE. file_pathFilePath0-1 The path to the file on the file system, excluding its name and extension. If this field is included without the file_name field, the file object instance specifies a directory. FieldTypeMultiplicityDescription extension_typestring1 Specifies the type of this extension; required and MUST be set to 'FileMetadataExtension' mime_typestring0-1 The MIME type name from the IANA media type registry (http://www.iana.org/assignments/media-types/media-types.xhtml) specified for the file, e.g., "msword".http://www.iana.org/assignments/media-types/media-types.xhtml
4
Recent Discussion Recap II Capture of Analytical Observations E.g., file masquerading “malware.exe.txt” Is this something that belongs in CybOX? is_masqueraded = true Or should CybOX only support “the facts” that support the analytical observation, and leave the observations to be captured elsewhere? file_name = “malware.exe.txt” mime_type = “vnd.microsoft.portable-executable”
5
Device/Sys. Object Refactoring I Current State (CybOX 2.1) OS Property Device Property
6
Device/Sys. Object Refactoring II Proposed Refactoring (straw man)
7
Face to Face Agenda (draft) Patterning refactoring Object refactoring Focus on any open questions for each CybOX Core Pruning Making a more lightweight, focused CybOX Core CybOX 3.0 “end state” Overlapping STIX/CybOX issues Design philosophy First-class relationships Required IDs Etc.
8
OASIS Work Product Update CybOX 2.1.1 90 specifications out of 94 reviewed and edited https://github.com/CybOXProject/specifications/tree/master/documents ETA: Late December
9
Next Meeting Thursday, January 28 th @ 10:00am ET
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.