Download presentation
Presentation is loading. Please wait.
Published byStanley Hodge Modified over 9 years ago
1
CTI CybOX SC Meeting www.oasis-open.org September 24, 2015
2
www.oasis-open.org Agenda CybOX Use Case Discussion CybOX 3.0 Object Discussion OASIS Work Product Status & Discussion
3
CybOX Use Cases I Support capture of atomic observable data Support malicious activity detection Support event data correlation and analysis from diverse sensors: network-based endpoint-based
4
CybOX Use Cases II Support capture of endpoint system state data PC-based BIOS state OS state, including artifacts such as: executable binary formats kernel artifacts general endpoint metadata Mobile-based Enable characterization of mobile device state Support malicious activity detection based on the above
5
CybOX Use Cases III Support capture of cyber analysis data from malware analysis filesystem-based artifacts memory-based artifacts network-based artifact digital forensics analysis network metadata filesystem analysis format-specific metadata (ie,.png,.pdf, etc) general filesystem metadata memory forensics metadata characterization of analyis tool-specific metadata
6
CybOX 3.0 Objects Refactoring and resolving existing issues with all objects is a significant undertaking Idea: focus on the core set of CybOX objects for the 3.0 release Top 20 objects from the survey Take an 80/20 approach to immediately improve things for most people's use cases Focus on refactoring additional subsets in future releases, i.e.: 3.1: endpoint-specific artifacts 3.2: network-specific artifacts … Users dependent on objects pending refactoring can continue to use the 2.1.x data models http://cyboxproject.github.io/cybox3.0/
7
Points for consideration... Notion of CybOX as the Dewey Decimal System of pwnage If CybOX can characterize bad state, it can also be used to represent healthy baseline state! Rome wasn't built in a day. Hubris doesn't lead to success. Does it really make sense to create XML-based representations of: pcap NetFlow protocol analyzer data YARA etc...? Maybe it makes more sense to encode higher-level metadata in CybOX and embed the rest base64-encoded in a field?
8
Points for consideration... Constrain our focus for success! Forest first, then the trees!
9
So we've been playing with Graphviz...
10
CybOX 2.1 Objects
11
CybOX 3.0 “Core” Objects I (notional)
12
CybOX 3.0 “Core” Objects II (notional)
13
Graphviz analysis, next steps We're finalizing the 2.1 and proposed 3.0 analysis. Once initial analysis completed, both the source and rendered graphs will be posted to http://cyboxproject.github.io/cybox3.0/ for comments and collaboration.http://cyboxproject.github.io/cybox3.0/
14
OASIS Work Product Discussion CybOX 2.1.1 Multi-part specification Part 1: Overview Part 2: Common Part 3: Core Part 4: Default Extensions Part 5: Default Vocabularies Part 6: UML Model Parts 7-94: Objects XML Binding Specification
15
Next meeting Thursday, October 29th @ 1:00pm EDT
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.