Re: [cti] Re: [EXT] [cti] Location as a Top-Level SDO

From
Bret Jordan <>
Date
2017-06-12T03:56:45+00:00
ID
Thread
Re: [cti] Re: [EXT] [cti] Location as a Top-Level SDO
Keep in mind the sure amount of overhead on the wire and in data systems to do this...  You would have to have a serious compelling argument to offset the extra volume of data.  For example:

{

  "type": "threat-actor",

  ...,

  "region": "Eastern Europe"

}

vs

[

{

  "type": "threat-actor",

  ...

},

{

  "type": "location",

  ...,

  "region": "Eastern Europe"

},

  {

    "type": "relationship",

    "id": "relationship--57b56a43-b8b0-4cba-9deb-34e3e1faed9e",

    "created": "2016-05-12T08:17:27.000Z",

    "modified": "2016-05-12T08:17:27.000Z",

    "relationship_type": "uses",

    "source_ref": "threat-actor--0c7e22ad-b099-4dc3-b0df-2ea3f49ae2e6",

    "target_ref": "location--7e33a43e-e34b-40ec-89da-36c9bb2cacd5"

  }

]

Bret

From:  <> on behalf of Jason Keirstead <>

Sent: Sunday, June 11, 2017 7:35:18 PM

To: 

Cc: Bret Jordan; ; ; 

Subject: Re: [cti] Re: [EXT] [cti] Location as a Top-Level SDO

 

You are assuming that we don't create a repository of "standard" location SDOs for things like continent and country names - IE the things that people would want to share in the first place. Which, I don't see why we would not do this, seeing
 how we're doing it for things like CAPEC.

 

-

Jason Keirstead

STSM, Product Architect, Security Intelligence, IBM Security Systems

www.ibm.com/security

Without data, all you are is just another person with an opinion - Unknown

 

 

----- Original message -----

From: John-Mark Gurney <>

Sent by: <>

To: "Back, Greg" <>

Cc: Bret Jordan <>, "Reller, Nathan S." <>, "" <>

Subject: Re: [cti] Re: [EXT] [cti] Location as a Top-Level SDO

Date: Fri, Jun 9, 2017 8:36 PM

 

Back, Greg wrote this message on Fri, Jun 09, 2017 at 20:18 +0000:

> If Location is an SDO, does that make it possible to “move” another object by versioning the Location object? That seems like a bad idea. Especially if you effectively “move” other, unrelated objects that also refer to the same Location. Even if we did make
 Location a TLO, we would have to mandate that people update the “_ref” fields to move an SDO, not the Location itself.

>

> (I haven’t made up my mind on whether I like the Location SDO in general, just pointing out one consideration).

Interesting point.  Which effectively means that if you create a

relationship to a location, that location should be one you own, not

one that was created by someone else (unless you can trust the creator

not to do what you just described)...

This means that by definition, there will be many Location SDO's for

the same location to prevent this from happeneing...

--

John-Mark

---------------------------------------------------------------------

To unsubscribe from this mail list, you must leave the OASIS TC that

generates this mail.  Follow this link to all your TCs in OASIS at:

https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php 

 

 

--------------------------------------------------------------------- To unsubscribe from this mail list, you must leave the OASIS TC that generates this mail. Follow this link to all your TCs in OASIS at: https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php