← Prev in month
← Prev in thread
Public comments on CTI TC by Cory Casanave
Addendum on OMG Threat Modeling: best (recent) article I found so far: "Advances in Operational Risk and Threat Modeling" Gerald Beuchelt, Cory Casanave, Vijay Mehra Pages 33-44 in National Cybersecurity Institute Journal 1/3 http://ncij.excelsior.edu/vol-1-no-3/ http://www.nationalcybersecurityinstitute.org/journal http://ncij.excelsior.edu/ File attached: OMG-National-Cybersecurity-Institute-Journal-Cory.pdf - rcc =========== Earlier: (with image files attached) OMG SysA Meeting https://beuchelt.com/blog/category/interoperability/ OMG-Threat-Modeling-and-Sharing-20140326.pptx In general, the conceptual model we are working on will describes the abstract concepts within the overall problem space of threat and risk modeling. With such a model, semantic mappings to specific logical models (such as the the cyber-domain specific model that STIX is creating) can be generated. This will allow the automated generation of ‘semantic glue’, i.e. mappings that transform different representations of data. The benefit of using a conceptual model lies in the fact that it is independent of the respective underlying logical models for each domain or protocol. This approach has been around for some time now, but it is currently formalized in the Semantic Information Modeling for Federation (SIMF) project. Threat and Risk Community http://threatrisk.org/drupal/ http://www.omg.org/hot-topics/threat-modeling.htm ---------- Forwarded message ---------- From: Robin Cover < > Date: Tue, Apr 21, 2015 at 1:14 PM Subject: Re: [staff-bizdev] Public comments on CTI TC by Cory Casanave To: Chet Ensign < > Cc: Staff BizDev < >, Robin Cover < > On Tue, Apr 21, 2015 at 12:29 PM, Chet Ensign < > wrote: Nope, clearly he just sent it to Carol. > Is Cory outside OASIS and thus unable to send to oasis-charter-discuss@? I think we want to get it posted there one way or the other... Cory Casanave (and seven others from Model Driven Solutions) have been in our CRM since 2010, but the company has never been motivated to join OASIS. OMG is their stomping ground, and Cory is one of the leads for OMG's " Threat Modeling" initiatives. I sent a summary last year [1]. Not sure Model Driven Solutions is likely to join OASIS soon. ;-) - rcc [1] sent to Staff in 2014-09 https://lists.oasis-open.org/archives/staff-bizdev/201409/msg00007.html Cory Casanave (President and CEO: Model Driven Solutions) "As some of you may know, we are working on data federation within the threat & risk space, including federation with STIX . This is being done as an OMG standards effort based on using a conceptual model as a pivot point between data structures. We have utilized the STIX schema (in a UML form) as the basis for the STIX mapping. Of course, the proof is in mapping real data. We would be very interested in having some STIX data to work with. Are there any unrestricted sources of such data? Of course, we are most interested in data that properly uses the STIX structures -- however we are not as concerned with it being 'good data'." General information on the effort can be found here: https://github.com/omg-threat-modeling/phase1 OMG Threat Modeling (Cyber Domain PIM, STIX and NIEM PSM) https://github.com/omg-threat-modeling/phase1/blob/master/LICENSE Apache License - Version 2.0, January 2004 http://www.apache.org/licenses/ OMG Threat Modeling Phase1 NEWS: The Object Management Group ( omg.org ) in collaboration with government, industry and academic organizations has initiated a standards activity for an operational threat and risk model (AKA Ontology) intended to federate multiple formats, technologies and use cases to enable a fusion of information in support of proactive and reactive threat/risk assessment, analytics, mitigation and information sharing. The focus of this effort is fusion of threat and risk information across physical, criminal and cyber concerns. Some of the data structures we are federating include the STIX, NIEM and CAP standards. As an OMG standards effort a team has formed to respond to this RFP with a specification for a proposed standard. This repository provides tghe foundation for the evolving specification. The specific RFP is available here: http://www.omg.org/cgi-bin/doc.cgi?sysa/2014-6-17 The workgroup meets each week and at OMG meetings. This submission team is reaching out to industry experts to participate, particularly vendors, researchers and organizations with critical threat/risk needs. Please contact us if you are interested in joining us. Most of the work will be conducted through an OMG email list: . For questions, please contact . The current Meeting Schedule is here: https://github.com/omg-threat-modeling/phase1/wiki Also, please check out Project Interoperatbility at http://project-interoperability.github.io/ . This project is spearheaded by PM-ISE to improve overall interoperability for information shareing. All information posted to this site must be unclassified and unrestricted. The site is open to all. Information derived from posted information may be utilized in the OMG specification being developed for threats and risks. Unless otherwise specified, all information posted to this site shall be deemed licensed under the Create Commons license. Reference Standards for Phase 1 - CWE Updated models and CWE Reference - FIBO EDM Links - ICS-CERT External references and connections - NIST CEW 3 Presentation - OMG Added model working directory - SACM Posted SACM standard [OMG Structured Assurance Case Metamodel (SACM)] - Veris With changes, as sent to OMG 4 months ago - stix_v1.1 Upload of STIX 1.1 On Tue, Apr 21, 2015 at 11:43 AM, Robin Cover < > wrote: I didn't see the following text on the oasis-charter-discuss list (maybe missed it)... Thought these comments from Cory Casanave and the OMG would be of interest to the community. Patrick Maroney Office: (856)983-0001 Cell: (609)841-5104 From: Cory Casanave < > Date: Tuesday, April 21, 2015 at 10:39 AM To: " " < > Cc: " ' '" < > Subject: [Threat-Risk-Community] Comments on: Oasis Cyber Threat Intelligence (CTI) Technical Committee The following are comments on the Oasis “Cyber Threat Intelligence (CTI) Technical Committee” draft charter from Cory Casanave of Model Driven Solutions. Basis of interest: Model Driven Solutions is a submitter to the OMG Operational Threat & Risk Model RFP ( http://www.omg.org/cgi-bin/doc.cgi?sysa/2014-6-17 ), which is referenced in the draft CTI charter ( https://lists.oasis-open.org/archives/members/201504/msg00006.html ). There is substantial overlap but some important differences in the intent and substance of the OMG standards effort and that as proposed by the Oasis CTI TC. These comments are intended to help both organizations develop standards that are in the best interests of the community of vendors, consumers and other stakeholders. Of particular importance is making sure that Cyber threats and risks are not made yet another “stovepipe” as we are faced with a world where the boundaries between the physical and cyber world are porous and an estimated 80% of threats are blended between cyber and physical. Protecting our citizens, property and critical infrastructure requires that we can “connect the dots” between all hazards and all risks from threat actors, system failures and natural disasters. This federation of information must happen at “machine speed” to enable effective and responsive analytics and information sharing to prevent and mitigate the impacts of threats and risks. The STIX /TAXII/Cybox schema represent important work within the cyber community for cyber threats and risks. It is appropriate and necessary that the Cyber community have detailed and specific exchange formats that are tuned to the needs of cyber professionals. The same is true of other domains and “verticals” such as law enforcement, critical infrastructure protection, terrorism, biological, nuclear, and responses to natural disasters. Yet these domains and the related organizations must work closely together, often in difficult and unexpected situations. To enable the focus needed for specific communities while preserving cross-community collaboration, information federation and information sharing the OMG threat & Risk model initiative is creating a standard UML conceptual model that federates the concepts from these multiple domains, based on the existing work such as is found in the STIX /TAXII/Cybox (as well as others). This UML model will then be mapped to the existing exchange formats, such as STIX (and others), to provide the basis for semantic and syntactic information federation, analytics and sharing. The OMG initiative is not defining any new data schema – we have enough. The RFP has been issued and initial submissions will be presented in May. The submission team is open (see http://www.threatrisk.org ) and STIX community members have monitored our progress. To relate the two efforts: The OMG effort is broader and shallower where as the CTI effort is deeper and narrower. Both efforts intend on providing UML models of the concepts (this fact is not explicit in the charter but has been made public on the STIX lists). The CTI effort is also specifying exchange data structures such as XML schema, the OMG effort is not defining any new schema but is mapping between schema (standard, community or proprietary). However, schema could be generated from the UML models. In that the OMG effort has STIX /TAXII/Cybox as a normative input and mapping the proper representation of the broad threat/risk and general concepts within STIX /TAXII/Cybox are or will be defined in the OMG conceptual model. Approximately 75% of this model has a direct correlation to STIX /TAXII/Cybox such that the STIX /TAXII/Cybox Cyber specific concepts could be considered an extension to the OMG conceptual model. While STIX /TAXII/Cybox are clearly focused on Cyber, a reading of the charter where the term “Cyber” was removed would correspond almost directly to the intent of the OMG threat/risk effort. What this suggests is that much of what is needed is in fact cross domain and not specific to Cyber. If not specific to Cyber there is an almost complete overlap with the OMG effort. It would be confusing, a waist of effort and a disservice to both vendors and our defenders to come out with redundant standards covering almost the same space. As stewards of standards it is our responsibility to make sure such efforts are coordinated, complementary and properly scoped. It is our position that these efforts must be complementary by charter and that the following be included in that charter: · That the CTI effort will include a UML representation of Cyber concepts (Our understanding is that this is the current intent) · That there will be an explicit mapping of this model to technology specific schema, such as XML schema (Our understanding is that this is the current intent) · That the CTI UML representation be an extension of the OMG operational threat and risk model (This is an additional constraint) · That the OMG effort must include a foundation appropriate for extension to the CTI model (A current requirement of the RFP) Cross membership and cross participation will ensure that these requirements are both met and that both efforts meet their objectives. Based on the substantial time we have spent evaluating both models such collaboration and integration is practical and would benefit both efforts. Regards, Cory Casanave CEO, Model Driven Solutions BoD, Object Management Group Threat/Risk submitter The above comments are from Cory Casanave representing Model Driven Solutions and do not necessarily represent the position of the other contributors and submitters to the OMG effort. Other stakeholders are encouraged to also submit comments to Oasis via . -- Robin Cover OASIS, Director of Information Services Editor, Cover Pages and XML Daily Newslink Email: Staff bio: http://www.oasis-open.org/people/staff/robin-cover Cover Pages: http://xml.coverpages.org/ Newsletter: http://xml.coverpages.org/newsletterArchive.html Tel: +1 972-296-1783 -- /chet [§] ---------------- Chet Ensign Director of Standards Development and TC Administration OASIS: Advancing open standards for the information society http://www.oasis-open.org Primary: +1 973-996-2298 Mobile: +1 201-341-1393 Check your work using the Support Request Submission Checklist at http://www.oasis-open.org/committees/download.php/47248/tc-admin-submission-checklist.html TC Administration information and support is available at http://www.oasis-open.org/resources/tcadmin Follow OASIS on: LinkedIn: http://linkd.in/OASISopen Twitter: http://twitter.com/OASISopen Facebook: http://facebook.com/oasis.open -- Robin Cover OASIS, Director of Information Services Editor, Cover Pages and XML Daily Newslink Email: Staff bio: http://www.oasis-open.org/people/staff/robin-cover Cover Pages: http://xml.coverpages.org/ Newsletter: http://xml.coverpages.org/newsletterArchive.html Tel: +1 972-296-1783 -- Robin Cover OASIS, Director of Information Services Editor, Cover Pages and XML Daily Newslink Email: Staff bio: http://www.oasis-open.org/people/staff/robin-cover Cover Pages: http://xml.coverpages.org/ Newsletter: http://xml.coverpages.org/newsletterArchive.html Tel: +1 972-296-1783 Attachment: OMG-Threat-Modeling-and-Sharing-20140326.pptx Description: application/vnd.openxmlformats-officedocument.presentationml.presentation Attachment: OMG-Model-Overview-20140326.jpg Description: JPEG image Attachment: OMG-Generic-Threat-Modeling-20140326.png Description: PNG image Attachment: OMG-National-Cybersecurity-Institute-Journal-Cory.pdf Description: Adobe PDF document
← Prev in month
← Prev in thread