Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Suggestion to Replace MITRE Asset with Infrastructure Object #48

Open
SYNchroACK opened this issue Jun 30, 2024 · 0 comments
Open

Suggestion to Replace MITRE Asset with Infrastructure Object #48

SYNchroACK opened this issue Jun 30, 2024 · 0 comments

Comments

@SYNchroACK
Copy link

Hi there!

I'm looking at the Infrastructure SDO and its definition and it seems similar to MITRE Asset object.

The Infrastructure SDO represents a type of TTP and describes any systems, software services and any associated physical or virtual resources intended to support some purpose (e.g., C2 servers used as part of an attack, device or server that are part of defense, database servers targeted by an attack, etc.). While elements of an attack can be represented by other SDOs or SCOs, the Infrastructure SDO represents a named group of related data that constitutes the infrastructure.

Link for reference: https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html#_jo3k1o6lr9

So, here’s my thought: we have this custom object called MITRE Asset, right? But when I look at what Infrastructure covers, it seems like it’s already doing what MITRE Asset is supposed to do. It feels a bit like we’re doubling up on the same kind of information.

My suggestion is that maybe we could consider using just Infrastructure instead of MITRE Asset. This could help simplify things and keep our data model more streamlined. What do you think?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant