CybOXProject / schemas

CybOX Schemas and Schema Development
42 stars 17 forks source link

Categorizing/Grouping Objects #373

Open ikiril01 opened 9 years ago

ikiril01 commented 9 years ago

We should consider ways to categorize/group CybOX Objects, to make it easier for content producers and consumers to define which set(s) of Objects they support.

One possibility is to use tags - from @athiasjerome:

"While categorization, grouping or trees of objects is difficult due to numerous potential use cases, I found internal tagging of the objects an interesting approach. (E.g. With keywords like reverse engineering, forensics, pcap, etc.) It could help identifying use cases, and attract potential new interests/adopters. Furthermore, tagging ( or relationships ;)) with common tools, and tools ouputs mapping with the objects/properties could also help interest/adoption, and while showing quality (RFC based, etc.) and completeness (or not) of the objects, would help to build bindings/convention tools. E.g. Sysinternals2CybOX, wireshark2CybOX, etc."

athiasjerome commented 9 years ago

SP 800-53 Families can be used for tagging, if community finds an interest. It is not very granular, but helps for some use cases.