PaloAltoNetworks / minemeld-core

Engine of MineMeld
Apache License 2.0
141 stars 95 forks source link

TaxiiDataFeed fails with error on `set_id_namespace` #281

Closed jtschichold closed 6 years ago

jtschichold commented 6 years ago

This is due the upgrade of the STIX library, even if it is a minor version.

2018-06-15T13:23:33 (24179)actorbase._actor_loop ERROR: CyberSOC-taxiiDataFeed-Test - error executing ActorCommand(command='update', kwargs_={u'source': u'MISP_CyberSOC_anyEvents', u'indicator': u'https://pastebin.com/v10rKA6d', u'value': {u'confidence': 70, u'last_seen': 1529056265701L, u'misp_event_tags': [u'family:njRAT', u'type:RAT', u'platform:Windows', u'tlp:green', u'admiralty-scale:source-reliability="a"'], u'misp_event_uuid': u'5b227613-8984-408b-b375-56c5ac110002', u'type': u'URL', u'misp_attribute_uuid': u'5b227617-dfac-4d8c-89c1-55d7ac110002', u'share_level': u'green', u'sources': [u'misp.test'], u'misp_attribute_comment': u'Malware in base64', u'misp_event_org': u'CyberSOC', u'first_seen': 1529056265701L, u'misp_event_orgc': u'CyberSOC', u'misp_event_threat_level_id': u'1', u'misp_event_info': u'20180614_Rat download in base64 from pastebin', u'misp_attribute_category': u'Network activity'}})
Traceback (most recent call last):
File "/opt/minemeld/engine/0.9.48/local/lib/python2.7/site-packages/minemeld/ft/actorbase.py", line 54, in _actor_loop
method(**acommand.kwargs_)
File "/opt/minemeld/engine/0.9.48/local/lib/python2.7/site-packages/minemeld/ft/base.py", line 126, in _counter
f(self, *args, **kwargs)
File "/opt/minemeld/engine/0.9.48/local/lib/python2.7/site-packages/minemeld/ft/base.py", line 512, in update
value=fltvalue
File "/opt/minemeld/engine/0.9.48/local/lib/python2.7/site-packages/minemeld/ft/base.py", line 126, in _counter
f(self, *args, **kwargs)
File "/opt/minemeld/engine/0.9.48/local/lib/python2.7/site-packages/minemeld/ft/taxii.py", line 1628, in filtered_update
self._add_indicator(now, indicator, value)
File "/opt/minemeld/engine/0.9.48/local/lib/python2.7/site-packages/minemeld/ft/taxii.py", line 1457, in _add_indicator
stix.utils.set_id_namespace(nsdict)
AttributeError: 'module' object has no attribute 'set_id_namespace'