STIXProject / schemas

STIX Schema Development
http://stixproject.github.io/
76 stars 21 forks source link

Add Ability to Capture Threat "Score" on TTP #344

Open ikiril01 opened 9 years ago

ikiril01 commented 9 years ago

We should consider adding the ability to capture one or more threat "scores" (or levels, etc.) as part of a TTP. While this would be arbitrary and highly contextually dependent, the ability to score threats in this manner may be useful to support existing use cases, e.g., around scoring "how" malicious a particular binary is.

athiasjerome commented 9 years ago

Investigate use of Risk, Impact, Damage, Vulnerability (e.g.: CVSS) etc. scores/formulas

athiasjerome commented 9 years ago

A potential scoring methodology could be based on TARA https://www.mitre.org/publications/technical-papers/threat-assessment--remediation-analysis-tara However the Asset Classes/Categories would be difficult to manage for now