Soru

Zorluk: ZorThreat Intelligence Sources and Research

A security engineering lead at a global telecommunications provider is building an automated workflow to ingest threat indicators into an enterprise SIEM. The threat intelligence vendor supplies standardized, machine-readable data structures representing threat actor TTPs, attack vectors, and observable indicators. To enable automated client-server polling and pushing of these structured data packages over HTTPS, which protocol must be deployed at the application transport layer?

  1. TAXII (Trusted Automated eXchange of Intelligence Information)Cevap
  2. B
    STIX (Structured Threat Information eXpress)
  3. C
    ISAC (Information Sharing and Analysis Center)
  4. D
    CVE (Common Vulnerabilities and Exposures)

Cevap

TAXII (Trusted Automated eXchange of Intelligence Information) is the transport protocol required to exchange threat intelligence over HTTPS.
The Trusted Automated eXchange of Intelligence Information (TAXII) is explicitly designed as the application-layer transport protocol that specifies services and message exchanges to deliver Structured Threat Information eXpress (STIX) threat intelligence over HTTPS.

Adım Adım Çözüm

1
Differentiate between threat data representation models and transport protocols
Identified STIX as the structured data format (content language) and TAXII as the container protocol (transport mechanism).
Machine-readable threat intelligence architectures pair STIX for formatting with TAXII for secure network transport.
2
Evaluate the functional requirement specified in the scenario
The requirement calls specifically for client-server polling and pushing over HTTPS.
TAXII defines REST API web services and messaging specs over HTTPS to deliver automated feeds to SIEM/SOAR platforms.

Anahtar Kavram

STIX vs. TAXII Architecture in Automated Threat Intelligence
Bu soruyu puanla