A cybersecurity analyst is establishing an automated intelligence pipeline to ingest threat indicators from external industry peers. The analyst needs a standardized language format to represent attack patterns, indicators of compromise, and threat actor tactics in a structured, machine-readable format, independent of how the data is transmitted across the network. Which of the following standards should the analyst implement for data representation?
- STIX (Structured Threat Information Expression)Cevap
- BTAXII (Trusted Automated Exchange of Intelligence Information)
- CISAC (Information Sharing and Analysis Center)
- DCVSS (Common Vulnerability Scoring System)
Cevap
STIX (Structured Threat Information Expression) is the correct standard because it provides a structured, machine-readable language format for specifying cyber threat intelligence.
STIX (Structured Threat Information Expression) is an open-standardized language designed specifically for describing cyber threat information in a structured, machine-readable JSON format. It allows organizations to share threat context, including indicators of compromise, threat actors, campaigns, and attack patterns, independently of the underlying network protocol used for transport.
Adım Adım Çözüm
Anahtar Kavram
STIX vs TAXII Standards in Cyber Threat Intelligence