mitre-attack / mitre-attack/attack-stix-data
Suggestion to Replace MITRE Asset with Infrastructure Object
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 671
- Forks
- 145
- PR merge metrics
- No merged PRs in 30d
Description
Hi there!
I'm looking at the Infrastructure SDO and its definition and it seems similar to MITRE Asset object.
The Infrastructure SDO represents a type of TTP and describes any systems, software services and any associated physical or virtual resources intended to support some purpose (e.g., C2 servers used as part of an attack, device or server that are part of defense, database servers targeted by an attack, etc.). While elements of an attack can be represented by other SDOs or SCOs, the Infrastructure SDO represents a named group of related data that constitutes the infrastructure.
Link for reference: https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html#_jo3k1o6lr9
So, here’s my thought: we have this custom object called MITRE Asset, right? But when I look at what Infrastructure covers, it seems like it’s already doing what MITRE Asset is supposed to do. It feels a bit like we’re doubling up on the same kind of information.
My suggestion is that maybe we could consider using just Infrastructure instead of MITRE Asset. This could help simplify things and keep our data model more streamlined. What do you think?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by comparing the MITRE Asset custom object with the Infrastructure SDO definition in the linked STIX v2.1 specification. Determine whether Infrastructure can fully replace MITRE Asset and document the data-model changes and migration scope; no repository files or tests are identified in the issue.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Refactor
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100