mitre-attack / mitre-attack/attack-stix-data

Suggestion to Replace MITRE Asset with Infrastructure Object

Open
#48 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
671
Forks
145
PR merge metrics
No merged PRs in 30d

Description

Hi there!

I'm looking at the Infrastructure SDO and its definition and it seems similar to MITRE Asset object.

The Infrastructure SDO represents a type of TTP and describes any systems, software services and any associated physical or virtual resources intended to support some purpose (e.g., C2 servers used as part of an attack, device or server that are part of defense, database servers targeted by an attack, etc.). While elements of an attack can be represented by other SDOs or SCOs, the Infrastructure SDO represents a named group of related data that constitutes the infrastructure.

Link for reference: https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html#_jo3k1o6lr9

So, here’s my thought: we have this custom object called MITRE Asset, right? But when I look at what Infrastructure covers, it seems like it’s already doing what MITRE Asset is supposed to do. It feels a bit like we’re doubling up on the same kind of information.

My suggestion is that maybe we could consider using just Infrastructure instead of MITRE Asset. This could help simplify things and keep our data model more streamlined. What do you think?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by comparing the MITRE Asset custom object with the Infrastructure SDO definition in the linked STIX v2.1 specification. Determine whether Infrastructure can fully replace MITRE Asset and document the data-model changes and migration scope; no repository files or tests are identified in the issue.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.