IT Security 101: the Structured Threat Information Expression (STIX) Standard
Introduction
In this installment of ITSEC101, I will discuss a useful standard to assist defenders with sharing threat intelligence, the Structured Threat Information Expression (STIX) standard.
STIX defines a way to structure threat intelligence data, making it easier to analyze and share the information. It was originally developed by the US Dept. of Homeland Security (DHS), and was transitioned in collaboration with MITRE to the Organization for the Advancement of Structured Information Standards (OASIS) in 2015.
As of the writing of this article, the current version is STIX 2.1.
STIX Explained
STIX is a standard lexicon for describing cyber threat intelligence (CTI) types and the relationships between them. Its purpose is to assist defenders with effectively detecting, analyzing and sharing cyber threats.
STIX uses JSON for formatting its data, allowing it to be easily shared and processed by disparate systems.
Version 2.1 is comprised of eighteen STIX Domain Objects (SDOs) that represent the CTI types, and two STIX Relationship Objects (SROs) that are used to describe the connections between them.
To help explain SDOs and SROs, the below table lists each with their description.
The SROs
The SROs
STIX in Action
Here is a simple, fictitious example to illustrate how SDOs and SROs relate.
Here it is represented in STIX JSON format. Note the use of UUIDs represented by a string of letters, numbers and hyphens.
This JSON block represents the Threat Actor SDO:
This JSON block represents the Malware SDO:
This JSON block represents the Relationship SRO:
Conclusion
STIX offers a standardized framework to describe real-world cyber threats in a format that is easy to analyze and share. It is designed to be flexible and can further be extended for additional functionality, without losing the base structure. It is another useful resource that allows defenders to identify threats, and collaborate with outside organizations to help strengthen the resiliency of the entire cyber defense community.
Daily Cuppa
Today’s cup of tea is Organic Vanilla Rooibos provided by Equal Exchange. Organic, fare trade, and full of delicious aromas and flavor.
If you found this article useful, or enjoy the site in general, feel free to buy the author a cup of tea.
The author is also available for work.