
क्यूरेटेड JSON ऑब्जेक्ट टेम्पलेट्स जो संरचित थ्रेट इंटेलिजेंस साझाकरण और इंटरऑपरेबल IOC एक्सचेंज के लिए MISP विशेषताओं और संबंध प्रकारों को परिभाषित करते हैं।

MISP ऑब्जेक्ट MISP प्रणाली में उपयोग किए जाते हैं और अन्य सूचना साझाकरण उपकरणों द्वारा भी उपयोग किए जा सकते हैं। MISP ऑब्जेक्ट विशेषताओं के उन्नत संयोजनों को सक्षम करने के लिए MISP विशेषताओं के अतिरिक्त हैं। इन ऑब्जेक्ट्स और उनसे जुड़ी विशेषताओं का निर्माण वास्तविक साइबर सुरक्षा उपयोग-मामलों और सूचना साझाकरण में मौजूदा प्रथाओं पर आधारित है।
बेझिझक MISP में शामिल करने के लिए अपना स्वयं का MISP ऑब्जेक्ट टेम्पलेट प्रस्तावित करें। यह प्रणाली misp-taxonomies के समान है, जहाँ कोई भी व्यक्ति सॉफ़्टवेयर में संशोधन किए बिना MISP में शामिल करने के लिए अपने स्वयं के ऑब्जेक्ट का योगदान कर सकता है।
{ "attributes": { "domain": { "categories": [ "Network activity", "External analysis" ], "description": "Domain name", "misp-attribute": "domain", "multiple": true, "ui-priority": 1 }, "first-seen": { "description": "First time the tuple has been seen", "disable_correlation": true, "misp-attribute": "datetime", "ui-priority": 0 }, "ip": { "categories": [ "Network activity", "External analysis" ], "description": "IP Address", "misp-attribute": "ip-dst", "multiple": true, "ui-priority": 1 }, "last-seen": { "description": "Last time the tuple has been seen", "disable_correlation": true, "misp-attribute": "datetime", "ui-priority": 0 }, "port": { "categories": [ "Network activity", "External analysis" ], "description": "Associated TCP port with the domain", "misp-attribute": "port", "multiple": true, "ui-priority": 1 }, "registration-date": { "description": "Registration date of domain", "disable_correlation": false, "misp-attribute": "datetime", "ui-priority": 0 }, "text": { "description": "A description of the tuple", "disable_correlation": true, "misp-attribute": "text", "ui-priority": 1 } }, "description": "A domain and IP address seen as a tuple in a specific time frame.", "meta-category": "network", "name": "domain-ip", "required": [ "ip", "domain" ], "uuid": "43b3b146-77eb-4931-b4cc-b66c60f28734", "version": 8 }
A MISP ऑब्जेक्ट को एक साधारण JSON फ़ाइल में वर्णित किया जाता है जिसमें निम्नलिखित तत्व होते हैं।
* **name** आपके ऑब्जेक्ट का नाम है।
* **meta-category** वह श्रेणी है जिसमें ऑब्जेक्ट आता है। (जैसे file, network, financial, misc, internal...)
* **description** ऑब्जेक्ट विवरण का सारांश है।
* **version** दशमलव मान के रूप में संस्करण संख्या है।
* **required** एक array है जिसमें ऑब्जेक्ट का वर्णन करने के लिए आवश्यक न्यूनतम attributes शामिल हैं।
* **requiredOneOf** एक array है जिसमें वे attributes शामिल हैं जहाँ ऑब्जेक्ट का वर्णन करने के लिए कम से कम एक मौजूद होना चाहिए।
* **attributes** एक और JSON ऑब्जेक्ट रखता है जो ऑब्जेक्ट को बनाने वाले सभी attributes की सूची देता है।
प्रत्येक attribute में MISP में मौजूदा attribute परिभाषा को संदर्भित करने के लिए एक **misp-attribute** संदर्भ होना चाहिए (MISP attribute प्रकार case-sensitive होते हैं)।
एक array **categories** का उपयोग यह वर्णन करने के लिए किया जाना चाहिए कि attribute किन श्रेणियों में है। **ui-priority**
attribute के उपयोग की आवृत्ति का वर्णन करता है। यह केवल सबसे अधिक उपयोग किए जाने वाले attributes को प्रदर्शित करने में मदद करता है और
उन्नत उपयोगकर्ताओं को उनके कॉन्फ़िगरेशन के आधार पर सभी attributes दिखाने की अनुमति देता है। एक वैकल्पिक **multiple** फ़ील्ड
को true पर सेट किया जाना चाहिए यदि ऑब्जेक्ट में एक ही key के कई तत्वों का उपयोग किया जा सकता है। एक वैकल्पिक **values_list**
जहाँ इस सूची के मानों को attribute के मान के रूप में चुना जा सकता है। एक वैकल्पिक **sane_default** जहाँ यह मानों की सूची किसी attribute के लिए
संभावित रूप से सही डिफ़ॉल्ट की अनुशंसा करती है। एक वैकल्पिक **disable_correlation** बूलियन फ़ील्ड किसी विशिष्ट attribute के लिए correlation को अक्षम करने का सुझाव देने हेतु। एक वैकल्पिक **to_ids** बूलियन फ़ील्ड किसी attribute के IDS फ़्लैग को अक्षम करने के लिए।