
構造化された脅威インテリジェンスの共有と相互運用可能なIOC交換のための、MISP属性とリレーションシップタイプを定義するキュレーション済みJSONオブジェクトテンプレート。

MISPオブジェクトはMISPシステムで使用され、他の情報共有ツールでも使用できます。MISPオブジェクトは MISP属性に加えて、属性の高度な組み合わせを可能にします。これらのオブジェクトとその関連属性の作成は、 実際のサイバーセキュリティのユースケースと情報共有における既存の慣行に基づいています。
独自のMISPオブジェクトテンプレートをMISPに含めるために提案してください。このシステムは misp-taxonomies と似ており、誰でもソフトウェアを変更することなく独自のオブジェクトをMISPに含めるために貢献できます。
{ "attributes": { "domain": { "categories": [ "Network activity", "External analysis" ], "description": "Domain name", "misp-attribute": "domain", "multiple": true, "ui-priority": 1 }, "first-seen": { "description": "First time the tuple has been seen", "disable_correlation": true, "misp-attribute": "datetime", "ui-priority": 0 }, "ip": { "categories": [ "Network activity", "External analysis" ], "description": "IP Address", "misp-attribute": "ip-dst", "multiple": true, "ui-priority": 1 }, "last-seen": { "description": "Last time the tuple has been seen", "disable_correlation": true, "misp-attribute": "datetime", "ui-priority": 0 }, "port": { "categories": [ "Network activity", "External analysis" ], "description": "Associated TCP port with the domain", "misp-attribute": "port", "multiple": true, "ui-priority": 1 }, "registration-date": { "description": "Registration date of domain", "disable_correlation": false, "misp-attribute": "datetime", "ui-priority": 0 }, "text": { "description": "A description of the tuple", "disable_correlation": true, "misp-attribute": "text", "ui-priority": 1 } }, "description": "A domain and IP address seen as a tuple in a specific time frame.", "meta-category": "network", "name": "domain-ip", "required": [ "ip", "domain" ], "uuid": "43b3b146-77eb-4931-b4cc-b66c60f28734", "version": 8 }
MISPオブジェクトは、以下の要素を含む単純なJSONファイルで記述されます。
* **name** は、オブジェクトの名前です。
* **meta-category** は、オブジェクトが分類されるカテゴリです。(file、network、financial、misc、internal など)
* **description** は、オブジェクトの説明の要約です。
* **version** は、10進数値としてのバージョン番号です。
* **required** は、オブジェクトを記述するために必要な最小限の属性を含む配列です。
* **requiredOneOf** は、オブジェクトを記述するために少なくとも1つが存在する必要がある属性を含む配列です。
* **attributes** は、オブジェクトを構成するすべての属性を列挙する別のJSONオブジェクトを含みます。