mitre-attack / attack-datasources

This content is analysis and research of the data sources currently listed in ATT&CK.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Support NIDS and WAF via new 'network traffic content' relationship

hxnoyd opened this issue · comments

Hello.

With the new DS structure NIDS and WAF are no longer available. A new relationship could be created in order to improve the mapping with alert related events:

  • Data source: Network Traffic
  • Data component: network traffic content
  • Relationship:
  - source_data_element: network traffic        
    relationship: triggered        
    target_data_element: alert

Thanks in advance.

Hey @hxnoyd!

Hmm yeah I see what you are getting at. I'm not sure this is something we would add though, since alert could apply as a relationship to (almost) every DS in the same fashion, since the level of abstraction is related to what kind of data (elements) are we referring to.

We'll think about it more, and definitely share more thoughts in opinions. Thanks!

Circling back to this, we have published the first release of the data sources - https://attack.mitre.org/datasources/ but will consider this feedback for future releases. I'll reach out to directly as needed.

Thanks again!