Re: [Cacao] [EXT] Re: [EXT] RE: Charter

"Jyoti Verma (jyoverma)" <jyoverma@cisco.com> Wed, 19 June 2019 16:31 UTC

Return-Path: <jyoverma@cisco.com>
X-Original-To: cacao@ietfa.amsl.com
Delivered-To: cacao@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C455F12023F for <cacao@ietfa.amsl.com>; Wed, 19 Jun 2019 09:31:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.499
X-Spam-Level:
X-Spam-Status: No, score=-14.499 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=I28Q/Yla; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=t7vizdyX
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xvfL0ipOzS9B for <cacao@ietfa.amsl.com>; Wed, 19 Jun 2019 09:31:00 -0700 (PDT)
Received: from rcdn-iport-2.cisco.com (rcdn-iport-2.cisco.com [173.37.86.73]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 124E912015D for <cacao@ietf.org>; Wed, 19 Jun 2019 09:31:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=23171; q=dns/txt; s=iport; t=1560961860; x=1562171460; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=pDD+npkRH0UUOZRM8sGh0qDdpeDHCIufVgXZ12Sg3l0=; b=I28Q/Yla+2QyW5ZWNG0IMvSLrW0CvW/uA1f3VIlUmJPRuopBnyIeQWzW lEgMN2EQ9iTeqaYfm+VfcAGldSsakcHgg33pIQmNLdl2h9rynVkMr09Qa E8LQd9DVwasXYL4EHtOsbRwA4XH+fdsgz0Juu4349ljAhyZkgen3DxoqQ Q=;
IronPort-PHdr: 9a23:5P4DkRP45EYM+iIpypol6mtXPHoupqn0MwgJ65Eul7NJdOG58o//OFDEu6w/l0fHCIPc7f8My/HbtaztQyQh2d6AqzhDFf4ETBoZkYMTlg0kDtSCDBj5Pfn0YjY/FexJVURu+DewNk0GUMs=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0BqAAAEYwpd/5ldJa1jAx0BAQUBBwUBgVMIAQsBgRQvUANqVSAECyiEFoNHA4RSig2CMiWJRY1xgS6BJANUCQEBAQwBAR8OAgEBhEACF4JBIzQJDgEDAQEEAQECAQVtijcMhUoBAQEBAxIRHQEBKgoDAQ8CAQgHBwMDAQIoAwICAh8RFAkIAgQBDQUbB4MAAYEdTQMdAQIMoFACgTiIX3GBMR+CWgEBBYUEDQuCEAmBNAGFT4YOF4FAP4ERJwwTgkw+ghqCQQkBFQgJgkMygiaLaioPgh6EdIIlhieNKj4JAoIRiyaEQYNsG4InhwaKYoMljR2JDo1ZAgQCBAUCDgEBBYFQOIFYcBVlAYJBCYI4g3CKU3KBKY5JAQE
X-IronPort-AV: E=Sophos;i="5.63,392,1557187200"; d="scan'208,217";a="580614448"
Received: from rcdn-core-2.cisco.com ([173.37.93.153]) by rcdn-iport-2.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 19 Jun 2019 16:30:20 +0000
Received: from XCH-ALN-011.cisco.com (xch-aln-011.cisco.com [173.36.7.21]) by rcdn-core-2.cisco.com (8.15.2/8.15.2) with ESMTPS id x5JGU4mO021069 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Wed, 19 Jun 2019 16:30:17 GMT
Received: from xhs-rcd-003.cisco.com (173.37.227.248) by XCH-ALN-011.cisco.com (173.36.7.21) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Wed, 19 Jun 2019 11:30:16 -0500
Received: from xhs-rcd-002.cisco.com (173.37.227.247) by xhs-rcd-003.cisco.com (173.37.227.248) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Wed, 19 Jun 2019 11:30:16 -0500
Received: from NAM01-BY2-obe.outbound.protection.outlook.com (72.163.14.9) by xhs-rcd-002.cisco.com (173.37.227.247) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Wed, 19 Jun 2019 11:30:16 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=pDD+npkRH0UUOZRM8sGh0qDdpeDHCIufVgXZ12Sg3l0=; b=t7vizdyXqYO4p9Vem38XD8PMURS5NHpEI/Hukv0qmZFumbDMgmfpwzg6qNcEcfNZxjQkHG2x1RrYW41l366FFISuffhXca9UKmLmDvVCzIhr25vP9Us0Jk2oSa41pt8mlIqk3Shqw+SwwpaUlvQqhefdTD2aFTpeeK6q/vn6Ls4=
Received: from BYAPR11MB3029.namprd11.prod.outlook.com (20.177.225.90) by BYAPR11MB2983.namprd11.prod.outlook.com (20.177.224.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1987.12; Wed, 19 Jun 2019 16:30:15 +0000
Received: from BYAPR11MB3029.namprd11.prod.outlook.com ([fe80::d87f:7f47:8482:a7ee]) by BYAPR11MB3029.namprd11.prod.outlook.com ([fe80::d87f:7f47:8482:a7ee%7]) with mapi id 15.20.1987.014; Wed, 19 Jun 2019 16:30:15 +0000
From: "Jyoti Verma (jyoverma)" <jyoverma@cisco.com>
To: Allan Thomson <athomson@lookingglasscyber.com>, Bret Jordan <jordan.ietf@gmail.com>, "mohamed.boucadair@orange.com" <mohamed.boucadair@orange.com>
CC: Bret Jordan <Bret_Jordan@symantec.com>, "cacao@ietf.org" <cacao@ietf.org>
Thread-Topic: [Cacao] [EXT] Re: [EXT] RE: Charter
Thread-Index: AQHVJeH3taRs0Jjn60yUJM0gvhHTF6aheQuAgACC9ICAAI2iAIAACogAgAAKToCAAArHgIAAF0qAgAATCoCAAAQVAIAABHCAgAAHQwCAADc5gP//nNqA
Date: Wed, 19 Jun 2019 16:30:15 +0000
Message-ID: <6CFBEDBB-66E6-4848-A7B1-1EE49C0F3757@cisco.com>
References: <BYAPR16MB30133C3DAF3CF2060CE4B565EDEA0@BYAPR16MB3013.namprd16.prod.outlook.com> <787AE7BB302AE849A7480A190F8B93302EAA890F@OPEXCAUBMA2.corporate.adroot.infra.ftgroup> <BYAPR16MB30137AC9C00633E80C7C8D65EDEA0@BYAPR16MB3013.namprd16.prod.outlook.com> <779CCF55-FABB-4BA1-9D84-1D9761A32944@tzi.org> <BYAPR16MB30139D44233E0256099264DCEDEA0@BYAPR16MB3013.namprd16.prod.outlook.com> <25088b69-1225-3f3c-b0e2-38e25f1f48fb@article19.org> <A7038D6C-C1C3-4B6A-B928-AC87F7A87AFC@gmail.com> <6130.1560896363@dooku.sandelman.ca> <634A811D-3674-42ED-A46F-9CDD8EFD5CEE@symantec.com> <787AE7BB302AE849A7480A190F8B93302EAA8FE0@OPEXCAUBMA2.corporate.adroot.infra.ftgroup> <B29832F6-8239-498C-A65D-A22B70A4A691@gmail.com> <787AE7BB302AE849A7480A190F8B93302EAA905B@OPEXCAUBMA2.corporate.adroot.infra.ftgroup> <05E3F9C3-20C6-47E4-9B68-DE9D81D9C358@lookingglasscyber.com> <787AE7BB302AE849A7480A190F8B93302EAA917C@OPEXCAUBMA2.corporate.adroot.infra.ftgroup> <92A6388D-ED3D-4B77-BA01-AE97E201681F@symantec.com> <787AE7BB302AE849A7480A190F8B93302EAA91C9@OPEXCAUBMA2.corporate.adroot.infra.ftgroup> <A8E5A7FB-F771-477C-90E5-4E2DE4FA69E6@gmail.com> <16585B06-5189-4B34-9A2C-7258B10DDD98@lookingglasscyber.com>
In-Reply-To: <16585B06-5189-4B34-9A2C-7258B10DDD98@lookingglasscyber.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/f.20.0.170309
authentication-results: spf=none (sender IP is ) smtp.mailfrom=jyoverma@cisco.com;
x-originating-ip: [2001:420:c0c8:1002::1c9]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 07406fd9-dc12-4032-f843-08d6f4d368da
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(5600148)(711020)(4605104)(1401327)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(2017052603328)(7193020); SRVR:BYAPR11MB2983;
x-ms-traffictypediagnostic: BYAPR11MB2983:
x-ms-exchange-purlcount: 3
x-microsoft-antispam-prvs: <BYAPR11MB298329A0D6689409B144B774D1E50@BYAPR11MB2983.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-forefront-prvs: 0073BFEF03
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(39860400002)(376002)(346002)(366004)(136003)(396003)(189003)(199004)(66946007)(76176011)(446003)(64756008)(73956011)(36756003)(6306002)(66556008)(99286004)(66446008)(6506007)(102836004)(71200400001)(86362001)(2501003)(68736007)(186003)(53546011)(6116002)(14454004)(6486002)(6436002)(76116006)(110136005)(58126008)(2906002)(229853002)(606006)(54906003)(33656002)(316002)(81156014)(71190400001)(81166006)(486006)(25786009)(478600001)(476003)(2616005)(236005)(53936002)(8676002)(6246003)(7736002)(5660300002)(54896002)(14444005)(46003)(11346002)(4326008)(6512007)(256004)(66476007)(8936002); DIR:OUT; SFP:1101; SCL:1; SRVR:BYAPR11MB2983; H:BYAPR11MB3029.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: fkW81KW4CQ8piRt0U6XCTEbf2QBI/k+ZVaC6nYa5tC1M9OrCy5xUBPexADlYpydjliPLxWk/fx5wTHivLpGKK6fRJaygkwbMJF9oH2zbXSmbi8Y40nvS7UXv5EB8sp04DDavz8D3AP4lbSE0oVFAM7bU16yHqKuntdHHYqsNLo5FqX5lvdfiw/TzDvfkQZY8qX8oOJXqAuOXjlX4Sy0WpTo07UA0e72TW8/eDFh8joM8ueqR0P6I/9YKszEqg2ylY3RUgTAr53gcagsvf7ezmP1g7tZRJXrV7IROoPPdE21wu6hcg/oXn3myiQKBnTSgQDVQeU/gPBMKoEf3zSR2fjIryWHgtpR4lN5DuVxv6jzKBvBycSfb5cYXWraI/oPJYb8p+Fa4C8A+HWzHvDuqhcKo3s3AJcj2gCVSDyY2rRw=
Content-Type: multipart/alternative; boundary="_000_6CFBEDBB66E64848A7B11EE49C0F3757ciscocom_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 07406fd9-dc12-4032-f843-08d6f4d368da
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Jun 2019 16:30:15.2713 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: jyoverma@cisco.com
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR11MB2983
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.21, xch-aln-011.cisco.com
X-Outbound-Node: rcdn-core-2.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/cacao/u8dtFxJ5mrOoPkKr2cQKREkLQD4>
Subject: Re: [Cacao] [EXT] Re: [EXT] RE: Charter
X-BeenThere: cacao@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Collaborative Automated Course of Action Operations <cacao.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cacao>, <mailto:cacao-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cacao/>
List-Post: <mailto:cacao@ietf.org>
List-Help: <mailto:cacao-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cacao>, <mailto:cacao-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 19 Jun 2019 16:31:03 -0000

+1 on JSON being mandatory here.

Thanks,
Jyoti

From: Cacao <cacao-bounces@ietf.org> on behalf of Allan Thomson <athomson@lookingglasscyber.com>
Date: Wednesday, June 19, 2019 at 8:25 AM
To: Bret Jordan <jordan.ietf@gmail.com>, "mohamed.boucadair@orange.com" <mohamed.boucadair@orange.com>
Cc: Bret Jordan <Bret_Jordan@symantec.com>, "cacao@ietf.org" <cacao@ietf.org>
Subject: Re: [Cacao] [EXT] Re: [EXT] RE: Charter

JSON is a must.

Anything else imo is a nice-to-have.

Most products exchanging intel (and playbooks could be considered as aspect of intel) are doing that using JSON.

There are other translations such as protobufs…etc. STIX2 models intel using JSON not anything else.

Allan Thomson
CTO (+1-408-331-6646)
LookingGlass Cyber Solutions<http://www.lookingglasscyber.com/>

From: Bret Jordan <jordan.ietf@gmail.com>
Date: Wednesday, June 19, 2019 at 5:07 AM
To: "mohamed.boucadair@orange.com" <mohamed.boucadair@orange.com>
Cc: Bret Jordan <Bret_Jordan@symantec.com>, Allan Thomson <athomson@lookingglasscyber.com>, "cacao@ietf.org" <cacao@ietf.org>
Subject: Re: [Cacao] [EXT] Re: [EXT] RE: Charter

The initial version needs to be done in JSON, if we want the market as a whole to adopt this. I have walked the floor at RSA and Blackhat for the past 2 years talking to all of the vendors that would potentially implement this.  They all say the same thing.  If it was JSON, they could easily do it.  If it is something else, well, maybe, maybe not.  We would then be reliant on market pressure and consumers to influence vendors to adopt.  That can take 10 years or more. Usually by then, the standard is failed and the market has moved on.  Let us not be yet another standard on the dusty shelves of of the SDO Library.

Further, anything not JSON would require the Web2.0 world of products and APIs to support something totally different.  CBOR may take off at some point.  YANG my take off at some point.  XML may come back from the dead. But right now, today, JSON is the model that the developers of products use and know. Adding additional hurtles for the solution to be adopted is not a good idea for this first version.

Overtime, once we get our first versions done and out the door and they get adopted, we can make changes or add functionality based on market demand.  If the market comes back and says, hey, we really need this done in a binary format like Protobuf, then great.  We can write a binding for that.



Thanks,
Bret
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."



On Jun 19, 2019, at 1:41 PM, mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com> wrote:

Re-,

Please see inline.

Cheers,
Med

De : Bret Jordan [mailto:Bret_Jordan@symantec.com]
Envoyé : mercredi 19 juin 2019 13:26
À : BOUCADAIR Mohamed TGI/OLN
Cc : Allan Thomson; Bret Jordan; cacao@ietf.org<mailto:cacao@ietf.org>
Objet : Re: [Cacao] [EXT] Re: [EXT] RE: Charter

I fundamentally do not support the idea of not using JSON for this work.
[Med] Are you referring to application encoding or data modelling part?

 Over time we may write a binding document for some other serialization.  But we need something that can be implemented and have guaranteed interoperability.
[Med] Why CBOR wouldn’t be an option here? BTW, there might be other requirements such as compactness (that may be worth when actions are enriched/augmented on-path). As a group, we don’t have yet the full set of requirements to make a design choice.

In order to gain mass adoption, we need a solution that can be used by the existing eco system.

Bret
Sent from my Commodore 128D