Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Research: How does MITRE D3FEND relate to Vulntology? #71

Open
Chris-Turner-NIST opened this issue Apr 12, 2022 · 4 comments
Open

Research: How does MITRE D3FEND relate to Vulntology? #71

Chris-Turner-NIST opened this issue Apr 12, 2022 · 4 comments
Labels
Discussion Needed Topic requires further discussion or research to provide more specific actions enhancement New feature or request Value List Adjustment Issue is related to adding to or modifying valid values in the data model

Comments

@Chris-Turner-NIST
Copy link
Collaborator

https://d3fend.mitre.org/

@ag0x00
Copy link

ag0x00 commented Apr 15, 2022

This is a very timely request, because at the moment, D3FEND ontology doesn't seem to have Vulnerability related classes: https://d3fend.mitre.org/ontologies/d3fend.ttl

Vulntology would be a perfect compliment to D3FEND. Being able to access Vulntology as a TTL or OWL would really help.

@netfl0
Copy link

netfl0 commented Apr 25, 2022

Hello,

We (MITRE D3FEND) are trying to standardize the names of components in a system, we call these digital artifacts. We'd be interested in aligning vocabularies where possible to enable compatibility.

D3FEND has over 400 digital artifacts defined, and we are adding quite a bit more. These are arranged in a classification taxonomy, and then related to one another semantically, all with definitions etc.

Let us know if we can help.

Peter

@david-waltermire
Copy link
Collaborator

@netfl0 Do you have some specific suggestions about where we can work to align these efforts?

@netfl0
Copy link

netfl0 commented Apr 26, 2022

@david-waltermire-nist , the context concept jumped out at me in particular. We have modeled various elements like Application, Firmware, Hardware, Channel and many more in the D3FEND ontology. They all have definitions and relationships specified. That might be an area of alignment.

You can view some of them on the D3FEND website, but you need to open the ontology file in order to see them all.

@Chris-Turner-NIST Chris-Turner-NIST added Discussion Needed Topic requires further discussion or research to provide more specific actions Value List Adjustment Issue is related to adding to or modifying valid values in the data model labels Oct 23, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Discussion Needed Topic requires further discussion or research to provide more specific actions enhancement New feature or request Value List Adjustment Issue is related to adding to or modifying valid values in the data model
Projects
None yet
Development

No branches or pull requests

4 participants