Skip to content

Commit 3c86527

Browse files
committed
changes for entity-count
1 parent 8f62739 commit 3c86527

11 files changed

+150
-52
lines changed

extension-definition-specifications/incident-ef7/Incident Extension Suite.adoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1040,7 +1040,7 @@ The value of this property *MUST* come from the [stixtype]#<<task-outcome-enum,t
10401040
|The value of this property *MUST* be set to [stixliteral]#task#.
10411041

10421042
|*affected_entity_counts* (optional)
1043-
|[stixtype]#<<entity-count,entity-count>>#
1043+
|[stixtype]#{list_url}[list]# of type [stixtype]#<<entity-count,entity-count>>#
10441044
|A list of affected entity types, along with the number of each type affected.
10451045

10461046
This property is used primarily to capture victim notification information.

extension-definition-specifications/incident-ef7/examples/example_2.1.json

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -25,11 +25,6 @@
2525
"impact_refs": [
2626
"impact--7a5806e4-0f37-4c48-9a50-7301bff4b195"
2727
],
28-
"impacted_entity_counts": {
29-
"individual": 100,
30-
"employee": 70,
31-
"customer-individual": 30
32-
},
3328
"incident_types": [
3429
"hosting-phishing-sites"
3530
],

extension-definition-specifications/incident-ef7/examples/example_2.3.2.1.1.json

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -9,9 +9,12 @@
99
"description": "Loss of availability for a critical service.",
1010
"end_time": "2023-11-22T16:00:00Z",
1111
"end_time_fidelity": "minute",
12-
"impacted_entity_counts": {
13-
"system": 1
14-
},
12+
"impacted_entity_counts": [
13+
{
14+
"entity_name": "system",
15+
"count": 1
16+
}
17+
]
1518
"impacted_refs": [
1619
"infrastructure--11c25d0e-48f5-4491-960a-0da71c4e0d16"
1720
],

extension-definition-specifications/incident-ef7/examples/incident_expo_1.json

Lines changed: 25 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -114,13 +114,7 @@
114114
"investigation_status": "open",
115115
"criticality": 90,
116116
"detection_methods": ["system-outage"],
117-
"impacted_entity_counts": {
118-
"computers-mobile": 2000,
119-
"computers-personal": 1000,
120-
"computers-server": 232,
121-
"domain-controller": 7,
122-
"network-device": 3252
123-
},
117+
124118
"incident_types": [
125119
"denial-of-service",
126120
"unattributed"
@@ -172,6 +166,30 @@
172166
"object_marking_refs": ["marking-definition--43b7719e-52a7-47d4-ba05-cddbd59d961f"],
173167
"description": "After bypass mode all servers still shutdown, but wireless and displays are now up in a limited capacity.",
174168
"impact_category": "availability",
169+
"impacted_entity_counts": [
170+
{
171+
"entity_type": "computers-mobile",
172+
"count": 2000,
173+
"precise_within": 100
174+
},
175+
{
176+
"entity_type": "computers-personal",
177+
"count": 1000,
178+
"precise_within": 100
179+
},
180+
{
181+
"entity_type": "computers-server",
182+
"count": 232
183+
},
184+
{
185+
"entity_type": "domain-controller",
186+
"count": 7
187+
},
188+
{
189+
"entity_type": "network-device",
190+
"count": 3252
191+
}
192+
],
175193
"start_time": "2022-09-14T17:00:00.000Z",
176194
"start_time_fidelity": "hour",
177195
"extensions": {

extension-definition-specifications/incident-ef7/examples/incident_expo_2.json

Lines changed: 24 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -136,13 +136,6 @@
136136
"investigation_status": "open",
137137
"criticality": 90,
138138
"detection_methods": ["system-outage"],
139-
"impacted_entity_counts": {
140-
"computers-mobile": 2000,
141-
"computers-personal": 1000,
142-
"computers-server": 232,
143-
"domain-controller": 7,
144-
"network-device": 3252
145-
},
146139
"incident_types": [
147140
"denial-of-service",
148141
"unknown-apt"
@@ -240,6 +233,30 @@
240233
"object_marking_refs": ["marking-definition--43b7719e-52a7-47d4-ba05-cddbd59d961f"],
241234
"description": "After bypass mode all servers still shutdown, but wireless and displays are now up in a limited capacity.",
242235
"impact_category": "availability",
236+
"impacted_entity_counts": [
237+
{
238+
"entity_type": "computers-mobile",
239+
"count": 2000,
240+
"precise_within": 100
241+
},
242+
{
243+
"entity_type": "computers-personal",
244+
"count": 1000,
245+
"precise_within": 100
246+
},
247+
{
248+
"entity_type": "computers-server",
249+
"count":
250+
},
251+
{
252+
"entity_type": "domain-controller",
253+
"count": 7,
254+
},
255+
{
256+
"entity_type": "network-device",
257+
"count": 3252
258+
}
259+
],
243260
"start_time": "2022-09-14T17:00:00.000Z",
244261
"start_time_fidelity": "hour",
245262
"end_time": "2022-09-15T10:00:00.000Z",

extension-definition-specifications/incident-ef7/examples/incident_expo_3.json

Lines changed: 24 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -158,13 +158,6 @@
158158
"investigation_status": "open",
159159
"criticality": 90,
160160
"detection_methods": ["system-outage"],
161-
"impacted_entity_counts": {
162-
"computers-mobile": 2000,
163-
"computers-personal": 1000,
164-
"computers-server": 232,
165-
"domain-controller": 7,
166-
"network-device": 3252
167-
},
168161
"incident_types": [
169162
"denial-of-service"
170163
],
@@ -246,6 +239,30 @@
246239
"object_marking_refs": ["marking-definition--43b7719e-52a7-47d4-ba05-cddbd59d961f"],
247240
"description": "All servers shutdown,wireless tied to these went down,all displays went down.",
248241
"impact_category": "availability",
242+
"impacted_entity_counts": [
243+
{
244+
"entity_type": "computers-mobile",
245+
"count": 2000,
246+
"precise_within": 100
247+
},
248+
{
249+
"entity_type": "computers-personal",
250+
"count": 1000,
251+
"precise_within": 100
252+
},
253+
{
254+
"entity_type": "computers-server",
255+
"count": 232
256+
},
257+
{
258+
"entity_type": "domain-controller",
259+
"count": 7
260+
},
261+
{
262+
"entity_type": "network-device",
263+
"count": 3252
264+
}
265+
],
249266
"start_time": "2022-09-14T14:57:00.000Z",
250267
"start_time_fidelity": "minute",
251268
"end_time": "2022-09-14T17:00:00.000Z",

extension-definition-specifications/incident-ef7/examples/incident_expo_4.json

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -181,13 +181,6 @@
181181
"investigation_status": "open",
182182
"criticality": 90,
183183
"detection_methods": ["system-outage"],
184-
"impacted_entity_counts": {
185-
"computers-mobile": 2000,
186-
"computers-personal": 1000,
187-
"computers-server": 232,
188-
"domain-controller": 7,
189-
"network-device": 3252
190-
},
191184
"incident_types": [
192185
"denial-of-service",
193186
"data-exfiltration"
@@ -294,6 +287,13 @@
294287
"object_marking_refs": ["marking-definition--43b7719e-52a7-47d4-ba05-cddbd59d961f"],
295288
"description": "After bypass mode all servers still shutdown, but wireless and displays are now up in a limited capacity.",
296289
"impact_category": "availability",
290+
"impacted_entity_counts": {
291+
"computers-mobile": 2000,
292+
"computers-personal": 1000,
293+
"computers-server": 232,
294+
"domain-controller": 7,
295+
"network-device": 3252
296+
},
297297
"start_time": "2022-09-14T17:00:00.000Z",
298298
"start_time_fidelity": "hour",
299299
"end_time": "2022-09-15T10:00:00.000Z",

extension-definition-specifications/incident-ef7/examples/incident_pii_report.json

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -38,10 +38,7 @@
3838
"impact--29d33f9d-a1a4-4d08-a48c-01a8f076331b",
3939
"impact--bb4e161d-3053-46e4-8496-3a00c3830037",
4040
"impact--a17c0f80-0d75-4f6a-863f-0097ec07fc84"
41-
],
42-
"impacted_entity_counts": {
43-
"individual": 123456
44-
}
41+
]
4542
}
4643
}
4744
},
@@ -52,6 +49,12 @@
5249
"modified": "2020-10-17T01:01:01.000Z",
5350
"spec_version": "2.1",
5451
"impact_category": "confidentiality",
52+
"impacted_entity_counts": [
53+
{
54+
"entity_type": "individual",
55+
"count": 123456
56+
}
57+
],
5558
"extensions": {
5659
"extension-definition--7cc33dd6-f6a1-489b-98ea-522d351d71b9": {
5760
"extension_type": "new-sdo"

extension-definition-specifications/incident-ef7/extension-definition--ef765651-680c-498d-9894-99799f2fa126.json

Lines changed: 24 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -121,14 +121,7 @@
121121
"$ref": "#/definitions/Recoverability"
122122
},
123123
"impacted_entity_counts": {
124-
"description": "A dictionary of entities that were impacted by the incident where the key is the entity type and the value is the number of entities of that type which were impacted. In most cases these should be understood to be estiamtes.",
125-
"patternProperties": {
126-
"^[a-z\\-]+": {
127-
"type": "integer",
128-
"description": "Key names MUST be lower case and separated by dashes. Common values include 'individuals', 'organizations', 'business-units', 'facilities', 'information-systems'",
129-
"minimum": 0
130-
}
131-
}
124+
"$ref": "#/definitions/entity_count"
132125
}
133126
}
134127
}
@@ -138,6 +131,29 @@
138131
}
139132
],
140133
"definitions": {
134+
"entity_count": {
135+
"type": "object",
136+
"description": "The Entity Count type represents the count of an entity type.",
137+
"properties": {
138+
"entity_type": {
139+
"type": "string",
140+
"description": "The type of entity. The value of the entity type should come from entity-type-ov open vocabulary."
141+
},
142+
"count": {
143+
"type": "integer",
144+
"description": "The number of instances of the entity type.",
145+
"minimum": 0
146+
},
147+
"precise_within": {
148+
"type": "integer",
149+
"description": "The order of magnitude of the approximate count. If this property is not provided, the count should be considered the accurate count."
150+
}
151+
},
152+
"required": [
153+
"entity_type",
154+
"count"
155+
]
156+
},
141157
"Recoverability": {
142158
"type": "string",
143159
"description": "The scope of impact required to recover from an incident",

extension-definition-specifications/incident-ef7/impact/examples/pii_loss.json

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -9,9 +9,12 @@
99
"created": "2023-04-07T20:00:00.0002Z",
1010
"modified": "2023-04-07T20:00:00.0002Z",
1111
"spec_version": "2.1",
12-
"impacted_entity_counts": {
13-
"individual": 123456
14-
},
12+
"impacted_entity_counts": [
13+
{
14+
"entity_type": "individual",
15+
"count": 123456
16+
}
17+
],
1518
"extensions": {
1619
"extension-definition--7cc33dd6-f6a1-489b-98ea-522d351d71b9": {
1720
"extension_type": "new-sdo"

0 commit comments

Comments
 (0)