Views:
Trusted Automated Exchange of Intelligence Information (TAXII) is an application protocol for exchanging Cyber Threat Intelligence (CTI) over HTTPS. The SMS contains embedded TAXII 2.0 and 2.1 Servers. TAXII clients can push Structured Threat Information eXpression (STIX™) 2.0/2.1 data to the SMS TAXII Servers. The advanced threat intelligence provided in tag categories keeps the Reputation Database updated, and enables robust reputation filters for enhanced protection of your system. You can use STIX/TAXII for IPS enforcement of IP, DNS, URL, and file hash Indicators of Compromise (IoCs).

Reputation database

The SMS automatically includes the following predefined tag categories for STIX/TAXII data. Use the following table to map STIX objects with user-provided Reputation tag categories.
Reputation tag STIX object property Description
STIX - ID id Identifies the STIX Indicator object, which is the only STIX 2.0 Domain Object the SMS imports.
Indicators contain a pattern that can be used to detect suspicious or malicious cyber activity. For example, an indicator may be used to represent a set of malicious IP addresses, domains, or URLs.
To be imported to the Reputation database, an indicator STIX object must:
  • Only contain a single comparison expression.
  • Object path pattern must be domain, URL, IPv4, IPv6, SHA-1, or SHA-256.
STIX - Severity labels Identifies the severity for the discovered threat, based on rules that match severity. This is not a standard property for STIX 2.0.
STIX - Confidence labels Identifies the confidence for the discovered threat, based on rules that match a confidence score. This is not a standard property for STIX 2.0.
Reputation Entries TTL valid_until Identifies the date SMS will remove the entry.
- revoked The SMS deletes the entry when it is tagged true.

Versions

This feature implements STIX/TAXII 2.

Import rules

  • To automatically send STIX data to the SMS, enable the TAXII service. The TAXII service is enabled by default. For more information, see "Enable SMS Services" in the SMS User Guide.
  • Only STIX Indicator objects can be added to the Reputation database.
  • STIX Indicator objects must only contain a single comparison expression.
  • You cannot export STIX objects from the SMS.