Trusted Automated Exchange of Intelligence Information (TAXII) is an application protocol
for exchanging Cyber Threat Intelligence (CTI) over HTTPS. The SMS contains embedded
TAXII 2.0 and 2.1 Servers. TAXII clients can push Structured Threat Information eXpression
(STIX™) 2.0/2.1 data to the SMS TAXII Servers. The advanced threat intelligence provided
in tag categories keeps the Reputation Database updated, and enables robust reputation
filters for enhanced protection of your system. You can use STIX/TAXII for IPS enforcement
of IP, DNS, URL, and file hash Indicators of Compromise (IoCs).
Reputation database
The SMS automatically includes the following predefined tag categories for STIX/TAXII
data. Use the following table to map STIX objects with user-provided Reputation tag
categories.
| Reputation tag | STIX object property | Description |
| STIX - ID | id | Identifies the STIX
Indicator object, which is the only STIX 2.0 Domain Object the SMS imports.
Indicators contain a pattern that can be used to detect suspicious or malicious cyber
activity. For example, an indicator may be used to represent a set of malicious IP
addresses, domains, or URLs.
To be imported to the Reputation database, an indicator STIX object must:
|
| STIX - Severity | labels | Identifies the severity for the discovered threat, based on rules that match severity. This is not a standard property for STIX 2.0. |
| STIX - Confidence | labels | Identifies the confidence for the discovered threat, based on rules that match a confidence score. This is not a standard property for STIX 2.0. |
| Reputation Entries TTL | valid_until | Identifies the date SMS will remove the entry. |
| - | revoked | The SMS deletes the entry when it is tagged
true.
|
Versions
This feature implements STIX/TAXII 2.
Import rules
- To automatically send STIX data to the SMS, enable the TAXII service. The TAXII service is enabled by default. For more information, see "Enable SMS Services" in the SMS User Guide.
- Only STIX Indicator objects can be added to the Reputation database.
- STIX Indicator objects must only contain a single comparison expression.
- You cannot export STIX objects from the SMS.
