ocsf-schema icon indicating copy to clipboard operation
ocsf-schema copied to clipboard

Add the severity/score confidence level as determined by the event source

Open Noafr opened this issue 2 years ago • 1 comments

Problem: In addition to the severity field, some vendors are also sending a "confidence" score to describe the certainty of the severity determined for the incident/event. For example, Vectra sends the $certainty field (int) to describe the certainty of the detection. This has been also the case with some TI vendors who are using indicator confidence score (IC-Score) to describe expert-based indicator confidence scores for TI events.

Suggestion: Add a new attribute (e.g. ref_severity_confidence (int)) to describe the confidence level of the score given by the event source.

Noafr avatar Oct 14 '22 15:10 Noafr

Agreed - pretty common to have confidence as well as severity.

pagbabian-splunk avatar Oct 14 '22 23:10 pagbabian-splunk

We are proposing a general purpose solution for all reference attributes to the original data.

Aniak5 avatar Oct 18 '22 17:10 Aniak5

I think there is another issue here: do we need to have the standard confidence (0-100) used with severity which would imply it would need to be in the base class. I agree that the original should be consistent with other original values within unmapped.

pagbabian-splunk avatar Oct 28 '22 03:10 pagbabian-splunk

We have a confidence in the finding object as seen here. This object is referenced within the security findings event class. Does this suffice for your use case @Noafr? Or do you need a confidence for non-security related events?

Aniak5 avatar Oct 28 '22 15:10 Aniak5

I would also ask/add: do we need confidence in standard events that include severity (i.e. all events) rather than only the finding object which is not usually an original source event (e.g. the result of an analysis of some kind)?

pagbabian-splunk avatar Oct 28 '22 17:10 pagbabian-splunk