From 9b9a8e2d8ef7176547e9ae4948c639d086136bc6 Mon Sep 17 00:00:00 2001 From: Frank Xu Date: Sun, 14 Feb 2021 11:11:36 -0500 Subject: [PATCH] add a graph --- STIX_for_digital_forensics/CFO_intro.svg | 305 +++++++++++------------ STIX_for_digital_forensics/readme.md | 2 + 2 files changed, 154 insertions(+), 153 deletions(-) diff --git a/STIX_for_digital_forensics/CFO_intro.svg b/STIX_for_digital_forensics/CFO_intro.svg index 1ba1613..acc3ec2 100644 --- a/STIX_for_digital_forensics/CFO_intro.svg +++ b/STIX_for_digital_forensics/CFO_intro.svg @@ -2,8 +2,8 @@ + xmlns:v="http://schemas.microsoft.com/visio/2003/SVGExtensions/" width="16.5in" height="21.5in" viewBox="0 0 1188 1548" + xml:space="preserve" color-interpolation-filters="sRGB" class="st12"> @@ -20,11 +20,10 @@ .st6 {fill:#00653e;font-family:Franklin Gothic Demi;font-size:1.00001em} .st7 {marker-end:url(#mrkr4-42);stroke:#008cd8;stroke-linecap:round;stroke-linejoin:round;stroke-width:0.75} .st8 {fill:#008cd8;fill-opacity:1;stroke:#008cd8;stroke-opacity:1;stroke-width:0.22935779816514} - .st9 {fill:#ffffff;stroke:none;stroke-linecap:butt} + .st9 {fill:#ffffff;stroke:none;stroke-linecap:butt;stroke-width:7.2} .st10 {fill:#002f49;font-family:Franklin Gothic Demi;font-size:0.666664em} - .st11 {fill:#ffffff;stroke:none;stroke-linecap:butt;stroke-width:7.2} - .st12 {font-size:1em} - .st13 {fill:none;fill-rule:evenodd;font-size:12px;overflow:visible;stroke-linecap:square;stroke-miterlimit:3} + .st11 {font-size:1em} + .st12 {fill:none;fill-rule:evenodd;font-size:12px;overflow:visible;stroke-linecap:square;stroke-miterlimit:3} ]]> @@ -44,7 +43,7 @@ Page-1 - + Rectangle x-disk-partition--1 @@ -54,7 +53,7 @@ x-disk-partition--1 - + Rectangle.4 x-secondary-storage--1 @@ -64,7 +63,7 @@ x-secondary-storage--1 - + Rectangle.5 x-disk-image--1 @@ -74,7 +73,7 @@ x-disk-image--1 - + Rectangle.1000 x-action--1 @@ -84,7 +83,7 @@ x-action--1 - + Rectangle.1001 indicator--1 @@ -94,7 +93,7 @@ indicator--1 - + Rectangle.1002 observed-data--1 @@ -104,7 +103,7 @@ observed-data--1 - + Rectangle.1003 x-webpage-visit--1 @@ -114,7 +113,7 @@ x-webpage-visit--1 - + Rectangle.1004 x-computer--1 @@ -124,7 +123,7 @@ x-computer--1 - + Rectangle.1005 x-crime-case--1 @@ -134,7 +133,7 @@ x-crime-case--1 - + Rectangle.1006 x-timeline--1 @@ -144,7 +143,7 @@ x-timeline--1 - + Rectangle.1008 x-action--2 @@ -154,7 +153,7 @@ x-action--2 - + Rectangle.1009 x-memory- image—1 @@ -164,7 +163,7 @@ x-memory- image—1 - + Dynamic connector.1011 evidence_of @@ -172,7 +171,7 @@ evidence_of - + Rectangle.1012 user-account --1 @@ -182,7 +181,7 @@ user-account --1 - + Dynamic connector.1013 exploits @@ -190,81 +189,81 @@ exploits - + Dynamic connector.1014 action_refs - + action_refs - + Dynamic connector.1017 Indicated-by - + Indicated-by - + Dynamic connector.1018 based-on - + based-on - + Dynamic connector.1019 object_refs - + object_refs - + class="st11" v:langID="2057">ject_refs + Dynamic connector.1021 image-of - + image-of - + Dynamic connector.1024 evidence-of - + evidence-of - + Dynamic connector.1025 action_refs - + action_refs - + Dynamic connector.1026 has - + has - + Dynamic connector.1027 reconstructed_from - + reconstructed_from - + class="st11" v:langID="2057">econstructed_from + Rectangle.1028 file--2 @@ -274,16 +273,16 @@ file--2 - + class="st11" v:langID="1033">2 + Dynamic connector.1029 source_ref - + source_ref - + Rectangle.1030 software--2 @@ -293,7 +292,7 @@ software--2 - + Dynamic connector.1031 browser_ref @@ -301,62 +300,62 @@ browser_ref - + Sheet.1032 directory-1 directory-1 - + Dynamic connector.1033 parent_directory_ref - + parent_directory_ref - + Dynamic connector.1034 contains-refs - + contains-refs - + class="st11" v:langID="2057">ontains-refs + Sheet.1035 threat-actor--1 threat-actor--1 - + Sheet.1036 Identity--1 Identity--1 - + Dynamic connector.1037 attributed-to - + attributed-to - + Dynamic connector.1038 related-to - + related-to - + Rectangle.1039 identity--2 @@ -365,19 +364,19 @@ - identity--identity--2 - + Dynamic connector.1040 reconstructed_by - - r + reconstructed_by - + Dynamic connector.1041 secondary_storage_refs @@ -385,7 +384,7 @@ secondary_storage_refs - + Rectangle.1042 indicator--3 @@ -395,7 +394,7 @@ indicator--3 - + Rectangle.1043 observed-data--3 @@ -405,7 +404,7 @@ observed-data--3 - + Rectangle.1044 x-pnp-evt--1 @@ -415,24 +414,24 @@ x-pnp-evt--1 - + Dynamic connector.1045 based-on - + based-on - + Dynamic connector.1046 object_refs - + object_refs - + class="st11" v:langID="2057">ject_refs + Rectangle.1047 file--4 @@ -442,39 +441,39 @@ file--4 - + class="st11" v:langID="1033">4 + Dynamic connector.1048 source_ref - + source_ref - + Sheet.1049 directory-3 directory-3 - + Dynamic connector.1050 parent_directory_ref - + parent_directory_ref - + Dynamic connector.1051 indicated-by - + indicated-by - + Rectangle.1052 indicator—2 @@ -484,7 +483,7 @@ indicator—2 - + Rectangle.1053 observed-data—2 @@ -494,7 +493,7 @@ observed-data—2 - + Rectangle.1054 x-windows-evt-2 @@ -504,24 +503,24 @@ x-windows-evt-2 - + Dynamic connector.1055 based-on - + based-on - + Dynamic connector.1056 object_refs - + object_refs - + class="st11" v:langID="2057">ject_refs + Rectangle.1057 file--3 @@ -531,60 +530,60 @@ file--3 - + class="st11" v:langID="1033">3 + Dynamic connector.1058 source_ref - + source_ref - + Sheet.1059 directory-2 directory-2 - + Dynamic connector.1060 parent_directory_ref - + parent_directory_ref - + Dynamic connector.1061 indicated-by - + indicated-by - + Dynamic connector.1062 contains-refs - + contains-refs - + class="st11" v:langID="2057">ontains-refs + Dynamic connector.1063 contains-refs - + contains-refs - + class="st11" v:langID="2057">ontains-refs + Dynamic connector.1065 part-of @@ -592,15 +591,15 @@ part-of - + Dynamic connector.1066 used-in - + used-in - + Rectangle.1067 Identify--3 @@ -610,8 +609,8 @@ Identify--3 - + class="st11" v:langID="1033">3 + Rectangle.1069 x-investigation-tool--1 @@ -621,15 +620,15 @@ x-investigation-tool--1 - + Dynamic connector.1070 acquired_using_tool_ref - + acquired_using_tool_ref - + Rectangle.1071 software--1 @@ -639,15 +638,15 @@ software--1 - + Dynamic connector.1072 software_ref - + software_ref - + Rectangle.1073 x-file-visit--1 @@ -657,8 +656,8 @@ x-file-visit--1 - + class="st11" v:langID="2057">--1 + Dynamic connector.1074 object_refs @@ -666,7 +665,7 @@ object_refs - + Rectangle.1075 file--1 @@ -676,33 +675,33 @@ file--1 - + Dynamic connector.1076 source-ref - + source-ref - + Dynamic connector.1077 contains-refs - + contains-refs - + class="st11" v:langID="2057">ontains-refs + Dynamic connector.1078 object-refs - + object-refs - + Rectangle.1079 Cyber Forensic Domain Object @@ -712,8 +711,8 @@ Cyber Forensic Domain Object - + x="25.91" dy="1.2em" class="st11">Domain Object + Rectangle.1080 Cyber Forensic Domain Object @@ -723,8 +722,8 @@ Cyber Forensic Domain Object - + x="48.15" dy="1.2em" class="st11">Object + Rectangle.1081 STIX Object @@ -734,47 +733,47 @@ STIX Object - + Dynamic connector.1082 assigned-to - + assigned-to - + Dynamic connector.1083 invovles - + invovles - + Dynamic connector.1084 acquired_by_ref - + acquired_by_ref - + Dynamic connector.1085 exploits - + exploits - + Dynamic connector.1086 exploits - + exploits - + Rectangle.1087 url @@ -784,22 +783,22 @@ url - + Dynamic connector.1088 url_ref - + url_ref - + Dynamic connector.1089 object_refs - + object_refs + class="st11" v:langID="2057">ject_refs diff --git a/STIX_for_digital_forensics/readme.md b/STIX_for_digital_forensics/readme.md index 1c18711..dc66fb0 100644 --- a/STIX_for_digital_forensics/readme.md +++ b/STIX_for_digital_forensics/readme.md @@ -16,6 +16,8 @@ The xSTIX includes a set of Cyber Forensic Objects (CFOs), customized properties - **Open Vocabulary extension:** Add vocabulary in the field of cyber forensic investigations. +## CFO Graph + ![CFO graph](CFO_intro.svg) ## Extension Format