Configuring stdlib.localDB with an "age_out" breaks the miner, allowing only 1 IOC at a time.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Configuring stdlib.localDB with an "age_out" breaks the miner, allowing only 1 IOC at a time.

L0 Member

Below is a link of a test implementation as I learn Minemeld. I have read the following documentation.

 

Use Case

 

Using Desmito, we would like to submit IOCs to the stdlib.localDB miner. Based off of investigations, the analyst will determine the TTL (age_out) policy for the IOC. The default policy should be configured for a 24 hour TTL.

The test case, I am using 30-60 seconds TTL to test default TTL funcationality. However, I have been running into strange issues.

 

Test conditions requirements

  1. Maintain a list of IOCs.
  2. Remove IOCs which have expired. 

 

Test Diagram

Connection_Graph.PNG

 

Case #1

 

The following settings have been configured on stdlib.localDB.
Observed behavior:

  1. Adding a new IOC after one has been added, will remove all previous IOCs. Resulting in the miner only ever having 1 IOC. Regardless of the expiration date.
  2. Expiration does properly work.

Tests Done:

  1. Attempted using default for age_out policy.
  2. Attempted using a manual age_out TTL legnth.

 

TEST-stdlib_localDB.PNG

 

Case #2

 

The following settings have been configured on stdlib.localDB-true.
Observed behavior:

  1. Adding a new IOC after one has been added, will remove all previous IOCs. Resulting in the miner only ever having 1 IOC. Regardless of the expiration date.
  2. Expiration does properly work.

Tests Done:

  1. Attempted using default for age_out policy.
  2. Attempted using a manual age_out TTL legnth.

TEST-stdlib_localDB-true.PNG

 

Case #3

 

The following settings have been configured on stdlib.localDB-true.
Observed behavior:

  1. Is able to maintain a list of IOCs. 
  2. Expiration does not properly work.

Tests Done:

  1. Attempted using default for age_out policy.
  2. Attempted using a manual age_out TTL legnth.

TEST-stdlib_localDB-false.PNG

1 REPLY 1

L0 Member

hi @KOFFENBACK , 

have you found a solution for this problem?
I'm facing the same issue, the only workaround I've found is to set for each IOC TTL=Disabled.

 

@admin: do you have any update in program to fix this? 

  • 2172 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!