SAN FRANCISCO — AT&T and several other companies joined the Open Cybersecurity Alliance, which, less than five months after IBM and McAfee launched the group, now has nearly 30 members. The group also today made available OpenDXL Ontology, which it says is the first open source language for connecting security tools.
“The level of interest that we’ve had illustrates that the problem are we are trying to tackle here really resonates,” said Jason Keirstead, chief architect of IBM Security Threat Management. “The feedback we hear is that it’s time that someone has stepped up to solve this interoperability problem.”
Some of the other new alliance members include Armis, Raytheon, Center for Internet Security, Recorded Future, Tripwire, and SAIC.
The Open Cybersecurity Alliance launched in October, under the auspices of the Organization for the Advancement of Structured Information Standards (OASIS). It aims to make the myriad of security products on the market interoperable using open source code as well as open standards and protocols.
This becomes more important as enterprises use an increasing number of security tools — ESG puts the number at between 25 and 59 — from up to 10 different vendors on average.
STIX Shifter, OpenDXL Ontology Gain TractionAt launch, IBM Security contributed STIX Shifter, an open source library that can identify information about potential threats within a variety of data repositories and translate it into a format that can be digested and analyzed by any security tool that has this standard enabled.
About a month later IBM announced the first commercial deployment of STIX Shifter in its new containerized security platform Cloud Pak for Security. This product uses STIX Shifter to integrate with IBM and other vendors’ security tools as well as data from across a company’s infrastructure.
Meanwhile McAfee at the launch committed to release the Open Data Exchange Layer (OpenDXL) Ontology “as soon as we could,” said Darren Thomas, senior product manager of McAfee’s Open Data Exchange Layer. More than 4,100 vendors and enterprises already use this open messaging framework to develop and share integrations with other tools. “We had a number of folks working up until the end of the year, we got that launched and made available just before New Year’s Day.”
The release of this open source project is significant in that it provides a single, common language for notifications, information, and actions across security products. Vendors can use the framework to communicate in a standard way with all other tools under its umbrella. Additionally, they can apply it once and it’s automatically reused everywhere across all product categories. It also eliminates the need to update integrations as product versions and functionalities change.
Both open source projects are seeing good traction in the form of new contributions and projects forks, IBM and McAfee executives say. “We’ve also had some preliminary but also very exciting conversations with other open source projects who may be looking to use the STIX Shifter project in their project,” Keirstead said.
Open Cybersecurity Alliance Launches Technical Steering CommitteeIn addition to the release of OpenDXL Ontology, the Open Cybersecurity Alliance today also announced the formation of its Technical Steering Committee, which includes leaders from AT&T, IBM Security, McAfee, Packet Clearinghouse, and Tripwire. This group will guide the technical direction of development of the open source projects, Keirstead said. “They are going to start forming working groups on how to focus in on certain aspects of interoperability, for example, around IoT security and things of that nature, places where we know we have gaps, and also flesh out StickShifter and the Ontology project,” he added.
RSA Conference 2020 will be the group’s coming out party, and it’s hosting an already-overbooked, invitation-only luncheon as it recruits more members and works to generate interest in open source security interoperability.
“We’ve been reaching out to a lot of organizations about getting involved in this," said Carol Geyer, chief development officer of OASIS. "We started first with the vendors, and now getting more into the end users and talking to the financial services companies and the telecoms. And of all the hundreds of companies we’re talked to, nobody says there’s not a need for this. Everybody says it’s about time that somebody is addressing this.”
Comments