IBM continued its push into containerized software and open source technology today with Cloud Pak for Security.
Customers can run the new containerized security platform on premises or in private or public clouds, and it comes pre-integrated with Red Hat OpenShift. (IBM recently acquired Red Hat and branded these services that combine IBM legacy software with Red Hat’s Kubernetes-based platform as “Cloud Paks.”)
Plus, it uses an open-source connector to integrate with IBM and other vendors’ security tools as well as data from across a company’s infrastructure.
Solving Fragmentation With Open Source“Our point of view is that clearly there is a level of fragmentation” across companies’ security and analytics products, said Aarti Borkar, VP of IBM Security business. To fix this, the industry should adopt “some level of open standards-based interaction so data and information can be shared, so customers aren’t doing it on their end.”
Additionally, customers’ multicloud environments “cause a level of fragmentation in the data that people are trying to protect,” Borkar said. “Applications and data are sitting in multiple places. Copies are being made in multiple places, and this widespread adoption of multicloud exacerbates the issue.”
IBM says open technology can help address this fragmentation, and to that end the company in collaboration with several other security vendors last month announced the Open Cybersecurity Alliance. By joining this group the vendors agree to promote interoperability and help reduce vendor lock-in across the security sector through co-developed open source technologies. This also plays into IBM’s new Cloud Pak for Security because it can run anywhere and it's interoperable with other vendor’s products.
IBM Security contributed open source code to the Open Cybersecurity Alliance at its launch, and its new security platform also uses this open source code. Specifically it uses STIX-Shifter, an open source library that can identify information about potential threats within a wide variety of data repositories and translate it into a format that can be digested and analyzed by any security tool that has this standard enabled.
Cloud Pak for SecurityCloud Pak for Security uses STIX-Shifter to connect data sources, which can then help to uncover threats, while leaving the data where it resides instead of moving it all to the IBM platform for analysis. Customers can access IBM and third-party tools to search for threat indicators across any cloud or on-premise location. And via the Cloud Pak for Security’s Data Explorer application, security analysts can streamline their hunt for threats across security tools and clouds instead of manually searching each environment.
“It’s a different point of view from our competitors in this space because neither are we saying move everything to one place,” and onto IBM’s platform, “nor are we saying we are only going to integrate with our own products and the few friends we have,” Borkar said. “Also moving data and copying data and replicas of data is a bad idea in general.”
The platform includes connectors for pre-built integrations with security tools from IBM, VMware’s Carbon Black, Tenable, Elastic, BigFix, Splunk, as well as public cloud providers including IBM Cloud, Amazon Web Services, and Microsoft Azure. It also can connect to additional products and data.
Cloud Pak for Security also uses IBM’s existing security orchestration, automation, and response (SOAR) technology, integrated with Red Hat Ansible to automate security processes and response. This helps security teams respond faster to incidents, Borkar said.
“We aren’t just talking about detection; we’re talking about response,” she said. “Yes, we will connect to a variety of tools, and yes, we can run it anywhere, but once you have those insights the speed to response is just as important.”
Comments