There’s a new open source initiative in town and this one’s unique because it targets interoperable security technologies. The new group, called Open Cybersecurity Alliance, formed under the auspices of the Organization for the Advancement of Structured Information Standards (OASIS). It launched today with initial open source content and code contributed by IBM Security and McAfee.

Other members include Advanced Cyber Security Corp, Corsa, CrowdStrike, CyberArk, Cybereason, DFLabs, EclecticIQ, Electric Power Research Institute, Fortinet, Indegy, New Context, ReversingLabs, SafeBreach, Syncurity, ThreatQuotient, and Tufin. Everyone involved says they welcome participation from other organizations and individuals, too.

The group aims to make the myriad security products on the market interoperable using open source code as well as open standards and protocols.

“The security industry today is confronted with a couple significant challenges,” said D.J. Long, vice president of business development at McAfee. “One is an ever-expanding threat attack surface: tablets, laptops, phones, just about everything including IoT devices are equally susceptible to attacks. These attacks are also becoming increasingly sophisticated and from a variety of different sources.”

While there are several other cybersecurity coalitions in existence, most of these focus on sharing threat intelligence (like the Cyber Threat Alliance and the Forum of Incident Response and Security Teams), or best practices (like the Cloud Security Alliance), or even policy change (like the Cybersecurity Tech Accord). None of these groups focus on bringing the benefits of open source code to the security landscape.

“What makes this so unique is that this is a true alliance of vendors, end users, and individuals around the world getting together to agree on standards and ways of interoperating,” said Carol Geyer, chief development officer at OASIS. “The OASIS Open Projects program is really built to streamline the process so we can get to standards in a very streamlined way and not bog this down. The industry needs these standards and needs them now.”

Too Many Products, Too Few Professionals

This becomes increasingly important as enterprises use an increasing number of security tools — ESG puts the number at between 25 and 59 — from up to 10 different vendors on average. Each of these products creates siloed data, and connecting these security tools and data requires complex integrations, which eats into security professionals’ time that should be spent hunting and responding to threats. There’s also the well-documented security skills shortage, and all of this erupts into the perfect storm — or the perfect opportunity for an open source group like the Open Cybersecurity Alliance.

“There’s a number of different alliances that exist in the cybersecurity space, but there are no groups that focus on this problem set, which is reducing the barriers to interoperability between products,” said Jason Keirstead, chief architect at IBM Security Threat Management.

To address this problem, the Open Cybersecurity Alliance will develop protocols and standards that will enable security products to work together out of the box.

“We believe in working together with OASIS and IBM, that employing our approach enables products to work more effectively together in a more seamless environment, so customers don’t just layer one security product on top of another,” Long added. “No one cybersecurity vendor, regardless of their size or scope, is capable of addressing all the needs of the enterprises we currently serve. It is better if we collaborate.”

IBM Security, McAfee Contributions

The group launched with contributions from IBM Security and McAfee.

IBM Security contributed STIX-Shifter, an open source library that can identify information about potential threats within a wide variety of data repositories and translate it into a format that can be digested and analyzed by any security tool that has this standard enabled.

“It’s a tech that provides a universal, out-of-the-box search capability for security products of all types,” Keirstead said. It connects security products to other security, cloud, and software data repositories via a standardized cybersecurity data model called STIX 2, which is also an OASIS standard.

McAfee contributed the OpenDXL Standard Ontology, which focuses on the development of an open and interoperable cybersecurity messaging format for use with the OpenDXL messaging bus.

“Think of this as a message bus for real-time exchange of security information,” Long said. “We developed this specifically to facilitate integrations amongst and between McAfee and third-party products and between third-party products themselves without McAfee products.”

The OpenDXL Standard Ontology will be offered under the Apache 2.0 license.

Open Cybersecurity Alliance will hold its first meeting later this month, at which point it will elect a chairperson and decide how to move forward with the two initial open source projects. “We’re all highly motivated to get things off to a quick running start, and I expect to see outcomes from this fairly quickly,” Keirstead said.

“We don’t want this to be seen as an effort dominated by IBM Security and McAfee,” Long added. “It’s collaborative, and it’s equally important to stress that we are interested in having other companies participate.”