STIX and TAXII, two popular open source projects that automate threat-intelligence sharing, have been approved as full-fledged OASIS standards in a move that supporters say will help prevent and defend against cyberattacks.
In addition to approving the standards, OASIS also released updated versions of both.
The Structured Threat Information Expression (STIX) standard defines a language for sharing structured threat intelligence in a consistent, machine-readable manner. Its authors say this allows organizations to anticipate and respond to attacks faster and more effectively. Several top security companies including Trend Micro, IBM, Avast, and Anomali already use it, as does the U.S. Cybersecurity and Infrastructure Agency (CISA).
It also powers the Cyber Threat Alliance’s threat-intelligence sharing platform. Additionally, STIX plays an important role in the work that the Open Cybersecurity Alliance — another OASIS project — is doing to drive security product interoperability using open source code as well as open standards and protocols.
What’s New With STIX, TAXII v2.1STIX v2.1 adds new objects and improvements based on experience implementing v2.0. “And we added significant support for malware and malware families,” said Richard Struse, a member of the OASIS board of directors and one of the original developers of STIX, which started as a U.S. Department of Homeland Security project back in 2012. He’s now the director of MITRE Engenuity’s Center for Threat-Informed Defense.
“One of our informal goals was that you could take the output of VirusTotal for example, and represent most if not all of what you get from VirusTotal in STIX and now our malware objects,” Struse explained.
STIX v2.1 also adds an extension mechanism, which essentially allows the community to contribute to the standard via an extension, then try it out, and it only becomes a part of STIX if it works. “It lowers the barrier to entry for people,” most of whom aren’t being paid to develop the standard as their full-time job, “and also strengthens our community,” said Trey Darley, a systems and security architect at CERT.be who co-chairs the OASIS Cyber Threat Intelligence (CTI) technical committee with Struse.
Meanwhile, the Trusted Automated Exchange of Intelligence Information (TAXII) standard, also released in v2.1, is the transportation protocol specifically designed to support the exchange of STIX data over HTTPS. TAXII enables organizations to share threat intelligence by defining an API that aligns with common sharing models.
CISA along with Trend Micro, IBM, Avast, and Fujitsu also use TAXII, and both standards have a combined total of 21 statements of use, which is more than any other OASIS standard in the organization’s 27-year history.
After spending a few years as government projects, the DHS handed off STIX and TAXII to standards-development organization OASIS in 2015, and the CTI Technical Committee has been working on both for half a dozen years now and released STIX v2.0 and TAXII v2.0 in 2018.
Why Open Security Standards MatterThe updated STIX v2.1 and TAXII v2.1, and their new status as full OASIS standards, sends a clear message to organizations, Struse said. “For anyone who’s been sitting on the sidelines, waiting to implement or seeing if they should adopt [STIX and TAXII] or commit developer resources, we now have the answer.”
Hint: the answer is yes.
“The work is done, there’s now significant implementation of these, and using them can help you be more secure,” he continued.
This becomes especially important with new (and bigger) cyberattacks hitting headlines every week, and may have been prevented by better threat intelligence sharing, Struse said. “Almost invariably, there are at least some elements of these attacks, which were well understood — in many cases years earlier,” he said. “Now we really need the community to get better at sharing threat intelligence, and then using that to protect your enterprises and your customers.”
Additionally, the new standards can help defenders fill in the cybersecurity skills gap, Darley said.
“We’re at this critical juncture where cyberattacks are becoming so disruptive to our way of life, our society, and critical infrastructure underpinning our economies our democracies,” he said. “We’re close to a tipping point, where things are getting more and more out of hand. We can't just throw money at population and increase by 10x the number of qualified, highly skilled cybersecurity defenders. I do believe these standards, in the near term, say the next three to five years, will have significant impacts on integrations between different security products.”
Security Product InteroperabilityThis also reflects the interoperability work happening within the Open Cybersecurity Alliance. As organizations use more security tools to defend their networks — ESG puts the number between 25 and 59 from up to 10 different vendors on average — trying to integrate all of these products becomes increasingly complex, and takes valuable security analysts’ time that would be better spent hunting and responding to threats.
Open standards can help, Darley said.
“Defenders are a very finite resource, and so much human talent is being spent and wasted on building integrations between these different proprietary systems,” he explained. “My hope is that we’ll be able to get back an awful lot of valuable, human defender time.”
Comments