Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Latest News
    • Storage

    CERT to Ease Sharing

    Written by

    Dennis Fisher
    Published July 28, 2003
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      In an effort to jump-start various bedraggled security information-sharing efforts in the IT industry, the CERT Coordination Center and several universities this week will announce a project that will allow for real-time data sharing and analysis among remote organizations.

      If the project is successful, it could be used as a model for data-sharing initiatives in the government and private sector.

      Known as the Cyber Security Information Sharing Project, the new collaboration is a sharp departure from the way unaffiliated organizations now share information.

      Currently, businesses or individuals wanting to inform CERT of a security incident or vulnerability have to fill out a form on the centers Web site or call an 800-number and then wait for an answer. This can lead to slow responses to situations that require urgent action. CERT officials said they hope that will all soon change.

      “Were trying to move beyond talking and do something that identifies what the issues are and provides solutions to problems,” said Richard Pethia, manager of the Software Engineering Institutes Survivable Systems Initiative and director of the CERT CC. “We want to promote the use of standards to share data. The future of widespread information sharing will depend on this.”

      A key part of the project is ArcSight Inc.s namesake security event management software, which will be installed at each participating site. Which universities will participate in the CSISP has yet to be determined, CERT officials said.

      The ArcSight softwares new distributed architecture will enable each participating school to act as a data-collection end point and funnel attack data directly to the CERT CC at Carnegie Mellon University, in Pittsburgh.

      CERT specialists will then be able to dissect and analyze the data. The CERT team will also have the advantage of being able to correlate information coming from all three end points, giving team members the ability to look for similar attacks or other patterns across the participating organizations. That data can then go into the CERT database and be made available to other organizations.

      Page Two

      ArcSights software will support two proposed Internet Engineering Task Force message standards for exchanging security messages—IDMEF (Intrusion Detection Message Exchange Format) and IODEF (Incident Object Description and Exchange Format)—which are designed for applications such as sharing attack data among organizations.

      “With the correlation, CERT can look for patterns outside of just what the [individual organizations] rules see,” said Hugh Njemanze, chief technology officer and senior vice president of research and development at ArcSight, based in Sunnyvale, Calif.

      The increased efficiency that Pethia hopes to get out of the CSISP would help the center respond more quickly to large-scale events such as the recent disclosure of a critical vulnerability in the software that runs most of Cisco Systems Inc.s routers and switches.

      And, thanks to a special feature in the ArcSight software, the organizations that contribute data to CERT will be able to strip out identifying data. This should help overcome one of the main objections that enterprises and other organizations raise to information sharing.

      The aversion to sharing sensitive data has been a key stumbling block for Information Sharing and Analysis Centers as well. ISACs, which are specific to industries such as IT or banking, were set up to encourage cooperation among members of each industry. But they have often been hampered by a lack of timely data because enterprises shy away from divulging sensitive data about attacks and other incidents.

      “We have to have this technology under the project if were going to have information sharing in any real way,” Pethia said. “There needs to be continuous progress on tools and tactics.”

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×