Could IF-MAP Accelerate Big Data Security Analytics?

Undervalued TNC standard may be a perfect fit for knowledge-driven network security

Author(s): Jon Oltsik

Published: January 23, 2013

Based upon recent ESG research data, it is easy to conclude the big data security analytics is inevitable.  In fact, large public sector and commercial organizations are already experimenting with technologies like Hadoop, Splunk, and PacketPig to bring the security and big data analytics world together.

While big data security analytics will roll out faster than most people think, there are bound to be some speed bumps along the way.  In fact, some of the more annoying short-term issues will be around basic operational tasks like collecting, normalizing, and sharing security data in a multitude of formats, schemas, and syntaxes.

These issues reared their ugly head in a recent ESG research project:

  • 54% of large organizations have “significant difficulties” or “some difficulties” with security data normalization
  • 54% of large organizations have “significant difficulties” or “some difficulties” with security data capture
  • 52% of large organizations have “significant difficulties” or “some difficulties” with security data sharing

How can the industry address these problems?  By providing standard data formats and APIs that eliminate data integration limitations and customization requirements. 

I’ve blogged about industry standards before.  For example, MITRE has done a great job with Common Vulnerabilities and Exposures (CVEs) but support for its many other security standards is fairly limited.  It seems like a no-brainer to me that leading security vendors like Check Point, Cisco, HP, IBM, McAfee, RSA, Symantec, and Trend Micro should get more involved. 

Aside from the MITRE standards, here’s another suggestion:  In order to accelerate big data security analytics, the security industry should get behind the Interface for Metadata Access Points (IF-MAP) standard introduced by the Trusted Network Connect (TNC) sub-group of the Trusted Computing Group (TCG) in 2008.  Juniper is a big IF-MAP supporter as is Enterasys and Infoblox.

Why is IF-MAP a good fit for big data security analytics?  In simple terms, IF-MAP allows devices to share information in a standard well-defined way.   What’s more, IF-MAP provides this data sharing for a broad range of use cases including physical security, cloud computing, grid computing, etc.  If nothing else, IF-MAP makes a lot of sense in the era of BYOD and mobile computing.

IF-MAP isn’t a big data security analytics requirement but it could go a long way toward making data collection, normalization, and sharing a bit easier.  This is especially important because there aren’t enough trained security professionals available to labor through this with manual processes and custom coding.  Furthermore, IF-MAP isn’t just about security analytics; it’s about security policy enforcement automation.  Once again this could help reduce time, labor, and money – and make us all more secure.

 

Comments (0)

Post Comment



  • Leave this field empty

*All views and opinions expressed in ESG blog posts are intended to be those of the post's author and do not necessarily reflect the views of Enterprise Strategy Group, Inc., or its clients. ESG bloggers do not and will not engage in any form of paid-for blogging. Click to see our complete Disclosure Policy.

Phone:
508-381-5166

E-mail

Jon Oltsik is an ESG senior principal analyst and the founder of the firm’s Information Security and Networking services. With 25 years of technology industry experience, Jon is widely recognized as an expert in threat and security management as well as all aspects of network security. Recently, Jon has been an active participant with cybersecurity issues, legislation, and technology within the U.S. federal government. Prior to joining ESG, Jon was the founder and principal of Hype-Free Consulting. He has also held senior management positions at GiantLoop Network, Forrester Research, Epoch Systems, and EMC Corporation.

Full Biography

NEWSLETTER

Enter your email address, and click subscribe