Version: 2008
  • On TV.com: SETH MACFARLANE 2 raunchy 4 Microsoft

May 28, 2003 8:38 AM PDT

Security firms seek common tongue

  • Post a comment
Related Stories

Security key goal for Web services group

February 4, 2003

Web services specs focus on security

December 18, 2002
A group of computer security companies plans to create a standardized way to share information on potential network security problems.

The Organization for the Advancement of Structured Information Standards, or OASIS, on Wednesday announced the formation of the Web Application Security (WAS) technical committee, which will develop a model and a data format for describing security problems. The planned standard will convey information via an XML document to classify and rate the risks of vulnerabilities once they are discovered.

The companies participating in the OASIS WAS technical committee include NetContinuum, Qualys, Sanctum, and SPI Dynamics.

Right now, security advisories are published in a variety of formats, something that hampers effective communication across different organizations, Mark Curphey, chair of the OASIS WAS Technical Committee, said in a statement. Corporations, as well as government institutions and law enforcement agencies count on rapid access to security information in order to patch network holes that are vulnerable to hacks or break-ins.

"WAS will allow vulnerabilities to be published and received in a consistent manner. Risks will be universally understood by law enforcement agencies, government representatives, companies and organizations, regardless of which tools or technologies are used," Curphey said.

The need for a better way of sharing data on security risks is becoming increasingly important, particularly as the use of Web services takes hold, said Ron Schmelzer, an analyst at ZapThink.

Web services applications use standardized means to make it easier to share information between applications. That simplified data exchange will usher in many more security problems, which creates a growing need to effectively communicate vulnerabilities, he said.

Web services applications "will continuously need to be on the lookout for security vulnerabilities and interact with each other to provide a cohesive network of secured systems," said Schmelzer.

The proposed WAS specification will work in conjunction with other standards under development at OASIS, including the Application Vulnerability Description Language (AVDL). The WAS specification will define how information will be shared, while AVDL will describe the potential vulnerability.

By combining the WAS with AVDL, companies that track network security problems and have a common format to understand the severity of vulnerabilities, according to OASIS.

The WAS Technical Committee will consider related work from other groups and companies, including a similar language under development at the open-source Open Web Application Security Project.

advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.72%) 73.00 10,270.47
S&P 500 (0.57%) 6.24 1,093.48
NASDAQ (0.88%) 18.86 2,167.88
CNET TECH (0.63%) 9.86 1,587.17
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right