Welcome Guest. | Log In| Register | Membership Benefits
April 14, 2003 (11:18 AM EDT)

OASIS Takes Up Interoperability Spec For Security Apps

OASIS Takes Up Interoperability Spec For Security Apps

By Antone Gonsalves ,

Security vendors on Monday unveiled a proposed standard that would enable their products to communicate with one another, giving enterprises the option of mixing products rather than buying application suites from one vendor.

The application vulnerability description language, or AVDL, was announced at the security-focused RSA Conference in San Francisco.

The Organization for the Advancement of Structured Information Standards, an international standards body known as OASIS, has established a technical committee for developing AVDL. The committee, which is scheduled to hold its first meeting May 15, is expected to release a final AVDL specification by the fourth quarter of this year.

Four categories of security software could use AVDL for communications: assessment tools, firewalls, patch management, and reporting applications. AVDL would define in extensible markup language (XML) the information each tool could use in coordinating network protection.

For example, an assessment tool that locates an application vulnerability could pass that information to the firewall, so it could block an intruder from taking advantage of the potential security breach. In addition, the information could be sent to a reporting tool that notifies the network administrator of the problem.

While the XML file could contain information related to several security products, each application would parse the file to extract only relevant information, said Brian Cohen, chief executive of Atlanta-based SPI Dynamics. SPI Dynamics joined Citadel Security Software, GuardedNet, NetContinuum, and Teros in submitting the standard proposal to OASIS.

For enterprises, AVDL would give the option of mixing software from several vendors, instead of buying a product suite from one company, Ronald Schmelzer, analyst for high-tech researcher ZapThink LLC, said. "For the people actually buying these tools, the benefits they're going to see is that they're going to have increased choice among vendors," he said.

While not directly related to security issues pertaining to web services, AVDL may become helpful in dealing with new vulnerabilities related to the emerging technologies. "I would argue that Web services will probably introduce quite a few [new vulnerabilities]," Schmelzer said.


CAREER CENTER
Ready to take that job and shove it?
SEARCH
Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.

Advertisement


TechSearch for related stories



Specialty Resources

Featured Microsite


Microsites

Featured Topic

Additional Topics

Crush The Competition

TechWeb's FREE e-mail newsletters deliver the news you need to come out on top.

Techencyclopedia

Get definitions for more than 20,000 IT terms.

Techwebcasts

Editorial and vendor perspectives


Vendor Resources


Focal Points