Open Cybersecurity Schema Framework
github.com
github.com
It must assume that all of the jargon words are already well known by its readers but it should definitely start with what problem a "schema framework" solves, which might then allow me to understand how this fixes it.
My concern with many high-level constructs is that they quickly become a bureaucratic exercise divorced from how people actually do their work so only corporates will use it even if it is super useful.
Basically every vendor has its own formats, fields and the way to centralize this data (syslog still rules...) and parse it in a common way (a source IP is a source IP in all tech) has been a pain point since forever. There is basically a whole industry around it, and a whole bunch of logstash parsers have been scarificed. Even better is that vendors have a tendency to change format once in a while, so even some you have will break way more often then they should. Many vendors dont see that as an issue as it locks their clients in.
This is another attempt at solving this. It does seem to have traction for once, and nobody wants to piss off Amazon, if they make this a prerequesite to be on their marketplace then it will actually work.
This sucked.
However, it really taught me how to skim logs for threats in the physical form super fast...
Without some institutional sponsors I have a hard time seeing this getting adopted--presumably you need cybersecurity companies to adopt the standard.
Edit: it looks like maybe AWS, based on the contributors!
Edit 2: Here we go: https://github.com/ocsf/governance/blob/main/Maintainers.md
* AWS
* Sumo Logic
* Rapid7
* Splunk
* Trend Micro
* IBM
* Tanium
* IronNet
Edit: Quote from the announcement...
Joining us in this announcement is an array of key security vendors, beginning with Splunk, the co-founder with AWS of the OCSF project, and also including Broadcom, Salesforce, Rapid7, Tanium, Cloudflare, Palo Alto Networks, DTEX, CrowdStrike, IBM Security, JupiterOne, Zscaler, Sumo Logic, IronNet, Securonix, and Trend Micro
I always worry when I see a project like this debut with very little meat on the bones, but a HUGE fleshed out "Code of Conduct" for contributors. What's driving this?
> OWASP SAMM
"Software Assurance Maturity Model"
This OCSF framework is trying to set out some standards on how that interop should happen. Put another way they're trying move from having plain text logs in Apache format to something more structured and formal that is (hopefully) easier to work with.
You might be thinking: "Well what could be easier and more open than plain text logs? Some grepping, some regex and we're golden."
The issue comes in that every single app that consumes those logs does so in a slightly different way and there's no standard (yadda yadda XKCD n+1 standards) enforceable format for handling those.
Seriously though. I'm all for any attempts to standardize schemas. Most SEIMS end up being a sprawling/proprietary/incompatible mess.
Can I ask why? What's wrong with the word "cyber"? The field is called "cybersecurity".