The failure of the security industry
scmagazine.com
scmagazine.com
Add-on security never really works except inept opponents, but it's a very profitable business.
Anyone have any thoughts on how successful I might be if I tried to build a platform that would take data from multiple vendors to perform analysis? Would the vendors be amenable, or would they fight against me?
Ultimately what we need here are open standards at all levels, that is the only way you can have a stable interaction of systems and keep the market open and competitive.
"STIX™ is a collaborative community-driven effort to define and develop a standardized language to represent structured cyber threat information. The STIX Language intends to convey the full range of potential cyber threat information and strives to be fully expressive, flexible, extensible, automatable, and as human-readable as possible. All interested parties are welcome to participate in evolving STIX as part of its open, collaborative community."
Needless to say, my interactions with antivirus companies have rarely been positive.
1. http://en.wikipedia.org/wiki/Security_information_and_event_...