Is it possible for enterprises to establish an interconnected security framework, where all disparate elements of security technology no longer stand alone, but are constantly communicating with each other? That is the goal of the ESUKOM project, for which NCP engineering is a core member. To learn more about this endeavor, we spoke to Jens Lucius, QA manager and trainer at NCP.
Q: Last year, NCP became a member of the Trusted Computing Group, in part to work on the ESUKOM project, which aims to develop real-time security solutions for enterprise networks based upon the correlation of metadata. Can you give us an update on what’s happened on the project in the last year?
Jens Lucius: Well, the project is using the TCG (Trusted Computing Group) IF-MAP Standard to try to achieve real-time security in networks. Till now, many network security components worked as standalones, so a network administrator had no chance of seeing the “whole picture” of network security. The ESUKOM project is trying to change that using IF-MAP.
IF-MAP is essentially a common database for network and security systems on the network, sharing information and acting on that information. All ESUKOM participants are integrating IF-MAP into their products or are adding IF-MAP support for OpenSource products, like snort (intrusion detection). Also the University of Applied Science Hannover is developing an IF-MAP server and the prototype of a correlation engine that dynamically detects “glitches” in the network or network usage, and reports this information back to the IF-MAP.
The next step within the project is the integration of a demonstrator showing a network access scenario in a hospital that is under attack by an intruder trying to get classified information and how the usage of IF-MAP is helping prevent that.
NCP has already integrated IF-MAP in the latest release 8.10 of the NCP Secure VPN Server and most of the open source components are available at the ESUKOM web-page. We have also compiled a small technical paper describing the ESUKOM project.
Stay tuned for our continued conversation with Lucius on this potentially transformative project.