Advertisement
Promo

Industry watch Toolkit

Oasis to create an XML security standard

Martin LaMonica CNET News

Published: 28 May 2003 15:56 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Organisation for the Advancement of Structured Information Standards, or Oasis, on Wednesday announced the formation of the Web Application Security (WAS) technical committee, which will develop a model and a data format for describing security problems.

The planned standard will convey information via an XML document to classify and rate the risks of vulnerabilities once they are discovered. The companies participating in the Oasis WAS technical committee include NetContinuum, Qualys, Sanctum, and SPI Dynamics.

Right now, security advisories are published in a variety of formats, something that hampers effective communication across different organisations, Mark Curphey, chair of the Oasis WAS Technical Committee, said in a statement. Corporations, as well as government institutions and law enforcement agencies count on rapid access to security information in order to patch network holes that are vulnerable to hacks or break-ins.

"WAS will allow vulnerabilities to be published and received in a consistent manner. Risks will be universally understood by law enforcement agencies, government representatives, companies and organisations, regardless of which tools or technologies are used," Curphey said.

The need for a better way of sharing data on security risks is becoming increasingly important, particularly as the use of Web services takes hold, said Ron Schmelzer, an analyst at ZapThink.

Web services applications use standardised means to make it easier to share information between applications. That simplified data exchange will usher in many more security problems, which creates a growing need to effectively communicate vulnerabilities, he said.

Web services applications "will continuously need to be on the lookout for security vulnerabilities and interact with each other to provide a cohesive network of secured systems," said Schmelzer.

The proposed WAS specification will work in conjunction with other standards under development at Oasis, including the Application Vulnerability Description Language (AVDL). The WAS specification will define how information will be shared, while AVDL will describe the potential vulnerability.

By combining the WAS with AVDL, companies that track network security problems and have a common format to understand the severity of vulnerabilities, according to Oasis.

The WAS Technical Committee will consider related work from other groups and companies, including a similar language under development at the open-source Open Web Application Security Project.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
58 out of 131 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Discussions

Tezzer Tezzer

Nice to see but...

Saturday 26 December 2009, 10:28 AM

5 comments
NoThomas NoThomas

Sure I can

Saturday 26 December 2009, 2:01 AM

11 comments
NoThomas NoThomas

It does not need clarification...

Saturday 26 December 2009, 1:30 AM

10 comments
Video icon

Video


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters