OpenAppID Language Enables Rapid Community Development of Application Controls
Harnessing the power of open source and community, Cisco announced that the company is delivering the ability to create and integrate new open source application identification capabilities into its Snort engine through the release of OpenAppID. Open source application detection and control allows users to create, share and implement custom application detection so that they can address new app-based threats as quickly as possible.
OpenAppID provides application visibility, accelerates development of application detectors, and controls and empowers the community to share detectors for greater protection. As new applications are developed and introduced into corporate environments at an unprecedented rate, this new language provides users with increased flexibility to control new or custom apps on the network. OpenAppID is especially important for organizations utilizing custom-built or specialized applications and those in highly regulated industries that require the highest levels of identification and control.
OpenAppID will accelerate and expand the breadth of application detection, by facilitating open community sharing and enhancement of new application detectors. It also supports the following critical capabilities:
Application Detection/Reporting OpenAppID enables Snort users to utilize the new OpenAppID detectors to detect and identify applications, and to report on application use.
Application Context associated with network intrusion events By providing application-layer context with security-related events, OpenAppID helps to enhance analysis and speed remediation.
Actionable Application Detection and Control OpenAppID enables Snort to block or alert on detection of certain applications. This helps to reduce risks by managing total threat surface.
Martin Roesch, creator of Snort and Vice President and Chief Architect, Cisco Security Business Group, said, “Open source is very important because it creates real collaboration and trust between vendors and the experts that are tasked with addressing advanced and aggressive threats. By open sourcing application visibility and control, Cisco is empowering the community to create technically superior solutions to address their most complex and unique security challenges.”