Alien Vault shows a new face at RSA

Security has also had a strong tradition of quality open source solutions. I have run across several out here this week, but one I want to tell you about is OSSIM from AlienVault. OSSIM stands for Open Source Security Information Manager and has been around for a few years now. The project was started by the two co-founders of Alien Vault, Julio Casal and Dominique Karg. Both Julio and Dominique are from Madrid. Their open source project OSSIM has been a favorite of many in the security industry, especially MSSPs.
Now they have raised some real venture capital to Alien Vault and a new management team has been dropped in made up of the former exec team of Fortify, a security software inspection company that was purchased by HP. The new team has embraced the open source heritage of AlienVault and is leading with it in their mission to finally bring SEIM to the mid-market and SMB market.
I first met Karg a few years back on a bus back from Security BSides San Fran to the RSA show. I invited him to the Security Bloggers Meet up I help run at RSA every year. I have stayed in touch with Dominique since then and followed him as the CTO of AlienVault. Now he has taken on a new role as Chief Hacking Officer. I met with Donminique and his successor Roger Thornton today. Thornton is a founder of Fortify and a veteran of Silicon Valley.
Both Karg and Thornton agree that the idea of leading with OSSIM as an open source SEIM is a key part of the special sauce that makes AlienVault so promising. By packaging it with other open source security tools, they have put together an all in one solution that puts the power and insight of a SEIM into the hands of organizations that have not had the size or expertise to leverage it before.
Many people in security think that SEIM is the ultimate end game of security. It gathers information from all of the security technologies, products and inputs you have already installed or going to installed. It can perform analysis on security data, alert you to potential threats and give you actionable intelligence. However, SEIM has never reach critical mass because it is so complex to install, configure and maintain. Even large companies have invested millions of dollars only to have their SEIM project fail.
Alien Vault thinks they have cracked this nut though. They have started something called the AlienVault Open Threat Exchange to allow thier customers share threat data with the idea that sharing data makes us all stronger. They have beefed up their own lab team and will now be ramping up marketing.
There have been others who have tried to bring SEIM down market and frankly have failed. But could open source be the special sauce that allows AlienVault to go “where no SEIM has gone before”?




