Connect2Data helps cut delays in vulnerability reporting
SIDN Fund supports the development of an open-source tool for the automated collection of registration data.
SIDN Fund supports the development of an open-source tool for the automated collection of registration data.
Getting relevant cybersecurity information to the right organisations depends on clarity about which of them own which IP addresses and domain names. However, in large and complex organisations, gathering and maintaining that kind of information often isn’t easy. So Connect2Trust teamed up with the National Internet Providers Management Organization (NBIP) to start the Connect2Data project. Together they have created a straightforward tool that enables organisations to automatically gather the information they need from their own systems.
Connect2Trust and NBIP have been working on inter-organisation information sharing for 10 years. They gather information from various sources and automatically pass it on to the appropriate organisations. Automation is particularly important for large, complex organisations, explains Raymond Bierens, Chair of Connect2Trust.
“We always say it’s about going from the ability to act to action,” he says. “You can give people information, but that doesn’t mean that they actually know what to do with it.” Therefore, as well as automating information sharing, Connect2Trust and NBIP are constantly working on networks through which organisations and experts can make contact, share knowledge and collaborate.
Connect2Data is a response to a practical problem. Getting information to the right organisations depends on technical information about IP addresses and domain names. Where large organisations are concerned, such information is often held in various systems and by various suppliers.
“Some outsource things, while others handle them in house,” says Raymond. “Having the information you need means going through each individual system, putting together the data you extract, and then delivering it in the right format. Traditionally, that’s meant a lot of manual work, so it was sometimes done only once a year. Given the speed at which the electronic world is changing around us, once a year simply isn’t enough. It’s something you really want to be doing once a month.”
Two straightforward but crucial questions therefore arose. First, how can we automatically gather technical data that’s spread across multiple systems and service providers? Second, how can the collected data be assembled into a file suitable for processing in the self-service portals of the National Cyber Security Centre (NCSC), NBIP or Connect2Trust? In response to those questions, Connect2Trust and NBIP decided to team up and develop the tool that became Connect2Data.
The need for a resource of the kind they envisaged was emphasised when the project was announced. Collaboration with the NCSC led to collaboration within the Cyclotron Programme and to various presentations to organisations in the NCSC’s target audience that are covered by the new Cyber Security Act.
The tool is now finished. Connect2Trust and NBIP have tested it from 2 perspectives: that of an internet provider that receives information from NBIP, and that of a multinational that receives information from Connect2Trust. The developers also looked at the security of the upload process, the management of data usage responsibilities, and the obligations that anyone using the tool should have. A total of 10 organisations took part in the testing.
Connect2Data works with a library detailing how the relevant data can be harvested from popular products and systems. Whenever an organisation adds a link for a product that’s not yet in the library, the arrangement is that the addition is available to all the other users.
During development, a question arose that no one had anticipated. The IP address of a system intended to receive threat information may not legally belong to the organisation whose system it is. Raymond illustrates the issue with an example. “If you’ve got a phone, the device itself is yours, but you rely on someone else’s services to make use of it. So, whose is the IP address? Yours or the service provider’s?”
In other words, the IP addresses that are relevant from a security viewpoint aren’t necessarily the same as the ones that an organisation is entitled to register and communicate. “What I want to know for defensive purposes isn’t whether I can legally communicate that an IP address.” SIDN Fund has joined forces with Connect2Trust, NBIP and the NCSC to get that problem investigated for a large number of different usage scenarios.
The project is divided into 2 parts. The receiving side, i.e. the portal where files are received and checked, has been set up by Connect2Trust itself. Meanwhile, on the distribution side, a grant from SIDN Fund has enabled development of the new tool and its testing with a 10-organisation user group.
It’s not the first time that NBIP, Connect2Trust and SIDN Fund have worked together. The trust previously obtained a pioneering project grant to support development of the information sharing platform. “At that time, the emphasis was on the core of the platform,” clarifies Raymond. “Now the focus has shifted to how we can feed information to the platform as quickly, accurately and frequently as possible.”
Mieke van Heesewijk, Programme Manager at SIDN Fund, explains why the Fund is pleased to back the initiative. “Many organisations already have the data they need to respond more quickly to security risks. However, gathering the data together and keeping it updated can be complicated. Connect2Data demonstrates how a practical open-source solution can contribute to a more secure and resilient digital ecosystem. That aligns perfectly with SIDN Fund's mission to enable internet projects with societal impact.
Before Connect2Data is released as an open-source tool, Connect2Trust wants to make proper arrangements regarding its management and ownership. The trust will continue to support the tool, but wants to prevent a situation arising where its management is dependent on multiple organisations. “The question is, how will the tool be picked up or even extended by the community,” says Raymond. “So, for the next year, we’ll monitor how often it’s downloaded, and whether organisations are actually using it.”
Meanwhile, Connect2Data has become part of a wider movement. In the Netherlands, various actors are working on a cyber-resilience network, through which NBIP, Connect2Trust and other organisations can deploy their platforms to support other collaborative initiatives with similar goals. And the new tool can contribute directly to that development. “The data we collect using Connect2Data will be useful for future SIDN projects in the same information domain.”
Read more articles about projects that contribute to a stronger internet.