Malware Information Sharing Platform
   HOME

TheInfoList



OR:

MISP Threat Sharing (MISP) is an
open source Open source is source code that is made freely available for possible modification and redistribution. Products include permission to use the source code, design documents, or content of the product. The open-source model is a decentralized sof ...
threat intelligence platform Threat Intelligence Platform (TIP) is an emerging technology discipline that helps organizations aggregate, correlate, and analyze threat data from multiple sources in real time to support defensive actions. TIPs have evolved to address the growing ...
. The project develops utilities and documentation for more effective threat intelligence, by sharing indicators of compromise. There are several organizations who run MISP instances, who are listed on the website.


History

This project started around June 2011 when Christophe Vandeplas had a frustration that way too many Indicators of Compromise (IOCs) were shared by email, or in pdf documents and were not parsable by automatic machines. So at home he started to play around with CakePHP and made a proof of concept of his idea. He called it CyDefSIG: Cyber Defence Signatures. Mid July 2011 he presented his personal project at work ( Belgian Defence) where the feedback was rather positive. After giving access to CyDefSIG running on his personal server the Belgian Defence started to use CyDefSIG officially starting mid August 2011. Christophe was then allowed to spend some time on CyDefSIG during his work-hours, while still working on it at home. At some point
NATO The North Atlantic Treaty Organization (NATO, ; french: Organisation du traité de l'Atlantique nord, ), also called the North Atlantic Alliance, is an intergovernmental military alliance between 30 member states – 28 European and two No ...
heard about this project. In January 2012 a first presentation was done to introduce them in more depth to the project. They looked at other products that the market offered, but it seemed they deemed the openness of CyDefSIG to be of a great advantage. Andrzej Dereszowski was the first part-time developer from NATO side. One thing led to another and some months later NATO hired a full-time developer to improve the code and add more features. A collaborative development started from that date. As with many personal projects the license was not explicitly written yet, it was collaboratively decided that the project would be released publicly under the Affero GPL license. This to share the code with as many people as possible and to protect it from any harm. The project was then renamed to MISP: Malware Information Sharing Project, a name invented by Alex Vandurme from NATO. In January 2013 Andras Iklody became the main full-time developer of MISP, during the day initially hired by NATO and during the evening and week-end contributor to an open source project. Meanwhile other organisations started to adopt the software and promoted it around the CERT world (CERT-EU, CIRCL, and many others). Nowadays, Andras Iklody is the lead developer of the MISP project and works for CIRCL. As the MISP project expanded, MISP is not only covering the malware indicators but also fraud or vulnerability information. The name is now MISP Threat Sharing, which includes the core MISP software and a myriad of tools (PyMISP) and format (core format, MISP taxonomies, warning-lists) to support MISP. MISP is now a community project led by a team of volunteers. Material was copied from this source, which is available under
Creative Commons Attribution-ShareAlike 3.0 Unported
license.


Funding

The project is funded by the
European Union The European Union (EU) is a supranational political and economic union of member states that are located primarily in Europe. The union has a total area of and an estimated total population of about 447million. The EU has often been des ...
(through the
Connecting Europe Facility The Connecting Europe Facility (CEF) is a European Union fund established in 2014 for infrastructure investments (in particular the Trans-European Networks) across the union in transport, energy, digital and telecommunication projects, which aims a ...
) and th
Computer Incident Response Center Luxembourg


Intelligence Integration

Indicators of compromise which are managed by MISP may originate from a variety of sources; including internal incident investigation teams, intelligence sharing partners or commercial intelligence sources. Commercial sources with integration to MISP includ
Symantec's DeepSight Intelligence (now called Broadcom)
Kaspersky threat feeds and McAfee Active Response. MISP integrations with open-source and commercial threat intelligence platforms includ
the ThreatQuotient Platform
an
EclecticIQ Platform


References


External links

*{{official website
IETF draft-dulaunoy-misp-taxonomy-format-06

Building and designing MISP: A practical information-sharing tool for cybersecurity and fraud indicators

Privacy Aware Sharing of IOCs in MISP

MISP: Sharing Done Differently
Data security Computer security software Free security software