Blog Partners

Introducing ETHOS: the Emerging Threat Open Sharing Platform

NetRise is thrilled to be working alongside a number of great organizations in the OT Security space on ETHOS, an open-source, community-driven tool with the goal of sharing and comparing OT/ICS data to identify anomalies and indicators of new attacks in real time.

Initial founding members of ETHOS include NetRise, 1898 & Co., ABS Group, Claroty, Dragos, Forescout, Network Perception, Nozomi Networks, Schneider Electric, Tenable, and Waterfall Security.

The open-source project will be hosted on GitHub, with the goal of releasing the first working proof of concept before 2024. Nozomi Networks has volunteered to host the first ETHOS server for beta testing.

At a high level, ETHOS will allow organizations to opt-in to sharing and receiving anonymized threat intelligence and anomalies that are detected in other ETHOS members' environments to allow for real-time monitoring of new threats. At NetRise, we are looking to bring our device- and firmware-level analysis capabilities to share SBOMs, configuration information, credential and cryptographic risk information, and more with this initiative.

In the future, any company or government agency will be able to independently host an ETHOS server. The host can allow selected participants and clients to connect and share information. To participate in an ETHOS server and receive notifications, an entity must also have an ETHOS client built with integration capabilities to send data.

Stay tuned for more updates as we continue to work together to build out this community-driven capability!

About NetRise
NetRise is the software supply chain security company that exists to eliminate blind trust in software forever. By identifying every component in each binary image across firmware, kernels, operating systems, containers, and applications, NetRise exposes the full stack of inherited risk that source-based tools, vendor SBOMs, and questionnaires cannot see. Non-code related risk uncovered includes hidden dependencies, cryptographic artifacts, misconfigurations, secrets, among others. Global enterprises that produce and consume software, including government agencies, rely on NetRise to validate what they ship and what they run. When unforeseen software vulnerabilities are exploited by bad actors, NetRise answers the question, “where am I exposed?” enabling rapid identification, prioritization, mitigation, and policy updates, reducing material risk to the business. https://www.netrise.io/
Press & Media Contact
Danielle Ostrovsky
Hi-TouchPR
Ostrovsky@Hi-TouchPR.com

Stay up to date with the news

Sign Up To Get Our Free Insights Delivered To Your Inbox

Real person here 👉