The Unbearable Weight of Commercial Licensing. Combining Closed Systems with Open Source Defense

Keya Arestad (security architect)

BSides Las Vegas 2025 · Day 1

Overview

Kia Ard’s talk uses commercial licensing complexity and closed security products as a launch point for a defender-centered argument: when procurement, entitlements, and opaque alert taxonomies slow understanding, open platforms that preserve history, context, and community vetting can complement—not replace—enterprise tools. The session is explicitly opinionated but not ideological; Ard acknowledges strong commercial products while critiquing how licensing lock-in, short telemetry retention in SaaS consoles, and marketing-heavy alert names can degrade analyst efficacy. The proposed counterweight is MISP (Malware Information Sharing Platform), presented as an open-source threat sharing and correlation hub with rich taxonomy support, TLP-style sharing semantics, workflow automation, and integrations that can feed EDR, firewalls, and SIEM pipelines.

Watch on YouTube

Visual summary for The Unbearable Weight of Commercial Licensing. Combining Closed Systems with Open Source Defense by Keya Arestad
Visual summary for The Unbearable Weight of Commercial Licensing. Combining Closed Systems with Open Source Defense by Keya Arestad

Key moments

  1. 2:00 Speaker frames open internet history and why interop culture matters to modern defenders.
  2. 6:00 Commercial licensing complexity and analyst pain: opaque SKUs and confusing alert branding (“whack attack” example).
  3. 10:00 MISP origin story (~2011), NATO interest, and EU/CIRCL stewardship described as community-driven threat sharing.
  4. 14:00 Architecture narrative: commercial and open sensors feed MISP; validated intel fans out to EDR/firewalls/SIEM-style tools.
  5. 18:00 Taxonomies, MITRE ATT&CK integration, galaxies, and correlation features for long-horizon analyst questions.
  6. 26:00 Live MISP UI: correlation counts, related events, IDS flags, and feed hits on shared IOCs.
  7. 28:00 Free-text IOC import demo (Unit 42 paste) showing automatic parsing, tagging, and IDS suggestions.
  8. 30:00 Q&A: trust establishment between sharing communities before auto-blocking; ISAC relationships and signing keys.

The Unbearable Weight of Commercial Licensing. Combining Closed Systems with Open Source Defense

Speakers: Kia Ard, Security Practitioner (vendor-neutral consulting, EDR/detection engineering, and analyst background as stated in talk)

Conference: BSides Las Vegas

YouTube: https://www.youtube.com/watch?v=QuuQIRGB6p0

Overview

Kia Ard’s talk uses commercial licensing complexity and closed security products as a launch point for a defender-centered argument: when procurement, entitlements, and opaque alert taxonomies slow understanding, open platforms that preserve history, context, and community vetting can complement—not replace—enterprise tools. The session is explicitly opinionated but not ideological; Ard acknowledges strong commercial products while critiquing how licensing lock-in, short telemetry retention in SaaS consoles, and marketing-heavy alert names can degrade analyst efficacy. The proposed counterweight is MISP (Malware Information Sharing Platform), presented as an open-source threat sharing and correlation hub with rich taxonomy support, TLP-style sharing semantics, workflow automation, and integrations that can feed EDR, firewalls, and SIEM pipelines.

The narrative arc moves from internet/open-source lineage (RFC culture, early community contributions) through market growth and RSA-style vendor floors, into concrete pain stories (Microsoft licensing diagrams, a recurring “whack attack” false-positive mystery), and then into MISP history, governance (NATO/EU/CIRCL), deployment scale (approximate org counts via internet exposure scans—caveat included), and a live UI walkthrough showing correlations, IDS flags, related events, and feed hits. Q&A covers operational maintenance, PHP hardening lessons from MISP’s self-audit, and the non-negotiable need for trust between sharing partners before automated blocking.

The talk also briefly nods to commercial sponsorship of open tools—Zeek sponsored by Corelight is named—as an example of hybrid models where open cores and vendors co-evolve rather than sitting in opposition.

Background

▶ Watch: Speaker frames open internet history and why interop culture matters to moder... (2:00)

Ard opens with audience polling (analysts, IR, researchers) and situates cybersecurity’s growth against the open origins of the internet: RFCs, collaborative protocol design, and figures such as Torvalds and Stallman, alongside Elizabeth Feinler’s role in early naming/navigation work (as described in the talk). The point is not hagiography; it is to remind defenders that interop and shared language are native to networked defense, not an accident of vendor product strategy.

Commercial ecosystems expand budgets and tooling, but Ard argues they also introduce friction: complex SKU matrices (referencing Aaron Denning’s Microsoft licensing visualization site—attributed in talk as a Microsoft employee’s personal project), sales-gated technical depth, and alerts that lack analyst-grade context. The “whack attack” example illustrates how a label can echo across forums, FP discussions, and vendor marketing without converging on a crisp, testable meaning—while defenders still must decide block vs allow under time pressure.

The licensing critique is not an argument that enterprises should refuse commercial support. It is an argument that complexity has a security cost: when the path from “what did we buy?” to “what telemetry can we access?” requires a project plan, teams under-invest in baseline comprehension. That comprehension gap shows up later as mis-tuned detections, over-blocking, and slow IR because analysts cannot map an alert’s semantics to a concrete artifact or behavior. Ard couples that observation with a second commercial pain point: SaaS operational consoles that expire historical visibility. For mature SOCs, history is not nostalgia—it is the difference between recognizing a repeat campaign and treating every sighting as novel.

Key Findings

▶ Watch: MISP origin story (~2011), NATO interest, and EU/CIRCL stewardship described ... (10:00)

1) SaaS retention blinds long-horizon correlation. EDR/NDR/SaaS consoles often age out data in 30–90 day (or similar) windows. Ard argues that many human-driven incident patterns only become obvious across months: repeat offenders, chronic clickers, and recycled IOCs. A durable, queryable IOC store can answer “have we seen this before?” when the primary console no longer remembers.

2) MISP’s purpose is sharing without duplicate labor. Origins trace to Christophe Vandeplas (~2011) seeking to reduce repeated malware research collisions (same hash rediscovered independently). NATO interest and funding appear in the story as validation of operational utility; current stewardship references EU/CIRCL (as stated on slides).

3) MISP is widely deployed and multi-hosted. Ard cites on the order of ~6,000 organizations discoverable via scanning approaches (methodology caveat: domain names and internet exposure are imperfect ground truth). Deployments span clouds and air-gapped environments; use cases include ISAC-style communities.

4) Taxonomies and MITRE alignment improve analyst speed. MISP ships integrations for MITRE ATT&CK and many other taxonomy packs. Tagging and galaxy constructs help bundle related knowledge so analysts do not rebuild structure per incident.

5) Trust and workflow matter more than feed volume. The IDS checkbox on attributes signals “others should block,” which is powerful and dangerous. Workflows, correlate flags, TLP boundaries, and object grouping help contain mistakes. Ard stresses reviewing partner quality before automated enforcement.

6) Self-audit surfacing configuration weaknesses. In Q&A, Ard notes MISP’s audit flagged a world-readable PHP config on a fresh Ubuntu install—an example of how running the platform teaches host hardening lessons quickly.

Technical Deep Dive

▶ Watch: Taxonomies, MITRE ATT&CK integration, galaxies, and correlation features for ... (18:00)

Object model and analyst workflow

MISP events bundle attributes and objects (grouped IOCs with shared context). In the demo, correlation counts surface related activity across events (e.g., fictional user personas like Mr. Pink used as teaching examples). Related events show parallel storylines (different compromise narratives that share IOCs). Feed hits connect local observations to external feeds (e.g., URLhaus mentioned as an open feed exemplar).

IDS flag semantics

When IDS is set, other communities can treat an attribute as suitable for blocking or detection deployment. Ard emphasizes this is a social + technical contract: downstream automation should be paired with governance about who may flip that bit and how disputes are resolved.

Ingestion paths

Free-text import is demonstrated with a pasted Unit 42 IOC block (as described): MISP parses mixed IOC types, proposes tags, and pre-checks IDS suitability. File upload paths hash binaries and support encryption with a supplied password when malware samples are involved—paired with an OPSEC reminder not to exfiltrate sensitive artifacts casually.

Integrations (conceptual)

Ard presents a diagrammatic story: commercial and open tools feed intel into MISP; analysts validate; automation fans out via API/webhooks to defensive controls (Defender, Sentinel, CrowdStrike named as examples). The point is orchestration around human validation, not blind feed piping.

Governance constructs

TLP-style sharing boundaries and inheritance across objects/events appear as first-class concepts—important for utilities that might store highly sensitive operational data alongside IOCs.

Community opinion propagation

Ard describes a mechanism where analysts can attach opinions to IOC quality; those opinions can sync across trusting instances, nudging upstream producers to correct or refine data. That is a socio-technical control: it rewards humility (“this IOC might not belong here”) and punishes feed arrogance if communities enforce norms. It also implies political work—disagreements become visible, and incident response teams must decide how to handle public contradiction of a peer organization’s call.

“MISP as database”

A recurring practical point is that many teams use MISP less as a glossy portal and more as a structured IOC database with APIs feeding enforcement tiers. That pattern matters for defenders designing SOAR playbooks: if your automation cannot cite provenance (who asserted maliciousness, under what TLP, with what confidence), you will struggle with post-incident review. MISP’s event/attribute model is not perfect, but it pushes teams toward explicit assertions rather than implicit spreadsheet folklore.

Demo / Proof of Concept

▶ Watch: Live MISP UI: correlation counts, related events, IDS flags, and feed hits on... (26:00)

After a brief A/V detour (duplicate display troubleshooting with room help), Ard navigates a self-hosted MISP instance on the internet (as stated). The demo highlights:

  • Correlation columns and drilling into a highly correlated persona/event.
  • Related events tying multiple narratives to shared IOCs.
  • Feed hits aligning local IOCs with external reputation data.
  • IDS selections aligned to defensive actions.
  • File upload hashing workflow and cautions about analyst workstation safety.

Ard offers test logins to interested attendees (as stated verbally).

Defensive Implications

▶ Watch: Q&A: trust establishment between sharing communities before auto-blocking; IS... (30:00)

For SOC leaders, the talk supports a defense-in-depth data strategy: commercial consoles for real-time response, durable intel repository for historical correlation, and explicit trust boundaries for automated blocking. For CTI functions, it argues for community participation with written sharing agreements—not just consuming anonymous feeds.

For procurement, the implicit challenge is to buy interfaces and export rights that do not trap telemetry you will need a year later during regulatory or insurance review. Licensing cost is not only dollars; it can be latency and opacity.

For appsec/supply chain parallels (not the speaker’s focus), the same pattern holds: tools that hide internals create security debt when incidents demand forensic clarity.

Leaders should also treat internet-exposed MISP instances as both a collaboration feature and an attack surface—Ard notes pounding on APIs in logs. That is a standard tradeoff: federation requires reachability; reachability requires patch discipline, auth hardening, and monitoring. The Q&A’s PHP permission example is a small but representative lesson: platforms do not absolve you of OS baseline ownership.

Key Takeaways

  • Commercial stacks solve many problems, but licensing complexity and retention windows can become security liabilities for analysts.
  • MISP provides open, community-governed structure for IOC lifecycle, taxonomies, and cross-event correlation.
  • Automation (IDS flags, webhooks) must be paired with trust and review—mistakes scale instantly.
  • MITRE and extensive taxonomy packs reduce repeated manual labeling work.
  • Self-hosting teaches ops security lessons quickly (configuration audits, exposure).
  • Open-source and commercial can coexist: the goal is integration, not purity.

About the Speaker(s)

Kia Ard introduces roughly a decade of infosec experience: early vendor-neutral security consulting with broad operational assignments, followed by endpoint detection work investigating suspicious events, detection engineering, and security analyst roles. Ard states these opinions are personal and not necessarily those of any single employer. The bundle metadata lists Speakers: Unknown; the talk audio identifies the presenter as Kia Ard.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A practitioner-friendly MISP advocacy talk with a credible live demo and honest trust/automation caveats, but limited new research for audiences already running modern TIP programs.

Heather Calloway (CISO) — STRONG ACCEPT

The talk translates threat intelligence operations into governance decisions: data retention, sharing boundaries, and automation risk—topics CISOs must own alongside SOC leads.

→ Top-rated talks at BSides Las Vegas 2025

All talks from BSides Las Vegas 2025