Hi Joe,

 

Both formats satisfy the NIST VDR data requirements identified in SP 800-161 
RA-5, IMO. 

 

REA uses an explicit model, listing each component and its vulnerability search 
status, including those with no vulnerabilities reported. It also supports SPDX 
and CycloneDX SBOM formats.

 

The CycloneDX VDR format uses an implicit model, listing only those components 
with reported vulnerabilities. I believe it can support both SPDX and CycloneDX 
SBOM formats, but I’ve not seen an SPDX representation.

 

The easiest way to see the differences is to view an example of each:

 

REA VDR:

https://raw.githubusercontent.com/rjb4standards/REA-Products/master/SBOMVDR_JSON/VDR_118.json
 

 

CycloneDX VDR: 

https://raw.githubusercontent.com/rjb4standards/REA-Products/master/CDXVEX/CDX14.xml
 

 

Thanks,

 

Dick Brooks

  

Active Member of the CISA Critical Manufacturing Sector, 

Sector Coordinating Council – A Public-Private Partnership

 

 <https://reliableenergyanalytics.com/products> Never trust software, always 
verify and report! ™

 <http://www.reliableenergyanalytics.com/> 
http://www.reliableenergyanalytics.com

Email:  <mailto:[email protected]> 
[email protected]

Tel: +1 978-696-1788

 

From: [email protected] <[email protected]> On Behalf Of Joseph Silvia via 
lists.spdx.org
Sent: Wednesday, April 12, 2023 8:14 AM
To: [email protected]
Cc: 'Phil Odence' <[email protected]>
Subject: Re: [spdx] SPDX Gen Meeting Follow up- Mistake and Thanks

 

Hello Dick,

 

You stated the REA has offered to withdraw it’s VDR format if the industry 
agrees to endorse the CycloneDX VDR format. Can you provide more details on the 
similarities and differences between the REA and CycloneDX VDR format?

 

Thanks,

Joe

 

Joseph D. Silvia
Director Software Quality Training and Consulting
Oriel STAT A MATRIX | Improving Workplace Performance Since 1968

1055 Thomas Jefferson St. NW, Suite 304 

Washington, DC 20007

Office:732.906.6142 Mobile:781.526.5636 |  <mailto:[email protected]> 
[email protected]  

View Our  
<http://ww2.orielstat.com/rs/orielstatamatrix/images/OrielSTATTrainingCatalog.pdf>
 Training Catalog

Follow us:  <http://www.linkedin.com/company/oriel-stat-a-matrix> LinkedIn |  
<http://www.orielstat.com/blog/> Blog |  <http://www.orielstat.com/> 
orielstat.com

 

This message and any attachments are intended only for the use of the addressee 
and may contain information that is privileged and confidential.  If you are 
not the intended recipient or an authorized representative of the intended 
recipient, you are hereby notified that any dissemination of this communication 
is strictly prohibited.  If you have received this communication in error, 
notify the sender immediately by return email and delete the message and any 
attachments from your system.

 

From: [email protected] <mailto:[email protected]>  <[email protected] 
<mailto:[email protected]> > On Behalf Of Dick Brooks
Sent: Wednesday, April 12, 2023 7:55 AM
To: [email protected] <mailto:[email protected]> 
Cc: 'Phil Odence' <[email protected] <mailto:[email protected]> >
Subject: Re: [spdx] SPDX Gen Meeting Follow up- Mistake and Thanks

 

May,

 

Thank you for the quick response.

 

With regard to testing; some of the spdx tool vendors conduct interoperability 
testing by sharing artifacts and reporting on any issues encountered. The 
DocFest is a formal version of this testing. Would Palo Alto Networks be 
willing to share their SPDX artifacts, confidentially, with spdx tool vendors 
for interoperability testing purposes only?

 

I agree with your findings on the NIST VDR; NIST identified the VDR data to be 
included, but not a specific format. There are two open source NIST VDR 
“interpretation” formats available, one from OWASP CycloneDX and the other from 
REA:

Here’s an example of the open-source REA VDR format:

https://raw.githubusercontent.com/rjb4standards/REA-Products/master/SBOMVDR_JSON/VDR_118.json
 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__raw.githubusercontent.com_rjb4standards_REA-2DProducts_master_SBOMVDR-5FJSON_VDR-5F118.json&d=DwQFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=qGkQFMOW3-vqrWgaEXeJ7i92gXAlepjIpITRCq8YfVU&e=>
  

 

I also wrote an article describing the NIST SBOM VDR that ties back to the SP 
800-161 standard and other NIST materials where VDR is referenced:

https://energycentral.com/c/pip/what-nist-sbom-vulnerability-disclosure-report-vdr
 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__energycentral.com_c_pip_what-2Dnist-2Dsbom-2Dvulnerability-2Ddisclosure-2Dreport-2Dvdr&d=DwQFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=2bOkA5ZKPHgtxXQSt8mt3oklNe_jJpRG8L9LSI49qq8&e=>
 

 

FYI: REA has offered to withdraw it’s VDR format if the industry agrees to 
endorse the CycloneDX VDR format. Also, note, REA offered to freely transfer 
its open-source VDR format to the Linux Foundation, when it was first 
introduced; the offer was never acted on.

 

Thanks,

 

Dick Brooks

  

Active Member of the CISA Critical Manufacturing Sector, 

Sector Coordinating Council – A Public-Private Partnership

 

 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__reliableenergyanalytics.com_products&d=DwMFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=K122ckSdZTIkgXLe5GXFiZbWdRDFcAIquQvgKJVOTLM&e=>
 Never trust software, always verify and report! ™

http://www.reliableenergyanalytics.com 
<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.reliableenergyanalytics.com&d=DwQFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=HVlqc__uTRLvFvOWFS9IoWQKJPzi9r2Z9I6MVquorJg&e=>
 

Email:  <mailto:[email protected]> 
[email protected]

Tel: +1 978-696-1788

 

From: [email protected] <mailto:[email protected]>  <[email protected] 
<mailto:[email protected]> > On Behalf Of May Wang via lists.spdx.org 
<https://urldefense.proofpoint.com/v2/url?u=http-3A__lists.spdx.org&d=DwQFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=_LVO6yCwVNtf6QCa4n4TvmV_eoCyMlsmRjJCaGiazs8&e=>
 
Sent: Wednesday, April 12, 2023 2:59 AM
To: [email protected] <mailto:[email protected]> 
Cc: Phil Odence <[email protected] <mailto:[email protected]> >
Subject: Re: [spdx] SPDX Gen Meeting Follow up- Mistake and Thanks

 

Dick, 

 

Thank you for your questions. 

 

1. Our spdx-based IoT SBOM is available to all our customers.  I am not sure 
about the specific "testing purposes" you are referring to, happy to talk more 
details offline. 

 

2. Good question.  In addition to the SBOM info, we also provided links from 
SBOM to vulnerabilities, based on our own vulnerability database and some CVEs 
for now.  We do plan to 1) expand to more vulnerability databases and CVEs. 2) 
expand to cover more devices. 3) the latest NIST VDR document 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__nvlpubs.nist.gov_nistpubs_SpecialPublications_NIST.SP.800-2D161r1.pdf&d=DwMFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=3EO34xcHx1Byvg_QN8rQe2KXJW3GycHY8dg2uise6hU&e=>
  provides good guidance but did not prescribe specific format, we will closely 
follow up any updates from NIST. 

 

Thank you, 

--

May Wang, Ph.D.  |  CTO, IoT Security

Palo Alto Networks  |  3000 Tannery Way  |  Santa Clara, CA 95054  |  USA

Email: [email protected] <mailto:[email protected]>  |  
www.paloaltonetworks.com 
<https://urldefense.proofpoint.com/v2/url?u=http-3A__paloaltonetworks.com&d=DwQFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=5UDSDWXpIVskvQpIMFYaEykXD0RHtz0omac81aFOL04&e=>
 

 

 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.paloaltonetworks.com_&d=DwMFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=GX2hTWl2vuDUetDQ5703jEMchw25tiIBYORzvJIi8pc&e=>
      
<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.linkedin.com_company_palo-2Dalto-2Dnetworks&d=DwMFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=I37_O13dR9-nZYGzp5EYjwAt9UHSuFH99dQ5S7mwb3k&e=>
  
<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.facebook.com_PaloAltoNetworks_&d=DwMFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=3Jrpfw-nN-P9W3pYBabVsVhqQJI4ytEGopSyfnRK6Zo&e=>
  
<https://urldefense.proofpoint.com/v2/url?u=https-3A__twitter.com_PaloAltoNtwks&d=DwMFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=RZwGCfRWvifAlt_4V8a0gp28OwPoFdWksYj26FF2UpY&e=>
 

The content of this message is the proprietary and confidential property of 
Palo Alto Networks, and should be treated as such. If you are not the intended 
recipient and have received this message in error, please delete this message 
from your computer system and notify me immediately by e-mail. Any unauthorized 
use or distribution of the content of this message is prohibited.

 

 

On Tue, Apr 11, 2023 at 5:10 AM Dick Brooks <[email protected] 
<mailto:[email protected]> > wrote:

Thanks May.

 

Two questions:

1.      Is the SPDX artifact available to use for testing purposes?
2.      Is Palo Alto Networks also planning to issue NIST SBOM Vulnerability 
Disclosure Reports (VDR) that will be linked to the published SBOM?

 

Thanks,

 

Dick Brooks

  

Active Member of the CISA Critical Manufacturing Sector, 

Sector Coordinating Council – A Public-Private Partnership

 

 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__reliableenergyanalytics.com_products&d=DwMFaQ&c=V9IgWpI5PvzTw83UyHGVSoW3Uc1MFWe5J8PTfkrzVSo&r=rmJB2YDEJefEydENp-aL880gNOGWgH12oLGXQ_MR4Qs&m=G9XFbJ6eNMR7WexyGB1CWvvvax8mW_CKqYqf6ZcoKd0RG7U7JemLV2qt0Lp2OX9K&s=xBPrdqEC430Uthyf_yCq30ZYOKxphNRu1diFITTNgII&e=>
 Never trust software, always verify and report! ™

http://www.reliableenergyanalytics.com 
<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.reliableenergyanalytics.com&d=DwQFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=HVlqc__uTRLvFvOWFS9IoWQKJPzi9r2Z9I6MVquorJg&e=>
 

Email:  <mailto:[email protected]> 
[email protected]

Tel: +1 978-696-1788

 

From: [email protected] <mailto:[email protected]>  <[email protected] 
<mailto:[email protected]> > On Behalf Of May Wang via lists.spdx.org 
<https://urldefense.proofpoint.com/v2/url?u=http-3A__lists.spdx.org&d=DwQFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=_LVO6yCwVNtf6QCa4n4TvmV_eoCyMlsmRjJCaGiazs8&e=>
 
Sent: Tuesday, April 11, 2023 12:05 AM
To: Phil Odence <[email protected] <mailto:[email protected]> >
Cc: SPDX-general <[email protected] <mailto:[email protected]> >
Subject: Re: [spdx] SPDX Gen Meeting Follow up- Mistake and Thanks

 

Thank you, Phil, the members of the SPDX Steering Committee, and the SPDX 
Community.  

 

I am grateful for the fruitful year we have had working together. This year, we 
released the first loT SBOM product by Palo Alto Networks based on SPDX. Such a 
significant milestone couldn't have been possible without your support and 
leadership. I look forward to our continued collaboration to advance the 
adoption of SPDX and foster innovation in SBOM, especially in cybersecurity.

 

-- 

May Wang, Ph.D.  |  CTO, IoT Security

Palo Alto Networks  |  3000 Tannery Way  |  Santa Clara, CA 95054  |  USA

Email: [email protected] <mailto:[email protected]>  |  
www.paloaltonetworks.com 
<https://urldefense.proofpoint.com/v2/url?u=http-3A__paloaltonetworks.com&d=DwQFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=5UDSDWXpIVskvQpIMFYaEykXD0RHtz0omac81aFOL04&e=>
 

 

 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.paloaltonetworks.com_&d=DwMFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=pgfiRY6kGPIhSpUgieJmXzjgUIi36UXPHr1XDTlPVhw&m=pcx12l2NOh7S7LnFmVmJa1qsisMHSrWdyJiDMv0qY44&s=GX2hTWl2vuDUetDQ5703jEMchw25tiIBYORzvJIi8pc&e=>
      
<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.linkedin.com_company_palo-2Dalto-2Dnetworks&d=DwMFaQ&c=V9IgWpI5PvzTw83UyHGVSoW3Uc1MFWe5J8PTfkrzVSo&r=rmJB2YDEJefEydENp-aL880gNOGWgH12oLGXQ_MR4Qs&m=G9XFbJ6eNMR7WexyGB1CWvvvax8mW_CKqYqf6ZcoKd0RG7U7JemLV2qt0Lp2OX9K&s=gLyVLEABGAXPiz4CwbphNtjHYMxx3vsResBSdiH8vGs&e=>
  
<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.facebook.com_PaloAltoNetworks_&d=DwMFaQ&c=V9IgWpI5PvzTw83UyHGVSoW3Uc1MFWe5J8PTfkrzVSo&r=rmJB2YDEJefEydENp-aL880gNOGWgH12oLGXQ_MR4Qs&m=G9XFbJ6eNMR7WexyGB1CWvvvax8mW_CKqYqf6ZcoKd0RG7U7JemLV2qt0Lp2OX9K&s=kbO55ncCPqv5UFI0N3SOVwn4nPuYyZyr7jYydTAfQJU&e=>
  
<https://urldefense.proofpoint.com/v2/url?u=https-3A__twitter.com_PaloAltoNtwks&d=DwMFaQ&c=V9IgWpI5PvzTw83UyHGVSoW3Uc1MFWe5J8PTfkrzVSo&r=rmJB2YDEJefEydENp-aL880gNOGWgH12oLGXQ_MR4Qs&m=G9XFbJ6eNMR7WexyGB1CWvvvax8mW_CKqYqf6ZcoKd0RG7U7JemLV2qt0Lp2OX9K&s=tA-7kZlGLO26f-gcMAslT85T0_gfwYms2BMYKL_BrjM&e=>
 

The content of this message is the proprietary and confidential property of 
Palo Alto Networks, and should be treated as such. If you are not the intended 
recipient and have received this message in error, please delete this message 
from your computer system and notify me immediately by e-mail. Any unauthorized 
use or distribution of the content of this message is prohibited.

 




 

 





-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#1675): https://lists.spdx.org/g/spdx/message/1675
Mute This Topic: https://lists.spdx.org/mt/98175049/21656
Group Owner: [email protected]
Unsubscribe: https://lists.spdx.org/g/spdx/leave/2655439/21656/1698928721/xyzzy 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to