<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DUYBR38-fCp7ImA9WxNbF0k.&quot;"><id>tag:blogger.com,1999:blog-19553129</id><updated>2009-11-20T11:59:16.154-08:00</updated><title>Anton Chuvakin Blog - "Security Warrior"</title><subtitle type="html">This blog covers all sorts of issues of interest to me, including information security, network security, data security - and all other fun things security.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://chuvakin.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://chuvakin.blogspot.com/" /><link rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>1373</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><link rel="self" href="http://feeds.feedburner.com/AntonChuvakinPersonalBlog" type="application/atom+xml" /><feedburner:emailServiceId>AntonChuvakinPersonalBlog</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry gd:etag="W/&quot;DUYBR389cCp7ImA9WxNbF0k.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-179411596210319503</id><published>2009-11-20T11:59:00.001-08:00</published><updated>2009-11-20T11:59:16.168-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-20T11:59:16.168-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="security management" /><category scheme="http://www.blogger.com/atom/ns#" term="compliance" /><category scheme="http://www.blogger.com/atom/ns#" term="musings" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="PCI" /><title>Smart vs Stupid: But Not Why You Think So!</title><content type="html">&lt;p&gt;This slightly rambling post was born out of some fun conference discussions and well as pondering the &lt;a href="http://chuvakin.blogspot.com/2009/11/more-pci-devil-defense.html"&gt;“PCI is the Devil”&lt;/a&gt; theme. So, some interesting dichotomy was born as a result. Let’s &lt;em&gt;temporarily&lt;/em&gt; call it “smart” vs “stupid” security, but if offensive labels … well.. offend you, you can pick something else instead :-)&lt;/p&gt;  &lt;p&gt;The table below shows some concepts loosely associated with each security paradigm (of course, this whole thing is a &lt;strong&gt;&lt;em&gt;gross&lt;/em&gt;&lt;/strong&gt; &lt;strong&gt;oversimplification&lt;/strong&gt;, but useful for our purposes nonetheless): &lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="400"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="200"&gt;&lt;strong&gt;“Smart” Security&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="200"&gt;&lt;strong&gt;“Stupid” Security&lt;/strong&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;Incident response&lt;/td&gt;        &lt;td valign="top" width="200"&gt;Badness prevention&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;Risk (to the extent understood … which is often not much)&lt;/td&gt;        &lt;td valign="top" width="200"&gt;Compliance, “doing the minimum checklist”&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;C of C-I-A, moving to I&lt;/td&gt;        &lt;td valign="top" width="200"&gt;A of C-I-A&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;Monitoring for attacks&lt;/td&gt;        &lt;td valign="top" width="200"&gt;“Nobody wants to hack us”&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;Logging + log analysis&lt;/td&gt;        &lt;td valign="top" width="200"&gt;No logging&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;Application security&lt;/td&gt;        &lt;td valign="top" width="200"&gt;Network security&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;System perimeter, application perimeter, network perimeter, “data perimeter”&lt;/td&gt;        &lt;td valign="top" width="200"&gt;Network perimeter&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;Firewalls, SSL, AV, IDS/IPS, WAF, SIEM, DLP, DAM, SDLC, VM, etc&lt;/td&gt;        &lt;td valign="top" width="200"&gt;&lt;u&gt;&lt;a href="http://1raindrop.typepad.com/1_raindrop/2009/05/but-i-dont-want-to-trust-the-cloud.html"&gt;Firewalls, SSL&lt;/a&gt;&lt;/u&gt;, AV&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;People&lt;/td&gt;        &lt;td valign="top" width="200"&gt;Boxes&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;Visibility (striving for it) – know control is impossible&lt;/td&gt;        &lt;td valign="top" width="200"&gt;Control (failing with it)&amp;#160; - afraid of visibility&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;Metrics (striving for it)&lt;/td&gt;        &lt;td valign="top" width="200"&gt;&lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/fudsec-fud-piece-reposted-with-comments.html"&gt;FUD&lt;/a&gt;&lt;/u&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;Want to know how secure they are&lt;/td&gt;        &lt;td valign="top" width="200"&gt;Afraid to know – but want to just “be secure”&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="200"&gt;0wned (know it, care to have less of it)&lt;/td&gt;        &lt;td valign="top" width="200"&gt;0wned (don’t know and don’t care)&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Now, forget my “offensive” column labels that I added to purposefully confuse you :-) Even though security literati prefer to call the left column “smart”, “correct”, “good”, “risk-based”, “new school”, etc while label the right column “stupid”, “wrong”, “evil”, “checklist-based”, etc, it is more useful to think of the left as “RARE” and of the right as “TYPICAL” if you consider the organizations of all sizes. &lt;/p&gt;  &lt;p&gt;However, things are actually a bit worse, even “TYPICAL” security from the right column is more than some smaller organizations have.&amp;#160; And this is where &lt;u&gt;&lt;a href="chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt;&lt;/u&gt; comes in, an angel with a flaming sword :-) In this context, PCI is a noble attempt to bring many organizations to somewhere better than the above “typical” level. And this is why I think it is awesome.&lt;/p&gt;  &lt;p&gt;P.S. If&amp;#160; you were expecting a post on why &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;PCI&lt;/a&gt; sometimes IS the devil, that will come later :-)&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/more-pci-devil-defense.html"&gt;More PCI Devil Defense&lt;/a&gt;&lt;/u&gt; &lt;/li&gt;    &lt;li&gt;&lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/musings"&gt;All posts tagged “musings”&lt;/a&gt;&lt;/u&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-179411596210319503?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/8pFfclljMEMzWeINTZTleiil6po/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8pFfclljMEMzWeINTZTleiil6po/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/8pFfclljMEMzWeINTZTleiil6po/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8pFfclljMEMzWeINTZTleiil6po/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=l88vOEMEDc0:fVWoMpi1qZM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=l88vOEMEDc0:fVWoMpi1qZM:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=l88vOEMEDc0:fVWoMpi1qZM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/l88vOEMEDc0" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/179411596210319503?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/179411596210319503?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/l88vOEMEDc0/smart-vs-stupid-but-not-why-you-think.html" title="Smart vs Stupid: But Not Why You Think So!" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/11/smart-vs-stupid-but-not-why-you-think.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUUFRno9fSp7ImA9WxNbFU0.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-848788309092251986</id><published>2009-11-17T16:13:00.001-08:00</published><updated>2009-11-17T16:13:37.465-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-17T16:13:37.465-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SANS" /><category scheme="http://www.blogger.com/atom/ns#" term="log management" /><category scheme="http://www.blogger.com/atom/ns#" term="logs" /><category scheme="http://www.blogger.com/atom/ns#" term="personal" /><category scheme="http://www.blogger.com/atom/ns#" term="logging" /><title>SANS Log Management Class in Sacramento</title><content type="html">&lt;p&gt;FYI, I will be teaching my SANS class SEC434 called “&lt;strong&gt;Log Management In-Depth: Compliance, Security, Forensics, and Troubleshooting&lt;/strong&gt;” on December 2nd in Sacramento.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;a href="http://www.sans.org/log-managment-sacramento-2009/description.php?tid=2912"&gt;Details&lt;/a&gt;&lt;/strong&gt;: “This first-ever dedicated log management class for IT and security managers will cover system, network, and security logs and their management at an organization. We will start with the basics, like making sure that logs exist, and then go on to touch upon everything from managing log storage, to analysis techniques, to log forensics and regulatory issues related to logging.&lt;/p&gt;  &lt;p&gt;In the beginning, we will cover various log types and provide configuration guidance, describe a phased approach to implementing a company-wide log management program, and go into specific tasks that IT and security managers need to be focusing on a daily, weekly, and monthly basis in regards to log monitoring.&lt;/p&gt;  &lt;p&gt;A unique and comprehensive section that covers the hot topic of using logs for regulatory compliance, such as PCI DSS, will also be presented. Everybody knows that logs are essential for resolving compliance challenges; this class will teach you what you need to concentrate on and how to make your log management &lt;q&gt;compliance-friendly.&lt;/q&gt;&lt;/p&gt;  &lt;p&gt;The class will also touch upon various uses of logs for incident response, forensics, and operational monitoring. Common logging mistakes, learned from many years of working with logs, will also be explained.”&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Sadly, the class is NOT public, but open to employees of the State of CA only&lt;/em&gt; (this time). The next time the class will be taught at &lt;a href="http://www.sans.org/cyber-defense-initiative-2009/"&gt;SANS CDI 2009&lt;/a&gt; (&lt;a href="http://www.sans.org/cyber-defense-initiative-2009/description.php?tid=2912"&gt;sign up!&lt;/a&gt;)&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-848788309092251986?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/4WqA71-j01rqwo8plII657WzR_4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/4WqA71-j01rqwo8plII657WzR_4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/4WqA71-j01rqwo8plII657WzR_4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/4WqA71-j01rqwo8plII657WzR_4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Pu0JDXkVlX8:q8FRKZM0QFk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Pu0JDXkVlX8:q8FRKZM0QFk:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Pu0JDXkVlX8:q8FRKZM0QFk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/Pu0JDXkVlX8" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/848788309092251986?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/848788309092251986?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/Pu0JDXkVlX8/sans-log-management-class-in-sacramento.html" title="SANS Log Management Class in Sacramento" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/11/sans-log-management-class-in-sacramento.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkAFRHY-cSp7ImA9WxNbE0Q.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-1816512125101316708</id><published>2009-11-16T10:05:00.001-08:00</published><updated>2009-11-16T10:05:15.859-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-16T10:05:15.859-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SIEM" /><category scheme="http://www.blogger.com/atom/ns#" term="security management" /><category scheme="http://www.blogger.com/atom/ns#" term="marketing" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="SEM" /><category scheme="http://www.blogger.com/atom/ns#" term="SIM" /><title>On SIEM Complexity</title><content type="html">&lt;p&gt;I love &lt;u&gt;&lt;a href="http://ries.typepad.com/"&gt;Laura Ries&lt;/a&gt;&lt;/u&gt; &lt;a href="http://twitter.com/lauraries"&gt;(@lauraries&lt;/a&gt;). Not in &lt;em&gt;that&lt;/em&gt; way, but I think she is the source of non-trivial marketing awesomeness (despite &lt;u&gt;&lt;a href="http://ries.typepad.com/ries_blog/2009/06/can-17-million-iphone-users-be-crazy.html"&gt;her iPhone fiasco&lt;/a&gt;&lt;/u&gt;).&lt;/p&gt;  &lt;p&gt;In any case, here are three pictures from &lt;u&gt;&lt;a href="http://www.slideshare.net/riesconsulting/war-in-the-boardroom"&gt;her recent presentation&lt;/a&gt;&lt;/u&gt;: &lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="400"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="133"&gt;&lt;a href="http://lh5.ggpht.com/_eCy8mZux-aI/SwGUT4wcPWI/AAAAAAAAIlQ/S5B1n5S_AuY/s1600-h/hyu1%5B2%5D.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="hyu1" border="0" alt="hyu1" src="http://lh6.ggpht.com/_eCy8mZux-aI/SwGUUTVrcWI/AAAAAAAAIlU/BipvRxQECDc/hyu1_thumb.jpg?imgmax=800" width="244" height="185" /&gt;&lt;/a&gt; &lt;/td&gt;        &lt;td valign="top" width="133"&gt;&lt;a href="http://lh3.ggpht.com/_eCy8mZux-aI/SwGUVa28vFI/AAAAAAAAIlY/JZhwWPIK9v0/s1600-h/hyu2%5B2%5D.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="hyu2" border="0" alt="hyu2" src="http://lh6.ggpht.com/_eCy8mZux-aI/SwGUV-flXWI/AAAAAAAAIlc/s6yU-jtcUlI/hyu2_thumb.jpg?imgmax=800" width="244" height="188" /&gt;&lt;/a&gt; &lt;/td&gt;        &lt;td valign="top" width="133"&gt;&lt;a href="http://lh3.ggpht.com/_eCy8mZux-aI/SwGUWUrsGRI/AAAAAAAAIlg/UK1Pr2LZdBY/s1600-h/hyu3%5B2%5D.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="hyu3" border="0" alt="hyu3" src="http://lh3.ggpht.com/_eCy8mZux-aI/SwGUW6UaBFI/AAAAAAAAIlk/CLDuWO7uUJg/hyu3_thumb.jpg?imgmax=800" width="244" height="183" /&gt;&lt;/a&gt; &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Note that on the 3rd picture she uses the line that I’ve heard many times, but never fully accepted: “&lt;strong&gt;Changing the reality doesn’t change the perception.&lt;/strong&gt;”&amp;#160; This is pretty darn profound – and darn hard to accept for folks of the scientific or engineering persuasion.&lt;/p&gt;  &lt;p&gt;What is has to do with Security Information and Event Management (SIEM)? You know, “&lt;strong&gt;SIEM is very complex.&lt;/strong&gt;” Everybody “knows” it. &lt;/p&gt;  &lt;p&gt;At a conference in Scotland last week, I was leading a roundtable on &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt;&amp;#160; and I started the discussion with this provocative question: “Is SIEM ‘a MUST-have’ or ‘a nice-to-have’?” No offense to my friends at SIEM vendors (you know I love you too :-)), but 100.00% of those who responded chose “nice-to-have” and, respectively,&amp;#160; 0.00% picked “must-have.” One person added that it would indeed be “nice”, but only if it will solve problems that his organization is having and at a reasonable cost. And another person stated that “SIEM is very complex” (with the implicit assumption that anything that complex cannot really be mandatory). And yet another got upset that his auditor requested that he “needs to get correlation” without explaining what it was…&lt;/p&gt;  &lt;p&gt;BTW, yet another person brought tears to my eyes by saying that “on the other hand, log management IS a MUST-have” for incident response, accountability and other uses, but this is a different story altogether.&lt;/p&gt;  &lt;p&gt;So, “simple to use SIEM” is “a luxury Hyundai” or (new meme alert!) “&lt;em&gt;an&lt;/em&gt; &lt;em&gt;anti-&lt;/em&gt;&lt;a href="http://chuvakin.blogspot.com/2009/10/smelly-goat-vs-flying-unicorn.html"&gt;&lt;em&gt;Unicorn&lt;/em&gt;&lt;/a&gt;” – you might find it, smell it, touch it, BUT still refuse to believe in it. That, my friends, is why (deep insight alert!) enterprise SIEM vendors don’t have much success with their SIEM appliance offerings (note that I am talking about their SIEM appliances and not their log management appliances; those are doing fine). Remember that “old school” SIEM vendors all started with ambitions of being an “HP OpenView of security” (EPIC FAIL alert!) which exudes pure complexity…&lt;/p&gt;  &lt;p&gt;Personally, I’ve seen some decent attempts to make appliance SIEM easier, but my suspicion is that today the theme of “SIEM is complex” is exceedingly powerful and mere reality will not overcome it. &lt;/p&gt;  &lt;p&gt;What can we do about it?&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;First&lt;/strong&gt;, if we are to believe &lt;a href="http://ries.typepad.com/"&gt;esteemed Ms Ries&lt;/a&gt;, fighting it with facts will not work. Perception will beat reality and you into bloody pulp. So, “but, dude, our SIEM really IS SIEMmple” won’t fly.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Second&lt;/strong&gt;, we can focus on how amazingly NICE it is, without being a MUST-have. Stop obsessing about your SIEM not being a MUST-have like, say, iPhone or, say, &lt;a href="http://www.twitter.com/anton_chuvakin"&gt;Twitter&lt;/a&gt; :-) In many cases other than &lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;SOC building&lt;/a&gt;&lt;/u&gt;, SIEM’s purchase justification is fuzzy at best, despite more than 10 years of concerted vendor efforts with “ROI”, “TCO”, etc. Or such justification is based on a compliance shortcut which then backfires. In fact, “SIEM is not for everyone” might not be a bad slogan to use… or maybe “grow up to SIEM!” BTW,&amp;#160; I’ve heard of cases where SIEM was deployed even before NIPS/NIDS (or at the same time), and this shows that some organizations place fairly high priority on it.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Third&lt;/strong&gt;, we can we sidestep the whole “must vs nice” debate and focus on specific problems that SIEM solves. You know, well-tuned correlation engine really can tell you about “bad shit” happening on your network! And it can simplify your daily workflow. And enrich logs with a lot of useful context information. And help with incident response (well, log management is better in that case).&amp;#160; If SIEM focuses on solving particular problems and solving them well, then the customer will have to decide whether solving that problem is a must for them or would just be nice. And the whole debate will change in a useful direction!&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Fourth&lt;/strong&gt;, you can focus on log management. Easy, huh? :-) And then decide which of your customers are ready for SIEM and who think of it as “sufficiently nice”&amp;#160; to deploy – then you can have them “grow up to SIEM.” Log management is – or, at least, at some point will be – for everybody who has logs and that is pretty much everybody…&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Finally, I’d like to invoke a curse of unspeakable evil: if you sell an appliance SIEM that has a&amp;#160; license-based “hard throttle” which causes you to &lt;em&gt;silently &lt;/em&gt;(!) drop incoming logs when &lt;em&gt;10%&lt;/em&gt; (!) of the EPS rate [that your customer paid for!] is exceeded and you are reading this post, &lt;strong&gt;please die a painful and embarrassing death&lt;/strong&gt;. You are an offense to common sense! Also: dear appliance SIEM buyers – please ask your vendor what happens if the EPS rate that you paid for is exceeded…&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;SIEM Bloggables&lt;/a&gt;&lt;/u&gt;&lt;/li&gt;    &lt;li&gt;&lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;All SIEM posts&lt;/a&gt;&lt;/u&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-1816512125101316708?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/512WFsg5kNrRVZAoosNa25AlojA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/512WFsg5kNrRVZAoosNa25AlojA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/512WFsg5kNrRVZAoosNa25AlojA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/512WFsg5kNrRVZAoosNa25AlojA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hASPjiElej4:BZFaydVeZM0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hASPjiElej4:BZFaydVeZM0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hASPjiElej4:BZFaydVeZM0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/hASPjiElej4" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/1816512125101316708?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/1816512125101316708?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/hASPjiElej4/on-siem-complexity.html" title="On SIEM Complexity" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/11/on-siem-complexity.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkIEQXw_eCp7ImA9WxNbEU8.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-3229593986327990798</id><published>2009-11-13T05:55:00.000-08:00</published><updated>2009-11-13T05:55:00.240-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-13T05:55:00.240-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="musings" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>FUDSec FUD Piece Reposted – With Comments</title><content type="html">&lt;p&gt;My &lt;a href="http://fudsec.com/a-treatise-on-fud"&gt;fudsec post&lt;/a&gt; (reposted below for backup purposes with a two week delay) was not “an endorsement” of FUD, it was a reminder to many overly excited folks that FUD is largely all we have today – and there are signs that change just ain’t coming.&amp;#160; As I hinted in&amp;#160; &lt;a href="http://chuvakin.blogspot.com/2009/10/smelly-goat-vs-flying-unicorn.html"&gt;my quick follow-up&lt;/a&gt; (“&lt;a href="http://chuvakin.blogspot.com/2009/10/smelly-goat-vs-flying-unicorn.html"&gt;Smelly Goat vs Flying Unicorn&lt;/a&gt;”), I am not defending Fear/Uncertainty/Doubt for the merits, I am explaining that we are largely stuck with it, for now. Another way to explain is to quite Churchill, as I do &lt;a href="http://fudsec.com/a-treatise-on-fud"&gt;in the comments&lt;/a&gt;. Those who know me can confirm that I am a huge proponent of metrics (but also highly skeptical of some metrics ever being achievable).&lt;/p&gt;  &lt;p&gt;Here are some of the insightful responses to it:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://newschoolsecurity.com/2009/10/just-say-no-to-fud/"&gt;Just say ‘no’ to FUD&lt;/a&gt; from New School of Security (personally, I think that “trumping with ethics” is a low card in intellectual arguments! IMHO it is one step above name calling)&lt;/li&gt;    &lt;li&gt;&lt;a href="http://newschoolsecurity.com/2009/11/on-smelly-goats-unicorns-and-fud/"&gt;On smelly goats, unicorns, and FUD&lt;/a&gt; from New School of Security.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;font size="4"&gt;&amp;#160;&lt;/font&gt;&lt;strong&gt;&lt;font size="4"&gt;A Treatise on FUD&lt;/font&gt; &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;FUD or Fear/Uncertainty/Doubt triad seems better known than the other security triad: C-I-A. It seems inextricably linked with security industry as well as with security technologies. After all, don’t we reach for some extra safety and security if we fear something, feel uncertain about something or doubt something? &lt;/p&gt;  &lt;p&gt;While few CSOs and security leaders admit that they build their security programs based on FUD, below we will hypothesize that FUD is indeed a meta-level above risks, threats, vulnerabilities as well as compliance mandates. &lt;strong&gt;FUD’s role in security today probably overshadows the role of any other factor we know&lt;/strong&gt;. To put more substance into our discussion, here are some well-known examples where fear, uncertainty and doubt manifest themselves:&lt;/p&gt;  &lt;p&gt;· Fear &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Getting compromised by attackers &lt;/li&gt;    &lt;li&gt;Failing an audit &lt;/li&gt;    &lt;li&gt;Suffering big loss &lt;/li&gt;    &lt;li&gt;All of the above: Failing an audit + getting hacked + being dragged into a media circus &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;· Uncertainty&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Keeping a security leadership job &lt;/li&gt;    &lt;li&gt;“Keeping the wheels on” for security infrastructure &lt;/li&gt;    &lt;li&gt;In case of an incident, loss amount is uncertain &lt;/li&gt;    &lt;li&gt;Threats and their impact &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;· Doubt&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Security mission success &lt;/li&gt;    &lt;li&gt;Effectiveness of security measures &lt;/li&gt;    &lt;li&gt;Support of senior management &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Further, many people view using FUD for driving security spending and security technology deployments as the very opposite of sensible risk management. &lt;strong&gt;However&lt;/strong&gt;, &lt;strong&gt;FUD is risk management at its best: FUD approach is simply risk management where risks are unknown and unproven but seem large at first glance, information is scarce, decisions uncertain and stakes are high. In other words, just like with any other risk management approach today!&lt;/strong&gt; Big Hairy Ass Risks (BHARs) dominate both the FUD-infested security vendor materials as well as internal CSO presentations. Note that very few of the BHARs are truly imminent and thus fall out of FUD realm as there is no uncertainty about them - just like only few people develop phobias of poisonous snakes (which would be a very useful phobia to have).&lt;/p&gt;  &lt;p&gt;In light of this, &lt;strong&gt;we have to accept that there are benefits of FUD – as well as risks.&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The benefits of FUD stem from the above view of security which is defined as “being free from danger” or ”measures taken as a precaution” against something bad.&lt;/p&gt;  &lt;p&gt;First, in the world we live in, FUD works! Demonstration of a BHAR followed by technology purchase or control implementation does reduce possible loss of not only due to said BHAR, but also due to other threats (if BHAR ends up being completely mythical). Such implementations often also deliver other useful things for the organization. It is worthwhile to remind that “FUD selling” applies to CISOs no less than to “enterprise software” sales people. It also applies to “fear of auditors” as well as “fear of attackers” – both drive security adoption, even if lately the former seems to be winning.&lt;/p&gt;  &lt;p&gt;Second, keep in mind that many of the BHARs are both genuinely scary and, in fact, likely. Scaring a company into updating its anti-malware tools (despite all the concerns about their relative efficiency) or into deploying tools to collect and analyze logs is excusable, at the very least.&lt;/p&gt;  &lt;p&gt;Third, many proclaim that people need to be naturally drawn towards doing &amp;quot;the right thing&amp;quot; after being educated about what the right thing might be and scaring people into action is not that efficient. The technical answer to such concern is a resounding “Ha-har-ha!!!”&lt;/p&gt;  &lt;p&gt;Finally, for years FUD was used to sell insurance as well as safety features in cars and other products, legal services, to make people update their boring DR and BC plans, and other good things. &lt;strong&gt;Fear might not be a very positive emotion to experience, but acting out of fear has led to things that are an overall positive, all the way down to resolving political tensions out of fear of a nuclear war…&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Admittedly, Fear/Uncertainty/Doubt approach has issues as well. The key issue with FUD is its “blunt weapon” nature. It is a sledgehammer, not a sword! If you use FUD to “power through” issues, you might end up purchasing or deploying things that you need and things that you don’t. &lt;/p&gt;  &lt;p&gt;Second, it is well-known that magic of FUD wanes if you invoke it too often. If you scare your customers or your management into taking your product or your security agenda seriously, they are almost guaranteed to stop listening to you at some point. However, if enough BHARs manifest , FUD approach will continue to be fairly productive. One can get desensitized upon hearing that &amp;quot;sky is falling&amp;quot; too often, but here is the thing: I am willing to take the risk of such &amp;quot;desensitization&amp;quot; given that sky is indeed &amp;quot;not quite stable.&amp;quot;&lt;/p&gt;  &lt;p&gt;Third, FUD power – as any other power – corrupts whoever wields it too often. If you end up scaring people into action or spreading uncertainty, you might well lose an ability to win security arguments any other way. Also, if fear is a motivation for every decision you make, checking into a mental institution is not a bad idea. You might actually be paranoid!&lt;/p&gt;  &lt;p&gt;Finally, I’d like to bring up the good old “greed vs fear” model for advancing security, last &lt;a href="http://chuvakin.blogspot.com/2009/08/blackhat-2009-day-2-bruce.html"&gt;mentioned at BlackHat&lt;/a&gt; by one of the speakers. As “greed-based” ROI scams fail to move security ahead, the role of fear has nowhere to go but up. &lt;strong&gt;In other words, all of us get to pick out favorite 3 letter abbreviation – and I’d take honest FUD over insidious ROI any day…&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;To conclude, fighting FUD is a noble pursuit&lt;/strong&gt;; Don Quixote thought the same about fighting windmills. Even if objective metrics will ever replace FUD as the key driver for security, we have a bit of time to prepare now. After all, in that remote future age interstellar travel, human cloning, teleportation and artificial intelligence will make the life of a security practitioner that much more complicated…&lt;/p&gt;  &lt;p&gt;&lt;a href="http://fudsec.com/a-treatise-on-fud"&gt;Original post.&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-3229593986327990798?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/e9rxIcjytCcDwUhcBcUd3qFMU3Y/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e9rxIcjytCcDwUhcBcUd3qFMU3Y/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/e9rxIcjytCcDwUhcBcUd3qFMU3Y/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e9rxIcjytCcDwUhcBcUd3qFMU3Y/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=lD_yiFR6B9U:zidvL1xd73E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=lD_yiFR6B9U:zidvL1xd73E:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=lD_yiFR6B9U:zidvL1xd73E:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/lD_yiFR6B9U" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/3229593986327990798?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/3229593986327990798?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/lD_yiFR6B9U/fudsec-fud-piece-reposted-with-comments.html" title="FUDSec FUD Piece Reposted – With Comments" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/11/fudsec-fud-piece-reposted-with-comments.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0QARno-eyp7ImA9WxNbEEo.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-7306073995916913584</id><published>2009-11-12T16:15:00.001-08:00</published><updated>2009-11-12T16:15:47.453-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-12T16:15:47.453-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="compliance" /><category scheme="http://www.blogger.com/atom/ns#" term="paper" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="reading" /><category scheme="http://www.blogger.com/atom/ns#" term="PCI" /><title>More PCI Devil Defense</title><content type="html">&lt;p&gt;Our paper “&lt;u&gt;&lt;a href="http://www.csoonline.com/article/507364/PCI_DSS_No_Angel_But_Certainly_Not_the_Devil"&gt;PCI: No Angel, but Not the Devil Either&lt;/a&gt;&lt;/u&gt;” just went up on “&lt;em&gt;CSO Magazine” online&lt;/em&gt; (and a &lt;u&gt;&lt;a href="http://www.cio.com/article/507378/PCI_DSS_No_Angel_but_Certainly_Not_the_Devil"&gt;few&lt;/a&gt;&lt;/u&gt; &lt;u&gt;&lt;a href="http://www.computerworld.com/s/article/9140692/PCI_DSS_No_Angel_But_Certainly_Not_the_Devil"&gt;other sources&lt;/a&gt;&lt;/u&gt;), &lt;u&gt;&lt;a href="http://www.csoonline.com/article/507364/PCI_DSS_No_Angel_But_Certainly_Not_the_Devil"&gt;check it out&lt;/a&gt;&lt;/u&gt;. It debates &lt;u&gt;&lt;a href="http://www.csoonline.com/article/506635/Analyst_PCI_Security_a_Devil_Like_No_Child_Left_Behind_"&gt;this piece&lt;/a&gt;&lt;/u&gt; which quotes Joshua Corman of The 451 Group. Sorry, Josh, we had to argue with the imperfect retelling of your words, so some points might not have came out well… Hopefully, we can have a real industry-advancing debate at some point!&lt;/p&gt;  &lt;p&gt;In any case, I am getting a bit tired defending &lt;a href="chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; (ya know, “I’d rather be logging” :-)) from smart people who should (IMHO) know better. As I am doing it, I am also looking for some sort of “root of PCI hatred” in order to dislodge it and stop this frenzy once and for all (the whole thing reminds me of &lt;u&gt;&lt;a href="http://www.sfsignal.com/archives/2009/03/free-ebook-deathworld-by-harry-harrison/"&gt;Harry Harrison “Deathworld” Jason dinAlt saga&lt;/a&gt;&lt;/u&gt;)&lt;/p&gt;  &lt;p&gt;Here is what occurred to me recently: I used to think that “security perfectionism” drives a lot of attacks on PCI (“it sucks because it is does not ‘guarantee’ ‘perfect’ security”). But some old Scottish whiskey made me realize that it is more subtle than that – it is not perfectionism per se, but “enterprise security disease.”&lt;/p&gt;  &lt;p&gt;Let me explain. If your entire security career happened while working at, selling to or advising global organizations about information security, it is highly likely that your brain has adjusted to that reality. But there is another reality – and, darn, it is big. &lt;/p&gt;  &lt;p&gt;Here is an example: next time you are having lunch somewhere and paying with a credit card, think: do there folks have a network IPS? Web application security scanner? SIEM perhaps? A DAM tool? Information risk protection strategy? BTW, the answer would be “No, no, no and no and no.” Their security is anti-virus (deployed on most systems and updated on some), filtering router with NAT (and with a very open ruleset) and a few other “bulletproof” shields of that sort. &lt;/p&gt;  &lt;p&gt;PCI is truly a beam of light (an annoying one…) for them – it motivates them to learn about all the wonderful security things they should be doing. Risk management? Pah. Threat posture? WTH. Encryption? Stop cursing. Firewall? &lt;a href="http://chuvakin.blogspot.com/2008/11/on-small-companies-and-pci-compliance.html"&gt;Yes, we have it&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Here is how I presented this side of a debate in a recent argument I had (via email), numbers are from my favorite source of security stats (that is &lt;em&gt;srand()&lt;/em&gt;, as you know :-)): &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;198x-1992: 99% of people just say 'screw information security' &lt;/li&gt;    &lt;li&gt;1996-1999: massive email viruses hit; 98% of people still say 'screw security' &lt;/li&gt;    &lt;li&gt;2002-2004: worms hit; 97% of people still say 'screw security' &lt;/li&gt;    &lt;li&gt;2005-2007: spyware hits, botnets start their ominous rise, 96% of organizations still say 'screw security' &lt;/li&gt;    &lt;li&gt;2007-2008: data losses hit, massive data theft happens, 95% of organizations still say 'screw security' &lt;/li&gt;    &lt;li&gt;2007-2009: PCI DSS spreads. Oops! Now only &lt;strong&gt;30%&lt;/strong&gt; say 'screw security.' The rest has to at least pay it some lip service and raise their “wooden shields.” Hurray!&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;That is the main reason I think PCI magick has &lt;a href="http://www.imdb.com/title/tt0441773/quotes"&gt;the blinding power of pure awesomeness.&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;BTW, I am working on a post that clarifies this “enterprise security thinking” a bit more. Also BTW, if you are looking to use PCI DSS as a general security or data security framework, go &lt;a href="http://chuvakin.blogspot.com/2009/10/my-fun-pci-webcast-on-oct-27-2009.html"&gt;here&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.slideshare.net/anton_chuvakin/pci-dss-myths-mistakes-misconceptions-2009-teaser-version-1171140 "&gt;My PCI Myths deck&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/04/five-reasons-to-dislike-pci-dss-and-why.html"&gt;Five Reasons to Dislike PCI DSS – And Why They Are WRONG!&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-7306073995916913584?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/g2dMCNrNU6JgTrzSbooNSdK5XIE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/g2dMCNrNU6JgTrzSbooNSdK5XIE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/g2dMCNrNU6JgTrzSbooNSdK5XIE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/g2dMCNrNU6JgTrzSbooNSdK5XIE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=tk1Rzogj9h8:qG01_tVb9ww:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=tk1Rzogj9h8:qG01_tVb9ww:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=tk1Rzogj9h8:qG01_tVb9ww:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/tk1Rzogj9h8" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/7306073995916913584?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/7306073995916913584?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/tk1Rzogj9h8/more-pci-devil-defense.html" title="More PCI Devil Defense" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/11/more-pci-devil-defense.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU8BSH05eSp7ImA9WxNUGEU.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-4829078016412768441</id><published>2009-11-10T05:05:00.000-08:00</published><updated>2009-11-10T13:17:39.321-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-10T13:17:39.321-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SIEM" /><category scheme="http://www.blogger.com/atom/ns#" term="security management" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="SEM" /><category scheme="http://www.blogger.com/atom/ns#" term="SIM" /><title>SIEM Bloggables</title><content type="html">&lt;p&gt;I was working on a presentation related to Security Information and Event Management (SIEM) the other day. Even though it was intended for a particular audience, a few pieces of it are generic enough to be shared with the world at large. Hopefully said world at large will find it useful for planning SIEM deployments, analyzing your requirements, improving SIEM product design, etc.&lt;/p&gt;  &lt;p&gt;So, in no particular order:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;What SIEM &lt;u&gt;MUST&lt;/u&gt; Have Today?&lt;/strong&gt;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Log and Context Data Collection &lt;/li&gt;    &lt;li&gt;Normalization (including event categorization)&lt;/li&gt;    &lt;li&gt;Correlation (what used to be bundled under “SEM”) &lt;/li&gt;    &lt;li&gt;Notification/alerting (“SEM”) [the role of real-time processing seems to be shrinking, as I &lt;a href="http://www.docstoc.com/docs/12824499/Real-time-fallacy-how-real-time-your-security-really-is"&gt;predicted in 2004&lt;/a&gt; - that surprised everybody including myself]&lt;/li&gt;    &lt;li&gt;Alert/event prioritization (“SEM”) &lt;/li&gt;    &lt;li&gt;Reporting (“SIM”) [including visualization]&lt;/li&gt;    &lt;li&gt;Security role workflow [from security analyst roles to incident responder (&lt;a href="http://www.docstoc.com/docs/13635590/Automated-Incident-Handling-Using-SIM"&gt;my classic piece on using SIEM for incident response&lt;/a&gt;, BTW) to security manager and – rarely! – the CSO]&lt;/li&gt;    &lt;li&gt;Everything else is icing on the cake!&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;Key SIEM Use Cases&lt;/strong&gt;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;em&gt;Security Operations Center (SOC):&lt;/em&gt; real-time views, analysts online 24/7, chase alerts as they “pop up” [this was the original SIEM use case when SIM started in the 1990s; nowadays it is relegated to the largest organizations only]&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Mini-SOC / “morning after”:&lt;/em&gt; delayed views (“analyst comes in the morning”), analysts online 1-3/24, review alerts and reports then drill-down as needed&lt;/li&gt;    &lt;li&gt;&lt;em&gt;“Automated SOC” / alert + investigate:&lt;/em&gt; configure SIEM to alert based on rules and forget until the alert, investigate alerts, review reports weekly/monthly [this is the use case that many users want and few SIEM products can deliver…]&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Compliance status reporting:&lt;/em&gt; review reports/views weekly/monthly, no security operation focus [it might be common, hopefully the organization can later transition to any of the use cases 1.-3.]&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;Two Types of Users To Make Happy – with SIEM or Log Management&lt;/strong&gt;&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="482"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="238"&gt;         &lt;p&gt;&lt;em&gt;“Minimalist”&lt;/em&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="242"&gt;         &lt;p&gt;&lt;em&gt;“Analyst”&lt;/em&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="238"&gt;         &lt;p&gt;•Still evolves from “logs are dirt” to raw collection&lt;/p&gt;          &lt;p&gt;•Pure compliance focus – “deliver me from evil… eh… auditors”&lt;/p&gt;          &lt;p&gt;•Collecting logs&lt;/p&gt;          &lt;p&gt;•Checkbox mentality&lt;/p&gt;          &lt;p&gt;•Less mature; needs more hand-holding&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="242"&gt;         &lt;p&gt;•Evolved to “so we have them collected – now what?”; now stuck&lt;/p&gt;          &lt;p&gt;•“Compliance+” or pure security/operational focus&lt;/p&gt;          &lt;p&gt;•Using logs (analysis)&lt;/p&gt;          &lt;p&gt;•Situational awareness mentality&lt;/p&gt;          &lt;p&gt;•More mature; needs more “cool tools”&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Enjoy!&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-4829078016412768441?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/kYRt4iU72ktR7i30B3A9sLLAG8U/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/kYRt4iU72ktR7i30B3A9sLLAG8U/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/kYRt4iU72ktR7i30B3A9sLLAG8U/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/kYRt4iU72ktR7i30B3A9sLLAG8U/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=kD4jVY1Qemw:oeHR7YLVOYs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=kD4jVY1Qemw:oeHR7YLVOYs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=kD4jVY1Qemw:oeHR7YLVOYs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/kD4jVY1Qemw" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/4829078016412768441?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/4829078016412768441?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/kD4jVY1Qemw/siem-bloggables.html" title="SIEM Bloggables" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/11/siem-bloggables.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEQBRH46fyp7ImA9WxNUFU8.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-376572087874202436</id><published>2009-11-06T01:11:00.001-08:00</published><updated>2009-11-06T07:45:55.017-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-06T07:45:55.017-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="book review" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="review" /><category scheme="http://www.blogger.com/atom/ns#" term="reading" /><category scheme="http://www.blogger.com/atom/ns#" term="myth" /><category scheme="http://www.blogger.com/atom/ns#" term="book" /><title>Book Review: “The myths of Security” by John Viega</title><content type="html">&lt;p&gt;My review for&lt;span class="Apple-style-span" style="font-family: Arial; font-size: 13px; white-space: pre; "&gt; “The myths of Security” by John Viega has been posted to Amazon; I gave it 4 out 5 stars.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Think about this book as a printed collection of blog posts – some a dozen pages, some half a page. John’s essays – all 48 of them - read like a typical blog: fun views on hot subjects, controversial opinions, new ideas for the future, dispelled myths, cool technology ideas, etc. I definitely enjoyed reading the book, even if most of the material was at least somewhat familiar to me. &lt;/p&gt;  &lt;p&gt;For starters, this was the first time that I have seen a book written by somebody employed by a major antivirus company, who would agree that antivirus solutions don't work too well and slow down systems. It was very impressive to read that the author himself does not use an antivirus solution and didn’t even use one when he' was in charge of building one! (Understandably, he does recommend that consumers use one on their systems)&lt;/p&gt;  &lt;p&gt;The following are some of my fave chapter highlights. “Security:”Nobody Cares” is one of my favorites; it covers why people, on average, don’t care about information security. His analysis matches that of some other industry thinkers, but it is presented well in the book.&lt;/p&gt;  &lt;p&gt;I also enjoyed his thinking about why Microsoft antivirus solution would never pick up and never present a threat to the big AV vendors. In his opinion, most people do not trust Microsoft as a security brand. He thinks that customers would always go to security specialist and not to MS for antivirus tools, even if such specialist is located in Russia or Czech Republic. Also, it looks like the 30% success ratio for antivirus solutions is pretty much a commonly accepted number nowadays; it is mentioned in the book more than a few times.&lt;/p&gt;  &lt;p&gt;One chapter that made me angry was chapter 7 on Google. He basically makes the insinuation that the Google in particular and pay-per-click advertising in general motivates people to hack into systems; a view as illogical as it is silly.&lt;/p&gt;  &lt;p&gt;In chapter 26, John has an interesting idea for a Social Security number replacement scheme. Many other chapters contain ideas for improving major parts of security technology, even if in some cases the author has to disclaim them with his disbelief about their implementation potential.&lt;/p&gt;  &lt;p&gt;It is quite interesting that in chapter 28 John dispelled the myth that including security early in the application design is cheaper. Compared to ignoring the problem until notice from customers, it is certainly more expensive. He touches most other known security industry “pain points” such as vulnerability disclosure. He proposes to replace “responsible disclosure” with a new scheme from my view looked kinda similar, less dangerous for the world at large but less motivating to software vendors. He also discusses whether disclosing vulnerabilities reduces or increases the risk for consumers (in his view seems to increase it).&lt;/p&gt;  &lt;p&gt;Closer to the end of the book chapters get shorter and shorter. For example, chapter 42 ends up being half of a page in length. It pretty much states that he would sacrifice some privacy for more functionality and so would most of the others, which seem to be a very popular view nowadays.&lt;/p&gt;  &lt;p&gt;I was very happy to find that he devoted an entire chapter - 2 pages in length - to criticizing academic security research (one of my pet peeves!). He says “lots of academics are reinventing what security industry has been doing for years. “ [They are also reinventing a lot of “epic FAIL”, proven to not work.] The book also mentions that there is nowhere near enough data sharing between security industry, where the problems are, and academia, where - supposedly - the brains are.&lt;/p&gt;  &lt;p&gt;Other reviewers have pointed out that it is not clear what is the audience for the book. Many of the chapters seemed written for the “curious consumer” while others are clearly intended for security practitioners or even security managers and imply a degree of IT industry savvy.&lt;/p&gt;  &lt;p&gt;Finally, I have to say that multiple mentions of McAfee did not annoy me at all. I fully realize that if somebody employed by the vendor criticizes the very livelihood of that vendor (classic signature AV, in this case), you must throw your employer a major bone. You absolutely have to mention your employer positively to counterbalance the criticism and he does – in many chapters.&lt;/p&gt;  &lt;p&gt;To conclude, I read books on information security for fun. This book was a lot of fun to read even if I did not agree with some of his opinions. It is well-written, has light writing style and touches most if not all controversial issues in security; the book also has a lot of fun novel ideas for the future to think about.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-376572087874202436?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/meLKi8el4M4xb17cjA6w5HPP9aE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/meLKi8el4M4xb17cjA6w5HPP9aE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/meLKi8el4M4xb17cjA6w5HPP9aE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/meLKi8el4M4xb17cjA6w5HPP9aE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=LJQ-XA57LPw:khfFy1FNkws:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=LJQ-XA57LPw:khfFy1FNkws:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=LJQ-XA57LPw:khfFy1FNkws:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/LJQ-XA57LPw" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/376572087874202436?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/376572087874202436?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/LJQ-XA57LPw/book-review-myths-of-security-by-john.html" title="Book Review: “The myths of Security” by John Viega" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/11/book-review-myths-of-security-by-john.html</feedburner:origLink></entry><entry><title type="text">Links for 2009-11-04 [del.icio.us]</title><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/1BbHK2L9BaA/anton18" /><updated>2009-11-05T00:00:00-08:00</updated><id>http://del.icio.us/anton18#2009-11-04</id><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.infosecurityadviser.com/view_message?id=150"&gt;The Limitations of Risk Assessment | Blog | Infosecurity Security Adviser&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/1BbHK2L9BaA" height="1" width="1"/&gt;</content><feedburner:origLink>http://del.icio.us/anton18#2009-11-04</feedburner:origLink></entry><entry gd:etag="W/&quot;A04EQXw_fyp7ImA9WxNUE04.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-5140288860665080506</id><published>2009-11-04T05:05:00.000-08:00</published><updated>2009-11-04T05:05:00.247-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-04T05:05:00.247-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="paper" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="chuvakin" /><category scheme="http://www.blogger.com/atom/ns#" term="reading" /><category scheme="http://www.blogger.com/atom/ns#" term="presentation" /><title>Releasing Many Of My Security Papers!</title><content type="html">&lt;p&gt;As you can guess, I have written a lot of fun security stuff over the years. I’ve been “liberating” my content for the community to read, starting from presentations (via &lt;a href="http://www.slideshare.net/anton_chuvakin"&gt;Slideshare&lt;/a&gt;)&lt;/p&gt;  &lt;p&gt;Now, I am releasing most of my old paper content as well:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.docstoc.com/profile/anton1chuvakin"&gt;My DocStoc collection&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/anton_chuvakin"&gt;My Scribd collection&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.slideshare.net/anton_chuvakin"&gt;My Slideshare collection&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Feel free to check these periodically as I will be adding old papers from my collections for a long time (they also get auto-dumped &lt;a href="http://twitter.com/anton_chuvakin"&gt;to Twitter&lt;/a&gt;). BTW, I am doing it despite the fact that some of my writing from 2002 is quite embarrassingly naive :-) But I never, ever misspelled HIPAA! Never!&lt;/p&gt;  &lt;p&gt;Notable papers released:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.docstoc.com/docs/13635590/Automated-Incident-Handling-Using-SIM"&gt;Automated Incident Handling Using SIM&lt;/a&gt; (now known as SIEM :-))&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.docstoc.com/docs/13087315/Log-Data-Mining"&gt;Log Data Mining&lt;/a&gt;&amp;#160; /awesomeness alert! :-)/&amp;#160; - and &lt;a href="http://www.slideshare.net/anton_chuvakin/log-mining-beyond-log-analysis"&gt;related presentation on log data mining&lt;/a&gt;.&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.docstoc.com/docs/13182961/Where-Logs-Hide-Logs-in-Virtualized-Environments"&gt;Where Logs Hide: Logs in Virtualized Environments&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.docstoc.com/docs/13427313/Discovery-of-Compromised-Machines"&gt;Discovery of Compromised Machines&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.docstoc.com/docs/14699924/Trends-in-Database-Log-Management"&gt;Trends in database log management&lt;/a&gt;&amp;#160;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.docstoc.com/docs/13073273/Buy-vs-Build-vs-Outsource-What&amp;rsquo;s-Your--Best-Log-Management-Strategy"&gt;Buy vs. Build vs. Outsource: What’s Your Best Log Management Strategy?&lt;/a&gt; – and related &lt;a href="http://www.slideshare.net/anton_chuvakin/choosing-your-log-management-approach-buy-build-or-outsource"&gt;presentation on the same subject&lt;/a&gt;.&lt;/li&gt;    &lt;li&gt;[very old, but still fun piece] &lt;a href="http://www.docstoc.com/docs/13636646/On-Covert-Channels"&gt;On covert channels&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.docstoc.com/docs/12759845/PCI-DSS-Myths"&gt;PCI DSS Myths&lt;/a&gt; – and related &lt;a href="http://www.slideshare.net/anton_chuvakin/pci-dss-myths-mistakes-misconceptions-2009-teaser-version-1171140"&gt;presentation on PCI myths&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.docstoc.com/docs/12696675/&amp;ldquo;Security-First&amp;rdquo;-or-&amp;ldquo;Compliance-First&amp;rdquo;"&gt;“Security First” or “Compliance First”&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.slideshare.net/anton_chuvakin/presentations"&gt;All presentations&lt;/a&gt; – there are pretty much all fun!&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;a href="http://www.docstoc.com/profile/anton1chuvakin"&gt;Go dig thru it&lt;/a&gt;, but keep in mind, old security stuff gets stale fast. So, while reading it, keep this in mind.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="chuvakin.blogspot.com/search/label/reading"&gt;Everything tagged security reading&lt;/a&gt;. &lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-5140288860665080506?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Q248fMxU1WK7Hfk3jm8M5CLLVOs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Q248fMxU1WK7Hfk3jm8M5CLLVOs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Q248fMxU1WK7Hfk3jm8M5CLLVOs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Q248fMxU1WK7Hfk3jm8M5CLLVOs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Y935WguPRHg:yAc4zWqrVQo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Y935WguPRHg:yAc4zWqrVQo:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Y935WguPRHg:yAc4zWqrVQo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/Y935WguPRHg" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/5140288860665080506?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/5140288860665080506?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/Y935WguPRHg/releasing-many-of-my-security-papers.html" title="Releasing Many Of My Security Papers!" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/11/releasing-many-of-my-security-papers.html</feedburner:origLink></entry><entry><title type="text">Links for 2009-11-03 [del.icio.us]</title><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/f_2j8TLJ3bc/anton18" /><updated>2009-11-04T00:00:00-08:00</updated><id>http://del.icio.us/anton18#2009-11-03</id><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;a href="http://vadim-proskurin.livejournal.com/385065.html"&gt;vadim_proskurin: &amp;#1057;&amp;#1085;&amp;#1086;&amp;#1074;&amp;#1072; &amp;#1086; &amp;#1090;&amp;#1077;&amp;#1088;&amp;#1088;&amp;#1086;&amp;#1088;&amp;#1080;&amp;#1089;&amp;#1090;&amp;#1072;&amp;#1093; &amp;#1080; &amp;#1072;&amp;#1085;&amp;#1090;&amp;#1080;&amp;#1074;&amp;#1080;&amp;#1088;&amp;#1091;&amp;#1089;&amp;#1072;&amp;#1093;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.pcworld.com/businesscenter/article/181283/m86_security_buys_finjan.html"&gt;M86 Security Buys Finjan - Business Center - PC World&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/f_2j8TLJ3bc" height="1" width="1"/&gt;</content><feedburner:origLink>http://del.icio.us/anton18#2009-11-03</feedburner:origLink></entry><entry gd:etag="W/&quot;D0MDSXw7eCp7ImA9WxNUEk0.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-3550388857767020486</id><published>2009-11-02T15:44:00.001-08:00</published><updated>2009-11-02T15:44:38.200-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-02T15:44:38.200-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="compliance" /><category scheme="http://www.blogger.com/atom/ns#" term="perimeter" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="Monthly" /><category scheme="http://www.blogger.com/atom/ns#" term="reading" /><category scheme="http://www.blogger.com/atom/ns#" term="PCI" /><title>Monthly Blog Round-Up – October 2009</title><content type="html">&lt;p&gt;As we all know, blogs are a bit &amp;quot;stateless&amp;quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see &lt;em&gt;today&lt;/em&gt;. These &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly round-ups&lt;/a&gt; is my attempt to remind people of useful content from the past month! If you are “too busy to read the blogs,” at least read &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;these&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;So, here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;&amp;quot;Security Warrior&amp;quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics.&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2009/10/top-log-fail.html"&gt;Top Log FAIL!&lt;/a&gt;” is hot! &lt;a href="http://chuvakin.blogspot.com/2009/10/top-log-fail.html"&gt;The post&lt;/a&gt; summarizes the most egregious, reckless, painful, negligent, sad, idiotic examples of “Log FAIL.”&lt;/li&gt;    &lt;li&gt;Open source SIEM theme continues to drive a lot of traffic – it looks like folks are still desperately googling for it. “&lt;a href="http://chuvakin.blogspot.com/2009/06/why-no-open-source-siem-ever.html"&gt;Why No Open Source SIEM, EVER?&lt;/a&gt;” post takes the spot in Top5 this month again. The older inspiration for this post is “&lt;a href="http://chuvakin.blogspot.com/2007/01/on-open-source-in-siem-and-log.html"&gt;On Open Source in SIEM and Log Management&lt;/a&gt;.” &lt;/li&gt;    &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2009/10/must-read-on-walmart-intrusion.html"&gt;MUST Read on Walmart Intrusion&lt;/a&gt;” includes the juicy bits from the &lt;a href="http://www.wired.com/threatlevel/2009/10/walmart-hack/"&gt;full story at Wired&lt;/a&gt;. Some amazing examples of “log FAIL” are mentioned there, BTW.&lt;/li&gt;    &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2009/10/open-source-cloud-siem-anybody.html"&gt;Open Source CLOUD SIEM, Anybody?&lt;/a&gt;” post is where I shared some ideas on how to go about building an open source SIEM/SIM/SEM tool using cloud computing. It seems to have attracted a lot of attention. And it should have :-)&lt;/li&gt;    &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2009/10/compliance-security-does-security.html"&gt;Compliance != Security, Does Security = Compliance?&lt;/a&gt;” contains some fun analysis of situations where not only “compliance != security”, but also “security != compliance.”&amp;#160; This theme will definitely be explored in the future.&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;This month I am also starting a new tradition: I am going to thank my top 5 referrers this month (those that are actual humans, that is). So, thanks a lot to the following people whose blogs/resources sent most visitors to my blog:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev blog&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://devteev.blogspot.com/"&gt;Dmitry Evteev blog&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.mckeay.net/"&gt;Martin McKeay blog&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.infosecramblings.com/"&gt;Kevin Riggins Infosec Ramblings blog&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://taosecurity.blogspot.com/"&gt;Richard’s TaoSecurity blog&lt;/a&gt;&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Thanks for all the link-love!&lt;/p&gt;  &lt;p&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;See you&lt;/a&gt; in November. Also see my &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual “Top Posts”&lt;/a&gt; (&lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;)&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts / past monthly popular blog round-ups:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/10/monthly-blog-round-up-september-2009.html"&gt;Monthly Blog Round-Up – September 2009&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/09/monthly-blog-round-up-august-2009.html"&gt;Monthly Blog Round-Up – August 2009&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/08/monthly-blog-round-up-july-2009.html"&gt;Monthly Blog Round-Up – July 2009&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/07/monthly-blog-round-up-june-2009.html"&gt;Monthly Blog Round-Up – June 2009&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/06/monthly-blog-round-up-may-2009.html"&gt;Monthly Blog Round-Up – May 2009&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/05/monthly-blog-round-up-april-2009.html"&gt;Monthly Blog Round-Up – April 2009&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/04/monthly-blog-round-up-march-2009.html"&gt;Monthly Blog Round-Up – March 2009&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/03/monthly-blog-round-up-february-2009.html"&gt;Monthly Blog Round-Up – February 2009&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/02/monthly-blog-round-up-january-2009.html"&gt;Monthly Blog Round-Up - January 2009&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/01/monthly-blog-round-up-december-2008.html"&gt;Monthly Blog Round-Up - December 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/12/monthly-blog-round-up-november-2008.html"&gt;Monthly Blog Round-Up - November 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/11/monthly-blog-round-up-october-2008.html"&gt;Monthly Blog Round-Up - October 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html"&gt;Monthly Blog Round-Up - September 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html"&gt;Monthly Blog Round-Up - August 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html"&gt;Monthly Blog Round-Up - July 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html"&gt;Monthly Blog Round-Up - June 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html"&gt;Monthly Blog Round-Up - May 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html"&gt;Monthly Blog Round-Up - April 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html"&gt;Monthly Blog Round-Up - March 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html"&gt;Monthly Blog Round-Up - February 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html"&gt;Monthly Blog Round-Up - January 2008&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html"&gt;Monthly Blog Round-Up - December 2007&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html"&gt;Monthly Blog Round-Up - November 2007&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html"&gt;Monthly Blog Round-Up - October 2007&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html"&gt;Monthly Blog Round-Up - September 2007&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html"&gt;Monthly Blog Round-Up - August 2007&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;/div&gt;  &lt;p&gt;&lt;strong&gt;Obligatory “added everywhere” posts :-)&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;I am &lt;a href="http://chuvakin.blogspot.com/2009/08/not-at-qualys-anymore.html"&gt;not at Qualys anymore&lt;/a&gt; and looking for the next big security idea to work on! Meanwhile, I might be available for fun &lt;strong&gt;consulting projects&lt;/strong&gt; related to PCI DSS, log management, SIEM or other fun security things. &lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-3550388857767020486?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/nc0_Ma5-VyIVjmSeF7lpYet2wGs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nc0_Ma5-VyIVjmSeF7lpYet2wGs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/nc0_Ma5-VyIVjmSeF7lpYet2wGs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nc0_Ma5-VyIVjmSeF7lpYet2wGs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=e5r57Pqbr6o:ksIWRxb1hxM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=e5r57Pqbr6o:ksIWRxb1hxM:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=e5r57Pqbr6o:ksIWRxb1hxM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/e5r57Pqbr6o" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/3550388857767020486?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/3550388857767020486?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/e5r57Pqbr6o/monthly-blog-round-up-october-2009.html" title="Monthly Blog Round-Up – October 2009" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/11/monthly-blog-round-up-october-2009.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkAEQXs_eyp7ImA9WxNVGUQ.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-2013819349725337796</id><published>2009-10-31T05:05:00.000-07:00</published><updated>2009-10-31T05:05:00.543-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-31T05:05:00.543-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="musings" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Smelly Goat vs Flying Unicorn</title><content type="html">&lt;p&gt;On &lt;a href="http://fudsec.com/a-treatise-on-fud"&gt;FUDSec FUD piece&lt;/a&gt; and &lt;a href="http://newschoolsecurity.com/2009/10/just-say-no-to-fud/"&gt;“data-driven” security&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Q: If you ride a smelly, ugly goat along the road and then meet&amp;#160; a&amp;#160; handsome stranger who promises to give you a new ride: a beautiful unicorn that can fly, teleport, butt enemies with its horn and doesn’t need any cleaning, should you take it? &lt;/p&gt;  &lt;p&gt;&lt;img style="display: inline; margin-left: 0px; margin-right: 0px" align="right" src="http://t3.gstatic.com/images?q=tbn:ZYFblGf0Ib95XM:http://unicorns.wizardio.com/images/unicorn.jpg" /&gt;&lt;/p&gt;  &lt;p&gt;A: No! Unicorns are mythical creatures. Please keep your goat for now :-)&lt;/p&gt;  &lt;div style="margin-top: 10px; height: 15px" class="zemanta-pixie"&gt;&lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-2013819349725337796?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/4p3KbbUxvgDHgHzltMivj19NAlg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/4p3KbbUxvgDHgHzltMivj19NAlg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/4p3KbbUxvgDHgHzltMivj19NAlg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/4p3KbbUxvgDHgHzltMivj19NAlg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=R3ViMHPtmt8:onNe64ASdNM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=R3ViMHPtmt8:onNe64ASdNM:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=R3ViMHPtmt8:onNe64ASdNM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/R3ViMHPtmt8" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/2013819349725337796?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/2013819349725337796?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/R3ViMHPtmt8/smelly-goat-vs-flying-unicorn.html" title="Smelly Goat vs Flying Unicorn" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/smelly-goat-vs-flying-unicorn.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQEQX49eip7ImA9WxNVGU0.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-4125952222067744637</id><published>2009-10-30T05:05:00.000-07:00</published><updated>2009-10-30T05:05:00.062-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-30T05:05:00.062-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="FAIL" /><category scheme="http://www.blogger.com/atom/ns#" term="conference" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Notes from CSI2009 Annual Conference</title><content type="html">&lt;p&gt;If you’ve ever been to a ghost town before,&amp;#160; you didn’t need to go to CSI this year. It seemed to have only a few people even at HOT topics. Initially I thought that it was because I spent only the last day of the show there, but others told me that it was not the case. I saw a ghost of risk management there, BTW…&lt;/p&gt;  &lt;p&gt;Other people’s impressions:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://preachsecurity.blogspot.com/2009/10/csi-annual-2009.html"&gt;Rafal Los on CSIAnnual&lt;/a&gt; (some observations about lack of passion, which I didn’t notice since I spoke on &lt;a href="chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; and PCI=passion :-)) &lt;/li&gt;    &lt;li&gt;&lt;a href="http://tech-rumble.blogspot.com/2009/10/cloudy-day-at-csi-annual-convention.html"&gt;TechRumble on CSI&lt;/a&gt; (some fun cloud stuff that I missed at the show is mentioned there; quote: “Today even a 1-person startup can compete with Google and IBM in terms of infrastructure”) &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Also, if you’d like to see my “PCI DSS as a framework for security” presentation (with voice and all!), go &lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2009/10/my-fun-pci-webcast-on-oct-27-2009.html"&gt;here&lt;/a&gt;&lt;/u&gt;. It is essentially the same presentation that I gave at CSI, minus some magic tricks I played on the live audience :-)&lt;/p&gt;  &lt;p&gt;BTW, if you suffer from mild voyeurism, you can see a picture of me giving this presentation &lt;a href="http://twitpic.com/n9ov0"&gt;here&lt;/a&gt; (yes, I had explosions and demons in my PCI presentation :-)).&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/conference"&gt;All conference stuff&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/10/notes-from-nist-scap-5th-security.html"&gt;Notes from NIST SCAP 5th Security Automation Conference&lt;/a&gt; (a day before CSI2009)&lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-4125952222067744637?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/E68G-aYC3MamfQh2jDZBFbiSMQY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/E68G-aYC3MamfQh2jDZBFbiSMQY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/E68G-aYC3MamfQh2jDZBFbiSMQY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/E68G-aYC3MamfQh2jDZBFbiSMQY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=TX73fb9g7pI:7sgk5A3suKY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=TX73fb9g7pI:7sgk5A3suKY:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=TX73fb9g7pI:7sgk5A3suKY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/TX73fb9g7pI" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/4125952222067744637?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/4125952222067744637?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/TX73fb9g7pI/notes-from-csi2009-annual-conference.html" title="Notes from CSI2009 Annual Conference" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/notes-from-csi2009-annual-conference.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUYEQXk4eCp7ImA9WxNVGE0.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-4533361492215928740</id><published>2009-10-29T02:05:00.000-07:00</published><updated>2009-10-29T02:05:00.730-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-29T02:05:00.730-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="conference" /><category scheme="http://www.blogger.com/atom/ns#" term="security management" /><category scheme="http://www.blogger.com/atom/ns#" term="cloud" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="NIST" /><category scheme="http://www.blogger.com/atom/ns#" term="government" /><title>Notes from NIST SCAP 5th Security Automation Conference</title><content type="html">&lt;p&gt;Sadly, I only had one day to spent at this fun event, but it was definitely well worth it. I missed some of the keynotes as I was speaking with various people, so the first presentation I went to was supposed to be about “HBSS Open Framework.” In this reality :-), it was replaced by John Pescatore from Gartner. He started to go about FISMA and NIST 800-53 (and even FDCC) popping up in commercial space (contractors mostly), but then&amp;#160; quickly boosted into the cloud :-)&lt;/p&gt;  &lt;p&gt;One fun thing he sad was that what he used to call “nightmare [cloud] scenario” is now called “everybody scenario.”&amp;#160; His theme was that we used to think that security needs to be included when new [cloud] infrastructure is being built BUT (!) this moment is slipping away FAST! He even uttered that we need to “inject security back” as cloud train is speeding out of the station.&amp;#160; His vision can be summarized as&amp;#160; “MySecurity.cloud” – some kinda SaaS service that you go “through” before accessing other cloud services. He then quickly summarized what is the status of such “cloud exodus” now: vulnerability management is &amp;quot;”fully gone”, various filtering (“network security in the cloud”&amp;#160; - he called it “MitM security”) is going now, what will go next (&lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2009/10/open-source-cloud-siem-anybody.html"&gt;log management or SIEM&lt;/a&gt;&lt;/u&gt;)?&lt;/p&gt;  &lt;p&gt;Another interesting thought was about “full stack, continuous VM” – don’t just check for presence&amp;#160; of Skype (for example – he really means “all apps” including consumer apps on work PCs!) or for vulnerabilities in Skype, but check whether Skype is configured securely. He also show this fun chart: &lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="400"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="100"&gt;/\          &lt;br /&gt;|           &lt;br /&gt;axis: value to           &lt;br /&gt;business&lt;/td&gt;        &lt;td valign="top" width="100"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="100"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="100"&gt;&amp;#160;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="100"&gt;high&lt;/td&gt;        &lt;td valign="top" width="100"&gt;&lt;strong&gt;embrace&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="100"&gt;&lt;strong&gt;contain&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="100"&gt;&amp;#160;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="100"&gt;low&lt;/td&gt;        &lt;td valign="top" width="100"&gt;&lt;strong&gt;disregard&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="100"&gt;&lt;strong&gt;block&lt;/strong&gt;&lt;/td&gt;        &lt;td valign="top" width="100"&gt;&amp;#160;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="100"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="100"&gt;low&lt;/td&gt;        &lt;td valign="top" width="100"&gt;high&lt;/td&gt;        &lt;td valign="top" width="100"&gt;axis: security          &lt;br /&gt;pressure -&amp;gt;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;[I love how Gartner folks can visualize something complex into a neat chart…]&lt;/p&gt;  &lt;p&gt;Another insightful thought from him was that the world has shifted away from directories. There is “no directory for cell phone” – instead&amp;#160; “ring of trust” such as Facebook is it… &lt;/p&gt;  &lt;p&gt;Next I went to see Ed Bellis&amp;#160; fling some SCAP goodness. The main idea is that one can build a tool to automate the layer of tasks and issues above vulnerability assessment. Basically, the whole workflow from discovery –&amp;gt; remediation task planning –&amp;gt; fixing the issue –&amp;gt; retest –&amp;gt; validate + track everything for all regular and custom web application vulnerabilities. I find it really, really curious that VM vendors didn’t do it like this …. So, this was very useful and &lt;u&gt;&lt;a href="http://scap.nist.gov/events/2009/itsac/presentations/index.html"&gt;checking the slides&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;  &lt;p&gt; when posted will come hand. I found it interesting that there is absolutely no reconciliation between “security asset management/discovery” with “real IT asset management.” IMHO it drives the nail into a coffin of “IT ops and security convergence” theme that many folks adore … Also, web application flaw severity scoring is still a big hole. Where is CWSS when you need it? :-)&lt;/p&gt;  &lt;p&gt;Next I made a mistake of going to a vendor presentation. It was so salesy I almost puked :-) BTW, the name of the vendor rhymes with “BigAss.” Please, dear BigAss folks, next time send somebody who can talk substance and not just that you are “strong in government!”&lt;/p&gt;  &lt;p&gt;As far as trend watching, for a brief second I sensed that “SCAP use outside of the government” is an emerging trend, but it really isn’t. Using CVE and other identifiers as well as CVSS for scoring – outside the government or anywhere else for that matter – does not SCAP use make. It is simply called “common sense” :-) Now, if you found some use for the juiciest pieces of SCAP – OVAL and XCCDF – then we are talking…&lt;/p&gt;  &lt;p&gt;Next I went to CEE presentation and &lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2009/10/presentation-from-nist-scap.html"&gt;my log standards challenges presentation&lt;/a&gt;&lt;/u&gt;. Obviously, this was the highlight of the day. At this stage, BTW, now I am convinced we can win this one and start standardizing the logs! In particular, we will release the architecture specification in about a week or two.&lt;/p&gt;  &lt;p&gt;I am writing this on the train to CSI2009, notes from that show will come tomorrow…&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-4533361492215928740?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/K2_T8a11vyalZEGHwUNmZcjxol4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/K2_T8a11vyalZEGHwUNmZcjxol4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/K2_T8a11vyalZEGHwUNmZcjxol4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/K2_T8a11vyalZEGHwUNmZcjxol4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=2-Lsk0g0YFg:Fil9aOM7y3k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=2-Lsk0g0YFg:Fil9aOM7y3k:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=2-Lsk0g0YFg:Fil9aOM7y3k:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/2-Lsk0g0YFg" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/4533361492215928740?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/4533361492215928740?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/2-Lsk0g0YFg/notes-from-nist-scap-5th-security.html" title="Notes from NIST SCAP 5th Security Automation Conference" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/notes-from-nist-scap-5th-security.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkAEQX05cCp7ImA9WxNVF08.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-6438160616247536603</id><published>2009-10-28T02:05:00.000-07:00</published><updated>2009-10-28T02:05:00.328-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-28T02:05:00.328-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CEE" /><category scheme="http://www.blogger.com/atom/ns#" term="log management" /><category scheme="http://www.blogger.com/atom/ns#" term="logs" /><category scheme="http://www.blogger.com/atom/ns#" term="standards" /><category scheme="http://www.blogger.com/atom/ns#" term="logging" /><title>Presentation from NIST SCAP</title><content type="html">&lt;p&gt;As &lt;a href="http://chuvakin.blogspot.com/2009/10/5th-annual-it-security-automation.html"&gt;mentioned&lt;/a&gt; before, &lt;a href="http://www.slideshare.net/anton_chuvakin/logchaos-challenges-and-opportunities-of-security-log-standardization"&gt;here&lt;/a&gt; is my presentation from 5th Annual IT Security Automation Conference in Baltimore, MD on Oct 26-29, 2009.&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;div style="text-align: left; width: 425px" id="__ss_2361054"&gt;&lt;a style="margin: 12px 0px 3px; display: block; font: 14px helvetica,arial,sans-serif; text-decoration: underline" title="LogChaos: Challenges and Opportunities of Security Log Standardization" href="http://www.slideshare.net/anton_chuvakin/logchaos-challenges-and-opportunities-of-security-log-standardization"&gt;LogChaos: Challenges and Opportunities of Security Log Standardization&lt;/a&gt;&lt;object style="margin:0px" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=nistlogstandard-challengesrel-091027164614-phpapp02&amp;amp;stripped_title=logchaos-challenges-and-opportunities-of-security-log-standardization" /&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowScriptAccess" value="always" /&gt;&lt;embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=nistlogstandard-challengesrel-091027164614-phpapp02&amp;amp;stripped_title=logchaos-challenges-and-opportunities-of-security-log-standardization" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;    &lt;div style="font-family: tahoma,arial; height: 26px; font-size: 11px; padding-top: 2px"&gt;View more &lt;a style="text-decoration: underline" href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a style="text-decoration: underline" href="http://www.slideshare.net/anton_chuvakin"&gt;Anton Chuvakin&lt;/a&gt;.&lt;/div&gt; &lt;/div&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;Onto CSI2009 tomorrow; my PCI presentation there is going to be totally awesome :-) It will feature … The Devil!!!&lt;/p&gt;  &lt;p&gt;Also, events notes from the NIST event will follow later.&lt;/p&gt;  &lt;p&gt;See you there!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-6438160616247536603?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/MPVk39QJA47TvsOvNA5dZ3IjFN0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/MPVk39QJA47TvsOvNA5dZ3IjFN0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/MPVk39QJA47TvsOvNA5dZ3IjFN0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/MPVk39QJA47TvsOvNA5dZ3IjFN0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=0zic5LyoIFI:LmXiZbuklGs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=0zic5LyoIFI:LmXiZbuklGs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=0zic5LyoIFI:LmXiZbuklGs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/0zic5LyoIFI" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/6438160616247536603?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/6438160616247536603?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/0zic5LyoIFI/presentation-from-nist-scap.html" title="Presentation from NIST SCAP" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/presentation-from-nist-scap.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQEQX0_fyp7ImA9WxNVFk4.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-6851466939332061020</id><published>2009-10-27T02:05:00.000-07:00</published><updated>2009-10-27T02:05:00.347-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-27T02:05:00.347-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="log management" /><category scheme="http://www.blogger.com/atom/ns#" term="FAIL" /><category scheme="http://www.blogger.com/atom/ns#" term="logs" /><category scheme="http://www.blogger.com/atom/ns#" term="logging" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Top Log FAIL!</title><content type="html">&lt;p&gt;The &lt;a href="http://www.wired.com/threatlevel/2009/10/walmart-hack/"&gt;Wal-Mart story&lt;/a&gt; inspired me to summarize the most egregious, reckless, painful, negligent, sad, idiotic examples of “Log FAIL.”&amp;#160; Here they are:&lt;a href="http://lh5.ggpht.com/_eCy8mZux-aI/SuZyF6g3p3I/AAAAAAAAIlA/LcT8ITZM_BU/s1600-h/image3.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; margin-left: 0px; border-left-width: 0px; margin-right: 0px" title="image" border="0" alt="image" align="right" src="http://lh6.ggpht.com/_eCy8mZux-aI/SuZyGrodmwI/AAAAAAAAIlE/J1FYf1w3YRw/image_thumb1.png?imgmax=800" width="217" height="244" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;strong&gt;Logging disabled&lt;/strong&gt;: if you got a system which &lt;em&gt;had&lt;/em&gt; operational logging &lt;em&gt;enabled by default&lt;/em&gt; and then you turned it &lt;strong&gt;off&lt;/strong&gt; before deploying in production – congratulations! You truly earn your title of a &lt;strong&gt;Log Idiot!&lt;/strong&gt; :-) &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Logging not enabled:&lt;/strong&gt; this is more sad than anything else … and the person who will suffer the most from this is likely the one who has caused it. After all, you’d need those logs at some point yourself. There is nothing sadder than see a person having to explain to management, police, FBI, press, QSA, SEC, whoever: “Well, logging … was … never … enabled!”&amp;#160; (check out this &lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2006/11/are-you-ignoring-logs.html"&gt;motivational horror story&lt;/a&gt;&lt;/u&gt;)&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;No log centralization: &lt;/strong&gt;Windows admins, read this one – logs on the machine that crashed, was 0wned or even stolen will do you absolutely no good. It used to be that only Unix administratory can do this (via the magic of &lt;em&gt;/etc/syslog.conf&lt;/em&gt; line&lt;em&gt; “*.*&amp;#160;&amp;#160;&amp;#160; @loghost.example.com”&lt;/em&gt;), but you, on the Windows side, could not. Please notice that the world &lt;u&gt;&lt;a href="http://sourceforge.net/projects/lassolog/"&gt;is&lt;/a&gt;&lt;/u&gt; &lt;u&gt;&lt;a href="http://www.windowsnetworking.com/articles_tutorials/Monitoring-Event-Logs-Windows-Vista.html"&gt;different&lt;/a&gt;&lt;/u&gt; &lt;u&gt;&lt;a href="http://www.splunk.com/base/Documentation/4.0.4/Admin/MonitorWindowsdata"&gt;now&lt;/a&gt;&lt;/u&gt;!&amp;#160; (check out &lt;u&gt;&lt;a href="http://www.slideshare.net/anton_chuvakin/anton-chuvakin-on-security-data-centralization"&gt;this deck&lt;/a&gt;&lt;/u&gt; on benefits and tips related to log centralization) &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Log retention period too short:&lt;/strong&gt; the picture on the right should make this item (as well as the one above) painfully clear: doing “the right thing” and building the centralized logging infrastructure and then limiting the retention to 30 days is still “log FAIL.” Many, many scenarios today require logs from the past – for the juiciest examples check &lt;u&gt;&lt;a href="http://www.wired.com/threatlevel/2009/10/walmart-hack/"&gt;all the&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt; &lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2008/01/tjx-lessons.html"&gt;recent&lt;/a&gt;&lt;/u&gt; “&lt;em&gt;compromised in 2006 – discovered in 2008&lt;/em&gt;” stories (see some &lt;u&gt;&lt;a href="http://www.slideshare.net/anton_chuvakin/six-mistakes-of-log-management-2008"&gt;here in this deck&lt;/a&gt;&lt;/u&gt;) &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;No logging of “Granted”, “Accepted”, “Allowed”, etc: &lt;/strong&gt;I don’t even know where to start on this one – maybe thus: logging a firewall “connection blocked” events simply means that the firewall was doing its job, logging “connection allowed” shows that somebody is now in your network… The same&amp;#160; idea applies to logging “login failed” and missing “login successful” – please make really sure to always log &lt;em&gt;both&lt;/em&gt; (read&lt;u&gt; &lt;a href="http://chuvakin.blogspot.com/2006/09/anton-security-tip-of-day-3-watch-for.html"&gt;this tip&lt;/a&gt;&lt;/u&gt; for more examples, instructions and ideas) &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Bad logs:&lt;/strong&gt; if you are in operations, this is truly not your fault. But if you are in development – it probably is. Creating such logging classics as “failed successfully”&amp;#160; and “login failed” [&lt;em&gt;with no actual user name recorded&lt;/em&gt;] are fine examples of this “log FAIL.” Be aware that &lt;a href="http://chuvakin.blogspot.com/search/label/CEE"&gt;our work on CEE&lt;/a&gt;&lt;u&gt;&lt;/u&gt; will fix it eventually, but more hilarity will have to transpire before it happens (see &lt;u&gt;&lt;a href="http://www.slideshare.net/anton_chuvakin/application-logging-good-bad-ugly-beautiful-presentation"&gt;this deck&lt;/a&gt;&lt;/u&gt; for&amp;#160; some ideas on how not to engineer logging and how to do it – and for some examples of hilarity, of course) &lt;a href="http://lh5.ggpht.com/_eCy8mZux-aI/SuZyHAaqP5I/AAAAAAAAIlI/JmSDmMWkSPU/s1600-h/clip_image0024.jpg"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; margin-left: 0px; border-left-width: 0px; margin-right: 0px" title="clip_image002" border="0" alt="clip_image002" align="right" src="http://lh5.ggpht.com/_eCy8mZux-aI/SuZyIEGS9PI/AAAAAAAAIlM/ji_mOxifSrE/clip_image002_thumb1.jpg?imgmax=800" width="244" height="178" /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;No log review&lt;/strong&gt;&lt;em&gt; or &lt;/em&gt;&lt;strong&gt;nobody is looking at logs&lt;/strong&gt;: I am saving this “log FAIL” for last;&amp;#160; logs are created to be reviewed, monitored, searched, investigated, etc and NOT – I assure you! – to simply use up disk space (check my famous “&lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2007/07/top-11-reasons-to-look-at-your-logs.html"&gt;Top 11 Reasons to Look at Logs&lt;/a&gt;&lt;/u&gt;” as well the classic “&lt;u&gt;&lt;a href="http://www.slideshare.net/anton_chuvakin/oreilly-webinar-five-mistakes-log-analysis"&gt;Top Logging Mistakes&lt;/a&gt;&lt;/u&gt;” for more info on this one) &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;BTW, check out Branden’s musings about the same subject&amp;#160; &lt;a href="https://www.brandenwilliams.com/blog/2009/10/23/the-problem-with-logging/"&gt;here&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possible related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.leune.org/blog/kees/2007/10/fbi-at-risk-for-internal-espio.html"&gt;Another One from &amp;quot;Ignore Logs at Your Peril&amp;quot;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.darkreading.com/document.asp?doc_id=111067&amp;amp;page_number=7"&gt;Are YOU Ignoring Logs?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2007/12/again-on-criticality-of-logs.html"&gt;Again, On Criticality of Logs&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/02/top-11-reasons-to-analyze-your-logs.html"&gt;Top 11 Reasons to Analyze Your Logs&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/logging"&gt;Everything tagged “logging”&lt;/a&gt; (a lot!) &lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-6851466939332061020?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/-6fJrips-p8E7XldNeN-V6hCh_8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-6fJrips-p8E7XldNeN-V6hCh_8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/-6fJrips-p8E7XldNeN-V6hCh_8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-6fJrips-p8E7XldNeN-V6hCh_8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=rrioFvP0Mek:d1SnVMwDrwI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=rrioFvP0Mek:d1SnVMwDrwI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=rrioFvP0Mek:d1SnVMwDrwI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/rrioFvP0Mek" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/6851466939332061020?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/6851466939332061020?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/rrioFvP0Mek/top-log-fail.html" title="Top Log FAIL!" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/top-log-fail.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0IEQ3gzfCp7ImA9WxNVFUg.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-6786274296500432969</id><published>2009-10-26T05:05:00.000-07:00</published><updated>2009-10-26T05:18:22.684-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-26T05:18:22.684-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="compliance" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="reading" /><category scheme="http://www.blogger.com/atom/ns#" term="PCI" /><title>Fun Reading on Security and Compliance #20</title><content type="html">&lt;p&gt;Instead of my usual &amp;quot;blogging frenzy&amp;quot; machine gun blast of short posts, I will just combine them into my new blog series &amp;quot;&lt;a href="http://chuvakin.blogspot.com/search/label/reading"&gt;Fun Reading on Security AND Compliance&lt;/a&gt;.&amp;quot; Here is an issue #20, dated Oct 25, 2009 (read past ones &lt;a href="http://chuvakin.blogspot.com/search/label/reading"&gt;here&lt;/a&gt;).&lt;/p&gt;  &lt;p&gt;&lt;em&gt;This edition of dedicated to all the folks who write blogs, but never read blogs. Shame on you :-)&lt;/em&gt;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Very, very bold statement: “&lt;a href="http://blog.alertlogic.com/2009/09/why-on-premise-log-management-is-destined-for-extinction/"&gt;Why On-Premise Log Management is Destined for Extinction&lt;/a&gt;” from my friends at &lt;a href="http://www.alertlogic.com/"&gt;AlertLogic&lt;/a&gt;: “why, for all but the largest organizations, hosting your own log management solution in your data center simply won’t be a practical solution” &lt;/li&gt;    &lt;li&gt;Some fun metrics-related reading: “&lt;a href="http://securosis.com/blog/a-bit-on-the-state-of-security-metrics/"&gt;A Bit on the State of Security Metrics&lt;/a&gt;” (quote: “Security is a complex system based on a combination of biological (people) and computing elements. Thus our ability to model will always have a degree of fuzziness.”) and &lt;a href="http://www.securitymetrics.org/content/Wiki.jsp?page=Metricon4.0"&gt;Metricon 4.0 slides&lt;/a&gt; (some exude pure awesomeness). &lt;/li&gt;    &lt;li&gt;Cyber Security Awareness Month is almost over. Here is my token tribute to it – a link to SANS “month of tips”” &lt;a href="http://isc.sans.org/diary.html?storyid=7210"&gt;Day 1 - Port 445 - SMB over TCP&lt;/a&gt;, &lt;a href="http://isc.sans.org/diary.html?storyid=7216"&gt;Day 2&lt;/a&gt;, etc. (BTW, &lt;a href="http://www.cringely.com/2009/10/the-cybersecurity-myth/"&gt;here&lt;/a&gt; is somebody making fun of the whole thing) &lt;/li&gt;    &lt;li&gt;This is hot shit (“&lt;a href="http://www.csoonline.com/article/503778/5_Mistakes_a_Security_Vendor_Made_in_the_Cloud_?source=CSONLE_nlt_update_2009-10-01"&gt;5 Mistakes a Security Vendor Made in the Cloud&lt;/a&gt;”) and the sad part is that I know what the vendor is… Quote: &amp;quot;The client now doesn't trust itself and blocks everything.&amp;quot; Good news? It was fixed quickly :-) &lt;/li&gt;    &lt;li&gt;&lt;a href="http://securosis.com/"&gt;Securosis&lt;/a&gt; shares a very useful tip on database logging: “&lt;a href="http://securosis.com/blog/database-audit-events/"&gt;Database Audit Events&lt;/a&gt;” (full lists &lt;a href="http://securosis.com/research/publication/database-audit-events/"&gt;here&lt;/a&gt;) for popular databases &lt;/li&gt;    &lt;li&gt;From the bizarro world, comes this LinkedIn thread: “&lt;a href="http://www.linkedin.com/answers?viewQuestion=&amp;amp;questionID=561476&amp;amp;askerID=1027617&amp;amp;browseIdx=0&amp;amp;sik=&amp;amp;report.success=vfLh7ZiQxNtkwQoO3efsNN1zAgQ8WXmCT24lKBBmlHq_pfcN7JydQUoVP_zdv4b8"&gt;When will Information Security professionals stop talking about ROI?&lt;/a&gt;” &lt;/li&gt;    &lt;li&gt;Burton Group &lt;a href="http://srmsblog.burtongroup.com/2009/09/the-issue-of-saas-security.html"&gt;weighs in&lt;/a&gt; on &lt;a href="http://chuvakin.blogspot.com/search/label/saas"&gt;SaaS&lt;/a&gt; security; key quote: “[cloud] vendors will provide the controls they feel are necessary to get and retain customers. They will provide proof to the customers of the controls if asked and as long as the proof does not increase their costs too much.” &lt;/li&gt;    &lt;li&gt;Richard encounters a “data idiot” and beats him into the pulp: “&lt;a href="http://taosecurity.blogspot.com/2009/10/protect-data-idiot.html"&gt;&amp;quot;Protect the Data&amp;quot; Idiot!&lt;/a&gt;”, “&lt;a href="http://taosecurity.blogspot.com/2009/10/protect-data-from-whom.html"&gt;&amp;quot;Protect the Data&amp;quot; from Whom?&lt;/a&gt;” (the answer to “How do you protect yourself from nation-state actors?” is revealed…) and “&lt;a href="http://taosecurity.blogspot.com/2009/10/protect-data-where.html"&gt;&amp;quot;Protect the Data&amp;quot; Where?&lt;/a&gt;” Read it! &lt;/li&gt;    &lt;li&gt;Philippe &lt;a href="http://news.qualys.com/newsblog/Philippe_Courtot_ITAdviser.pdf"&gt;on the shift to the cloud [PDF]&lt;/a&gt;. Quote: “One day, almost everything we do on private networks – manage information, applications, infrastructure, and services – will be accessible instantly and securely from anywhere and from any Web browser.”&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.ethicalhacker.net"&gt;EthicalHacker.net&lt;/a&gt; is doing another challenge, &lt;a href="http://www.ethicalhacker.net/content/view/279/2/"&gt;here.&lt;/a&gt;&amp;#160;&lt;/li&gt;    &lt;li&gt;We had an &lt;a href="chuvakin.blogspot.com/search/label/ROI"&gt;ROI war&lt;/a&gt;. Now another war is coming: “&lt;a href="http://newschoolsecurity.com/2009/10/how-to-value-digital-assets-web-sites-etc/"&gt;How to Value Digital Assets?&lt;/a&gt;” started it. The pile-up is &lt;a href="http://blogs.forrester.com/srm/2009/10/information-asset-value-some-coldhearted-calculations-.html"&gt;here&lt;/a&gt;, &lt;a href="http://communities.intel.com/community/openportit/it/blog/2009/10/22/how-to-value-digital-assets"&gt;here&lt;/a&gt;, &lt;a href="http://1raindrop.typepad.com/1_raindrop/2009/10/lindstroms-razor.html"&gt;here&lt;/a&gt;, &lt;a href="http://spiresecurity.com/?p=1046"&gt;here&lt;/a&gt;, &lt;a href="http://newschoolsecurity.com/2009/10/on-the-value-of-digital-asset-value-for-security-decisions/"&gt;here&lt;/a&gt; – hostilities continue…&lt;/li&gt;    &lt;li&gt;Finally, &lt;a href="http://cognitivedissidents.wordpress.com/"&gt;Josh Corman&lt;/a&gt; (now &lt;a href="http://www.451group.com/security/451_security.php"&gt;a security lead at 451 Group&lt;/a&gt;) unleashes some awesomeness &lt;a href="http://fudsec.com/do-the-evolution-1"&gt;here&lt;/a&gt; at &lt;a href="http://fudsec.com/"&gt;FUDsec&lt;/a&gt;: “&lt;a href="http://fudsec.com/do-the-evolution-1"&gt;Do the Evolution..&lt;/a&gt;” He uses what lately became one of my favorite ideas as well: “Can you name *one* security control we’ve retired?” He also bitch-slaps some folks with “… or we could continue to whine about PCI ruining risk management” :-) BTW, you also must read the &lt;a href="http://fudsec.com/do-the-evolution-1"&gt;turmoil in the comments&lt;/a&gt;…&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; section: &lt;/strong&gt;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Good or bad data, but this is worth thinking about: “&lt;a href="http://www.pcworld.com/businesscenter/article/172438/pci_survey_finds_some_merchants_dont_use_antivirus_software.html"&gt;PCI Survey Finds Some Merchants Don't Use Antivirus Software&lt;/a&gt;” (PCI haters should read it too, BTW!) This is about folks who security is nowhere near PCI DSS levels. Key quote: “Around 10 percent of the respondents who said they were PCI DSS compliant said they weren't using basic security software such as antivirus, firewalls and SSL.”&amp;#160; More comments on it &lt;a href="http://www.braintreepaymentsolutions.com/blog/PCI-Compliance-a-Check-Box-for-70-Percent-of-Retailers/"&gt;here&lt;/a&gt;.&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.bankinfosecurity.com/articles.php?art_id=1823"&gt;Fun interview&lt;/a&gt; with Bob Russo. Enough said. Quote: “How many [QSAs] have left the QSA program because they weren't able to recertify [after being kicked in the balls by the QSA QA SWAT team]?” &lt;/li&gt;    &lt;li&gt;“&lt;a href="http://www.bankinfosecurity.com/articles.php?art_id=1869"&gt;Tokenization Vs. End-to-End Encryption: Experts Weigh in&lt;/a&gt;” (myself includes). “End-to-end” claim worry me in the same way intrusion PREVENTION worries me…&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;All other &lt;a href="http://chuvakin.blogspot.com/search/label/reading"&gt;security reading posts&lt;/a&gt;. &lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-6786274296500432969?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/B4vFxQDhtL3CIJtzHRm18eSG7Qw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B4vFxQDhtL3CIJtzHRm18eSG7Qw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/B4vFxQDhtL3CIJtzHRm18eSG7Qw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B4vFxQDhtL3CIJtzHRm18eSG7Qw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=H3KWxvKADwI:ku8xuV7fps0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=H3KWxvKADwI:ku8xuV7fps0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=H3KWxvKADwI:ku8xuV7fps0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/H3KWxvKADwI" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/6786274296500432969?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/6786274296500432969?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/H3KWxvKADwI/fun-reading-on-security-and-compliance.html" title="Fun Reading on Security and Compliance #20" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/fun-reading-on-security-and-compliance.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUCQXo5fip7ImA9WxNVFEQ.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-341708494040494936</id><published>2009-10-25T11:11:00.000-07:00</published><updated>2009-10-25T11:11:00.426-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-25T11:11:00.426-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="application" /><category scheme="http://www.blogger.com/atom/ns#" term="malware" /><category scheme="http://www.blogger.com/atom/ns#" term="compliance" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="PCI" /><title>On PCI and Whitelisting</title><content type="html">&lt;p&gt;I am hearing some interesting rumors… But let’s take a step back. &lt;a href="http://chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; Requirement 5.1 mandates the use of anti-virus on systems in scope of PCI (“Deploy anti-virus software on all systems commonly affected by malicious software”)&lt;/p&gt;  &lt;p&gt;Now, when people think “AV software” they think about classic anti-virus with daily updates, painful scans, etc. In other words, “&lt;a href="http://www.ranum.com/security/computer_security/editorials/dumb/index.html"&gt;enumerating badness&lt;/a&gt;”, blacklisting, &lt;a href="http://chuvakin.blogspot.com/2007/09/bit-more-on-av.html"&gt;FAIL&lt;/a&gt;, etc. Give relatively low adoption of the whitelisting for desktop security (and slightly wider adoption for single-purpose systems such as PoS or industrial control boxes), I was under impression that the issue of whether a whitelisting protection would be a satisfactory control for PCI Requirement 5 was never&amp;#160; presented to a QSA.&lt;/p&gt;  &lt;p&gt;Well, I was mistaken. It seems like many QSA WILL accept a whitelisting-based security application for Req 5, even if it is a pure whitelisting app with no embedded blacklisting mini-engine. Isn’t it cool?&lt;/p&gt;  &lt;p&gt;And the rumor was that PCI Council will issue some kind of an opinion on this soon. So, maybe, just maybe, &lt;a href="http://chuvakin.blogspot.com/2009/10/praying-to-pci-gods.html"&gt;PCI gods&lt;/a&gt; will bless this technology into wider adoption – I think it might well happen. And I think it deserves to happen, especially since some vendors have &lt;em&gt;usable&lt;/em&gt; implementations of whitelisting which does not plunge its user into “granular-policy-writing hell” (but more on this in the future…)&lt;/p&gt;  &lt;p&gt;BTW, my favorite whitelisting vendor, &lt;a href="http://www.savantprotection.com/"&gt;Savant Protection&lt;/a&gt; (where I &lt;a href="http://www.savantprotection.com/advisoryboard.html"&gt;serve on the advisory board&lt;/a&gt;) is &lt;a href="http://www.savantprotection.com/registerwebinar.html"&gt;doing a fun webinar&lt;/a&gt; on Tuesday, October 27th.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-341708494040494936?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/gzH9WiDCR_njuG_ubjV_KhFMD9U/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gzH9WiDCR_njuG_ubjV_KhFMD9U/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/gzH9WiDCR_njuG_ubjV_KhFMD9U/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gzH9WiDCR_njuG_ubjV_KhFMD9U/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=BzqhJev_rt0:Al-_msms17s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=BzqhJev_rt0:Al-_msms17s:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=BzqhJev_rt0:Al-_msms17s:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/BzqhJev_rt0" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/341708494040494936?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/341708494040494936?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/BzqhJev_rt0/on-pci-and-whitelisting.html" title="On PCI and Whitelisting" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/on-pci-and-whitelisting.html</feedburner:origLink></entry><entry><title type="text">Links for 2009-10-23 [del.icio.us]</title><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/QeM_bRqLqx8/anton18" /><updated>2009-10-24T00:00:00-07:00</updated><id>http://del.icio.us/anton18#2009-10-23</id><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blog.securitymonks.com/2009/08/09/standardization-and-interoperability-in-security/"&gt;System Advancements at the Monastery  &amp;raquo; Blog Archive   &amp;raquo; Standardization and Interoperability in Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://securosis.com/blog/a-bit-on-the-state-of-security-metrics/"&gt;Securosis						 Blog						 |						A Bit on the State of Security Metrics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://srmsblog.burtongroup.com/2009/09/the-issue-of-saas-security.html"&gt;Security and Risk Management Strategies Blog: The issue of SaaS Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://projects.webappsec.org/Web-Application-Security-Scanner-Evaluation-Criteria"&gt;The Web Application Security Consortium / Web Application Security Scanner Evaluation Criteria&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://steve.yegge.googlepages.com/google-at-delphi"&gt;Stevey's Home Page - the Google at Delphi&amp;nbsp;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://newschoolsecurity.com/2009/10/how-to-value-digital-assets-web-sites-etc/"&gt;How to Value Digital Assets (Web Sites, etc.) &amp;laquo;  The New School of Information Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/QeM_bRqLqx8" height="1" width="1"/&gt;</content><feedburner:origLink>http://del.icio.us/anton18#2009-10-23</feedburner:origLink></entry><entry gd:etag="W/&quot;CkACR3o4eCp7ImA9WxNVE08.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-7845632173458836596</id><published>2009-10-23T10:59:00.001-07:00</published><updated>2009-10-23T10:59:26.430-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-23T10:59:26.430-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SIEM" /><category scheme="http://www.blogger.com/atom/ns#" term="strategy" /><category scheme="http://www.blogger.com/atom/ns#" term="security management" /><category scheme="http://www.blogger.com/atom/ns#" term="cloud" /><category scheme="http://www.blogger.com/atom/ns#" term="musings" /><category scheme="http://www.blogger.com/atom/ns#" term="saas" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="SEM" /><category scheme="http://www.blogger.com/atom/ns#" term="SIM" /><title>Open Source CLOUD SIEM, Anybody?</title><content type="html">&lt;p&gt;&amp;quot;It's too bad I am not building an open-source SIEM … but if I would&amp;quot; (&lt;em&gt;extra credit&lt;/em&gt;: guess the inspiration for this line), I would actually not build a software security information and event management (SIEM) product.&lt;/p&gt;  &lt;p&gt;If I were doing it (and I am not!),&amp;#160; I’d built an open-source-based “cloud SIEM” with a default option to have it hosted by the vendor (that is you) as well as with a possibility to have it hosted by the customer (that is, old school on-premise model). The latter option would give you a classic open source “product.”&lt;/p&gt;  &lt;p&gt;Think about it! If you are a new company, you cannot afford to be in the appliance business. That leaves two choices: software and &lt;a href="http://chuvakin.blogspot.com/search/label/saas"&gt;SaaS&lt;/a&gt;. If you want to sell software, you are probably insane, go lock yourself up :-) If you want to give away software and sell services, you are OK. But won’t SaaS be better? And you can combine it with on-prem model, if some folks insist.&amp;#160; My &lt;a href="chuvakin.blogspot.com/2009/08/not-at-qualys-anymore.html"&gt;recent employment&lt;/a&gt; made me quite SaaS-obsessed, since I had a chance to observe an excellent SaaS operation from the inside. It was amazing how easy it is to provision trials as well deploy the service in production, track usage and improve customer experience.&lt;/p&gt;  &lt;p&gt;But let’s take a step back first! A lot of folks try to understand the relationship between “open source” and “cloud everything” (discussions about their relationship &lt;a href="http://blogs.gartner.com/andrea_dimaio/2009/09/02/is-cloud-computing-killing-open-source-in-government/"&gt;here&lt;/a&gt;, &lt;a href="http://radar.oreilly.com/2008/07/open-source-and-cloud-computing.html"&gt;here&lt;/a&gt;, &lt;a href="http://www.ebizq.net/blogs/cloudtalk/2009/09/is_cloud_computing_killing_ope.php"&gt;here&lt;/a&gt; and obviously &lt;a href="http://www.eucalyptus.com/open/"&gt;here&lt;/a&gt;). The main idea here is the following: if people have “trust issues” with cloud providers, what is a better “mistrust breaker” than showing the source code for your solution? “Wonna audit?” - “Knock yourself out!” Moreover, if people have “hidden costs issues” with open source software, what is a better way to mitigate&amp;#160; it but to offer to run it for them? No hidden costs, not even electricity…&lt;/p&gt;  &lt;p&gt;So, if you are possessed by SIEM aspirations (and I am not!), head to the clouds. For starters, your tool will be easier to deploy and update. But what is much more important, you’d take a fare shot at solving scalability problems without being a database tuning uber-guru. Unlike early software SIEM vendors (&lt;a href="http://failblog.org/"&gt;FAIL!&lt;/a&gt;), you won’t have to sheepishly point in the direction of mammoth Sun boxes, you’d just fire up another EC2 instance (or a thousand).&amp;#160; Moreover, on the scalability front, you’d have a fare shot against established SIEM vendors: I often hear rumors that even today, in the age of “cheap hardware”, some large organizations with loads of log data simply cannot architect a SIEM to handle all their security log data. And cloud computing leads to affordable scalability!&lt;/p&gt;  &lt;p&gt;Solving these performance problems will let you use the CPU resources for log data parsing, correlation, stored data analysis and all sorts of other fun stuff. Storage, whether raw text or parsed data, will be even easier. Bandwidth will be a bit tricky, but I am leaving it out of this piece for a particular reason … don’t want to spill too much (I am leaving “the collection challenge” out as well).&lt;/p&gt;  &lt;p&gt;Finally, as cloud applications [as well as web applications, in general] grow in importance, the whole idea of “SIEM in the cloud for the cloud” won’t be as naive. As we know,&amp;#160; the need for auditing comes last (&lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2008/02/auditmonitor-controls-or-auditmonitor.html"&gt;here&lt;/a&gt;&lt;/u&gt;), but when it does come, it will come in force and both SMBs and F2000s will have this problem.&amp;#160; And it never hurts to be better prepared for the death of on-prem apps, if we are to believe&lt;u&gt; &lt;a href="https://365.rsaconference.com/blogs/podcast_series_rsa_conference_2009/2009/04/20/philippe-courtot-keynote-changing-security-as-we-know-it-software-as-a-service-saas-has-arrived-giving-rise-to-plethora-of-security-applications"&gt;certain visionaries.&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;  &lt;p&gt;So, throw together some EC2 magic, some database code and a sleek, well-designed UI to delight the users – and you are ready to do battle with foes 10x your size…&lt;/p&gt;  &lt;p&gt;Any thoughts?&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/06/why-no-open-source-siem-ever.html"&gt;Why No Open Source SIEM, EVER?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;“&lt;a href="http://www.matasano.com/log/661/pro-forma-06-punditry-results/"&gt;On Open Source in SIEM and Log Management&lt;/a&gt;&lt;a href="http://chuvakin.blogspot.com/2007/01/on-open-source-in-siem-and-log.html"&gt;”&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;Various SIEM posts.&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;strong&gt;Obligatory “added everywhere” posts :-)&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;I am &lt;a href="http://chuvakin.blogspot.com/2009/08/not-at-qualys-anymore.html"&gt;not at Qualys anymore&lt;/a&gt; and looking for the next big security idea to work on! Meanwhile, I might be available for fun consulting projects related to PCI, log management or other fun security things. &lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-7845632173458836596?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/gniWOpJQniiPiWRJtzKj8kaj0qM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gniWOpJQniiPiWRJtzKj8kaj0qM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/gniWOpJQniiPiWRJtzKj8kaj0qM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gniWOpJQniiPiWRJtzKj8kaj0qM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=NTfRGGYwZW8:4CZF5Znl8no:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=NTfRGGYwZW8:4CZF5Znl8no:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=NTfRGGYwZW8:4CZF5Znl8no:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/NTfRGGYwZW8" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/7845632173458836596?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/7845632173458836596?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/NTfRGGYwZW8/open-source-cloud-siem-anybody.html" title="Open Source CLOUD SIEM, Anybody?" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/open-source-cloud-siem-anybody.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0UNRns6cCp7ImA9WxNVEUU.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-2509077029171220855</id><published>2009-10-21T19:58:00.000-07:00</published><updated>2009-10-21T22:28:17.518-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-21T22:28:17.518-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="conference" /><category scheme="http://www.blogger.com/atom/ns#" term="personal" /><category scheme="http://www.blogger.com/atom/ns#" term="compliance" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="PCI" /><title>My Fun PCI Webcast on Oct 27, 2009</title><content type="html">&lt;div&gt;So, apart from flying to Baltimore, speaking at &lt;a href="http://chuvakin.blogspot.com/2009/09/speaking-at-csi-2009-and-conference.html"&gt;CSI2009&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/2009/09/speaking-at-nist-security-automation.html"&gt;NIST Security Automation conference&lt;/a&gt; and meeting a huge number of fun people, next week I will also be doing this exciting &lt;a href="http://chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; webcast, where I will unveil my latest idea. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here is an embed that talks about it:&lt;/div&gt;&lt;br /&gt;&lt;object width="705" height="660"&gt; &lt;param name="movie" value="http://www.brighttalk.com/dc/swf/dotcom_base.swf?212"&gt;  &lt;param name="flashvars" value="channelid=188&amp;amp;commid=4716&amp;amp;autoStart=FALSE"&gt;  &lt;embed src="http://www.brighttalk.com/dc/swf/dotcom_base.swf?234" type="application/x-shockwave-flash" width="705" height="660" wmode="transparent" flashvars="channelid=188&amp;amp;commid=4716&amp;amp;autoStart=FALSE"&gt;&lt;/embed&gt;  &lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;And if you are in Baltimore at CSI or NIST  - see you next week!.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;P.S. Somebody&lt;/i&gt; (wink-wink) promised to bring cigars, please do it ;-)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-2509077029171220855?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/7HbTpGXzRQeAgtuND4MUujX4VbA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/7HbTpGXzRQeAgtuND4MUujX4VbA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/7HbTpGXzRQeAgtuND4MUujX4VbA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/7HbTpGXzRQeAgtuND4MUujX4VbA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=iv7vlshB6Lc:myOXVRnPehk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=iv7vlshB6Lc:myOXVRnPehk:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=iv7vlshB6Lc:myOXVRnPehk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/iv7vlshB6Lc" height="1" width="1"/&gt;</content><link rel="related" href="http://www.brighttalk.com/summit/pcicompliance2" title="My Fun PCI Webcast on Oct 27, 2009" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/2509077029171220855?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/2509077029171220855?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/iv7vlshB6Lc/my-fun-pci-webcast-on-oct-27-2009.html" title="My Fun PCI Webcast on Oct 27, 2009" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/my-fun-pci-webcast-on-oct-27-2009.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU4EQX4zcSp7ImA9WxNWGUg.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-1026957062202466356</id><published>2009-10-19T05:05:00.000-07:00</published><updated>2009-10-19T05:05:00.089-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-19T05:05:00.089-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="book review" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="review" /><category scheme="http://www.blogger.com/atom/ns#" term="book" /><title>Book Review: “Into the Breach”</title><content type="html">&lt;p&gt;&lt;a href="http://www.amazon.com/gp/product/0981636306"&gt;“Into the breach” by Michael Santarcangelo&lt;/a&gt; is actually a fun read; it seems to be a useful book on security for management. It is non-technical by design since it is about the people side of security. In fact, he presents security itself as “a human issue.”&lt;/p&gt;  &lt;p&gt;One of my favorite sections in Part 1 reminds that many policy violations happen because people just want to do their jobs better (the author also claims that people “want to do the right thing” if such choice is easy enough). I loved the “compliance is not a video game” theme, where your faults do not have real world consequences, as well as “security as something inflicted upon the organization” and “security as a crash diet” themes. What is also interesting is that the book seeks to solve one of the key problems of “what is risky?” vs “what is only perceived as risky?” &lt;/p&gt;  &lt;p&gt;The part of the book is Part 2 where author’s “strategy to protect information” is unveiled. The author then goes into some level of details on how to implement the strategy (run a pilot, “build a flywheel”, etc).&lt;/p&gt;  &lt;p&gt;On the negative side, I was saddened that Michael succumbed to a popular insider myth (on page 11 – “70% of attacks are by insiders”) while trying to dispel another security myth. That is the risk anybody runs while quoting too many questionable surveys. Also, the book sounds too fluffy at times (e.g. the strategy is “understand-engage-optimize”, frequent advice to “be effective”, etc), but does seem to convey its message pretty well. &lt;/p&gt;  &lt;p&gt;Overall, if you are managing security on a high level, or manage IT or even the whole business, read this book. It is short enough so that such people will read it and get the ideas! If you are a security pro and can handle a non-technical volume, grab it as well and keep in mind that this is a management book. After reading it, please give it you your manager!&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;My &lt;a href="http://chuvakin.blogspot.com/search/label/book%20review"&gt;other recent book reviews&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;My &lt;a href="http://www.amazon.com/gp/cdp/member-reviews/A25L1P7IWHNRSB"&gt;Amazon book reviews&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;My &lt;a href="http://www.chuvakin.org/book.html"&gt;old book reviews&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-1026957062202466356?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/bckR3Te8Fx6h3hIIkY8UFVVkIu4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bckR3Te8Fx6h3hIIkY8UFVVkIu4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/bckR3Te8Fx6h3hIIkY8UFVVkIu4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bckR3Te8Fx6h3hIIkY8UFVVkIu4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=-T65ORvOBHY:r9pike-NpTQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=-T65ORvOBHY:r9pike-NpTQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=-T65ORvOBHY:r9pike-NpTQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/-T65ORvOBHY" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/1026957062202466356?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/1026957062202466356?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/-T65ORvOBHY/book-review-into-breach.html" title="Book Review: “Into the Breach”" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/book-review-into-breach.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0cFSXg4eCp7ImA9WxNVFUo.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-3731120466951166650</id><published>2009-10-16T01:01:00.000-07:00</published><updated>2009-10-26T09:36:58.630-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-26T09:36:58.630-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="compliance" /><category scheme="http://www.blogger.com/atom/ns#" term="musings" /><category scheme="http://www.blogger.com/atom/ns#" term="humor" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="PCI" /><title>Praying to PCI Gods</title><content type="html">&lt;p&gt;Obviously, inspired by &lt;a href="http://techbuddha.wordpress.com/"&gt;Amrit’s&lt;/a&gt; “&lt;a href="http://www.computerworlduk.com/community/blogs/index.cfm?entryid=2573&amp;amp;blogid=33"&gt;Exorcising the PCI demons&lt;/a&gt;” and, in fact, morphed right from it.&lt;/p&gt;  &lt;p&gt;“… But let’s get back to Josh’s demonological metaphor and consider some of the ways that PCI resembles ...” &lt;strong&gt;the Benign Deity&lt;/strong&gt; (specific deity is up to the reader…)&lt;/p&gt;  &lt;p&gt;&lt;b&gt;The God holds promise. &lt;/b&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; offers its adherents access to the spiritual  riches — and not only those attainable through debit and credit cards—so long as they know and respect (and validate!) PCI’s 12 commandments. While delivering its spiritual riches, it also makes its adherents BETTER in the process: better security, better businesses, better awareness of the threats.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;The God is honest.&lt;/b&gt; PCI does not promise falsities such as “to make retailers secure against hackers.” It promises to raise them out of the ignorance and “0wnage” to finally having a modicum of much-needed security technology and process.&lt;/p&gt;  &lt;p&gt;The sorry history of breaches, blowouts, and damaged reputations attests that there is a long and sometimes difficult road ahead of us and that both faith and hard work will be needed along the way.&lt;/p&gt;  &lt;p&gt;The great thing is that PCI is likely the best that many organizations can use to protect a transaction technology based on account numbers, magnetic stripes, fixed user identities, and passwords.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;The God is an inspiration for goodness. &lt;/b&gt;PCI has led countless companies and organizations to improve security and reduce their operational risks – as well as instill customer confidence.&lt;/p&gt;  &lt;p&gt;Security professionals often find themselves assisted by the PCI God when they win an argument with management which then allows them to start taking actions to block threats and keep the business running and out of the negative press. PCI both inspires them to build a solid security program and helps them as a powerful force for good security.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;The God loves humanity, &lt;a href="https://www.brandenwilliams.com/blog/2009/09/18/why-you-should-love-a-pci-hater/"&gt;even its haters&lt;/a&gt;.&lt;/b&gt; As at least one commentator has pointed out, the PCI standard is a brilliant way to shift responsibility for IT security from card issuers to retailers. &lt;/p&gt;  &lt;p&gt;It is indeed brilliant since many merchants are negligent and lose card data in massive amounts as a result of their own ignorance, but issuing banks have to “eat” all of the card replacement costs which are due to no fault of their own.&lt;/p&gt;  &lt;p&gt;Card issuing banks did not invent and institute the technologies that have proven so vulnerable to moderately skilled hackers. When a breach occurs, merchants shrug and talk about their devotion to promulgating security measures, knowing that the issuers will be left with all of the card replacement costs and some of the fraud costs.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;The God is sometimes a sacrificial lamb. &lt;/b&gt;There are two groups that will vehemently attack the virtues of PCI by completely lacking any insight into it. One group are organizations who refuse to implement any security measures and prefer to be negligent and breach the social contract with their customers by losing their data left and right. The other group are idiotic perfectionists who want all the data to be protected all the time, no matter what the business impact. The latter group also wants somebody (but, obviously, not them!) to pay for an overhaul of the world’s electronic payment processing systems.&lt;/p&gt;  &lt;p&gt;Vendors that provide security solutions and those that provide PCI assessment services, also known as qualified security assessors (QSA), will always position PCI as necessary and useful for security. Indeed, PCI God guides the willing – by providing the Data Security Standard – and motivates those still in the darkness – by providing the validation regime and His army of God’s Angels aka QSAs.&lt;/p&gt;  &lt;p&gt;At this point, readers may ask, with all of the God’s awesomeness and track record in doing good even to those who prefer to remain ignorant, why do people criticize it? Well, remember the old saying: "&lt;a href="http://afeatheradrift.files.wordpress.com/2009/07/stupid_people.jpg"&gt;I see...&lt;/a&gt;"&lt;/p&gt;&lt;p&gt;&lt;b&gt;UPDATE&lt;/b&gt;: link for the "I see..." updated; the previous link had some bad language in comments. Thanks for one of my readers for pointing it out.&lt;/p&gt;  &lt;p&gt;Amrit, sorry for all the quoting! :-) Enjoy!&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/04/five-reasons-to-dislike-pci-dss-and-why.html"&gt;Five Reasons to Dislike PCI DSS – And Why They Are WRONG!&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-3731120466951166650?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/L89pUNqyaE2QKStXvYS0paNl1Rs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/L89pUNqyaE2QKStXvYS0paNl1Rs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/L89pUNqyaE2QKStXvYS0paNl1Rs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/L89pUNqyaE2QKStXvYS0paNl1Rs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=rFxWocjdfDQ:33Mi2khJzNI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=rFxWocjdfDQ:33Mi2khJzNI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=rFxWocjdfDQ:33Mi2khJzNI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/rFxWocjdfDQ" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/3731120466951166650?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/3731120466951166650?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/rFxWocjdfDQ/praying-to-pci-gods.html" title="Praying to PCI Gods" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/praying-to-pci-gods.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0MARHg5eCp7ImA9WxNWFk8.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-5584564385575568380</id><published>2009-10-15T09:50:00.001-07:00</published><updated>2009-10-15T09:50:45.620-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-15T09:50:45.620-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="conference" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Notes from Cornerstones of Trust Conference</title><content type="html">&lt;p&gt;I spent a day yesterday at &lt;a href="http://cornerstonesoftrust.com"&gt;Cornerstones of Trust Conference conference&lt;/a&gt; here in Bay Area. The event was “a cooperative effort of the San Francisco Bay and Silicon Valley chapters of the Information Systems Security Association (ISSA); and San Francisco Bay Area InfraGard.”&lt;/p&gt;  &lt;p&gt;Here is what I attended; they promise to post the presentations soon:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;“Compliance is Not The Same as Security” panel moderated by&amp;#160; &lt;a href="http://cornerstonesoftrust.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=72&amp;amp;Itemid=66#robertw"&gt;Robert K. West&lt;/a&gt;, CEO and Founder of &lt;a href="http://www.echelonone.net/"&gt;Echelon One&lt;/a&gt;.&lt;/li&gt;    &lt;li&gt;“Head in the clouds, feet on the ground - The business side of security in the cloud” by &lt;a href="http://cornerstonesoftrust.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=72&amp;amp;Itemid=65#timm"&gt;Tim Mather&lt;/a&gt;, Security Strategist and &lt;a href="http://cornerstonesoftrust.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=72&amp;amp;Itemid=65#subra"&gt;Subra Kumaraswamy&lt;/a&gt;.&lt;/li&gt;    &lt;li&gt;&amp;quot;Why We Must Develop a New Model for Collaboration in Cyber Security: A Perspective on America’s Innovation Crisis&amp;quot;, keynote by &lt;a href="http://cornerstonesoftrust.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=72&amp;amp;Itemid=68#pascal"&gt;Pascal Levenson&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;“Cloud Computing Security - Practical and Actionable Security Controls to Assess the Cloud Vendor” by &lt;a&gt;Brian Koref , Information Security Officer at KLA-Tencor&lt;/a&gt;.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Do you know what amazed me the most about this event? Lack of tweeting! Back at &lt;a href="http://chuvakin.blogspot.com/search/label/RSA"&gt;RSA&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/BlackHat"&gt;BlackHat&lt;/a&gt;, you can see flashes of TweetDeck everywhere in the audience, if you look from the back. Here – you see a lone gunman…eh... tweetman :-)&amp;#160; In any case, I invented” the hashtag &lt;a href="http://search.twitter.com/search?q=%23cornerstonestrust"&gt;“#cornerstonestrust&lt;/a&gt;” and took some notes; read them &lt;a href="http://search.twitter.com/search?q=%23cornerstonestrust"&gt;here&lt;/a&gt; (as usual, you have to read from the bottom).&lt;/p&gt;  &lt;p&gt;The conference was fun, but I couple of times I had my “buffoon alert” tingled. For example, somebody said that Heartland is suing their QSA and, to the best of my knowledge, that is not true. Cloud sessions – both of them – were pretty interesting. I learned what is “cloud angst”&amp;#160; and realized that despite &lt;a href="http://www.cloudsecurityalliance.org/"&gt;CSA&lt;/a&gt; work, people are still creating their own cloud provider diligence sheets (hopefully, the upcoming version 2 will help). The innovation keynote reminded me of my ROTC training in PsyOps. Namely, when you push your message &lt;em&gt;too&lt;/em&gt; hard, people just start doubting you (our ROTC colonel also cautioned us from ever saying anything like “I am not saying it because I profit from it; on the opposite…” :-))&lt;/p&gt;  &lt;p&gt;In any case, the conference was a day well spent!&lt;/p&gt;  &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-5584564385575568380?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/aXyTP3oMWUOXzI_FDZuHJWsnF9A/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/aXyTP3oMWUOXzI_FDZuHJWsnF9A/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/aXyTP3oMWUOXzI_FDZuHJWsnF9A/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/aXyTP3oMWUOXzI_FDZuHJWsnF9A/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Pq8QIBKNQU0:kwy7ukDekwA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Pq8QIBKNQU0:kwy7ukDekwA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Pq8QIBKNQU0:kwy7ukDekwA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/Pq8QIBKNQU0" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/5584564385575568380?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/5584564385575568380?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/Pq8QIBKNQU0/notes-from-cornerstones-of-trust.html" title="Notes from Cornerstones of Trust Conference" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/notes-from-cornerstones-of-trust.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C04EQXkyeCp7ImA9WxNWFU8.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-5955716168049416419</id><published>2009-10-14T05:05:00.000-07:00</published><updated>2009-10-14T05:05:00.790-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-14T05:05:00.790-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="log management" /><category scheme="http://www.blogger.com/atom/ns#" term="logs" /><category scheme="http://www.blogger.com/atom/ns#" term="logging" /><title>SANS Log Management Class – CDI2009</title><content type="html">&lt;p&gt;As some of you know, I’ve been secretly working on a one day SANS Log Management class for quite some time now. A few trials were conducted and most-if-not-all-all guinea pigs survived their encounter with the log :-)&lt;/p&gt;  &lt;p&gt;It now seems increasing likely that this class will be first launched at &lt;a href="http://www.sans.org/cyber-defense-initiative-2009"&gt;SANS CDI 2009&lt;/a&gt; in DC this December.&lt;/p&gt;  &lt;p&gt;Here is the information about it – please sign up now:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://www.sans.org/cyber-defense-initiative-2009/description.php?tid=2912"&gt;Log Management In-Depth: Compliance, Security, Forensics, and Troubleshooting&lt;/a&gt;&amp;#160; (1 day)&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Thursday, December 17, 2009 : &lt;em&gt;9am – 5pm&lt;/em&gt;&lt;/strong&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Description:&amp;#160; &lt;/strong&gt;This first-ever dedicated log management class for IT and security managers will cover system, network, and security logs and their management at an organization. We will start with the basics, like making sure that logs exist, and then go on to touch upon everything from managing log storage, to analysis techniques, to log forensics and regulatory issues related to logging.&lt;/p&gt;    &lt;p&gt;In the beginning, we will cover various log types and provide configuration guidance, describe a phased approach to implementing a company-wide log management program, and go into specific tasks that IT and security managers need to be focusing on a daily, weekly, and monthly basis in regards to log monitoring.&lt;/p&gt;    &lt;p&gt;A unique and comprehensive section that covers the hot topic of using logs for regulatory compliance, such as PCI DSS, will also be presented. Everybody knows that logs are essential for resolving compliance challenges; this class will teach you what you need to concentrate on and how to make your log management &lt;q&gt;compliance-friendly.&lt;/q&gt;&lt;/p&gt;    &lt;p&gt;The class will also touch upon various uses of logs for incident response, forensics, and operational monitoring. Common logging mistakes, learned from many years of working with logs, will also be explained.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Here is my “&lt;strong&gt;Author Statement&lt;/strong&gt;” about &lt;a href="http://www.sans.org/cyber-defense-initiative-2009/description.php?tid=2912"&gt;the class&lt;/a&gt;:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Logs and log analysis have long been one of the most challenging areas of security; they are also closely tied to proper system and network administration practices. With regulatory compliance added on top with specific requirements on log collection, retention, and analysis (such as those found in PCI DSS), there has never been a better time to FINALLY get your logs under control. This class is the first-ever dedicated class on getting your log management project right. If you know that &amp;quot;you need to have those logs handled!&amp;quot;, sign up and learn exactly how to do that. Many years of experience with logs went into this class and so you, an attendee, have a chance to avoid the most damaging mistakes and learn from many years of the author's experience with logging, log management, log tools, and the use of logs for various purposes.      &lt;br /&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.sans.org/cyber-defense-initiative-2009/description.php?tid=2912"&gt;More info and sign-up here&lt;/a&gt;!&lt;/p&gt;  &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-5955716168049416419?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/nIG0xqV1cxpBbwXN_Dt-46L0PL4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nIG0xqV1cxpBbwXN_Dt-46L0PL4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/nIG0xqV1cxpBbwXN_Dt-46L0PL4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nIG0xqV1cxpBbwXN_Dt-46L0PL4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=QPe3Oot3-y4:_ek6x1tXPhE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=QPe3Oot3-y4:_ek6x1tXPhE:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=QPe3Oot3-y4:_ek6x1tXPhE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/QPe3Oot3-y4" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/5955716168049416419?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/5955716168049416419?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/QPe3Oot3-y4/sans-log-management-class-cdi2009.html" title="SANS Log Management Class – CDI2009" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/sans-log-management-class-cdi2009.html</feedburner:origLink></entry><entry><title type="text">Links for 2009-10-13 [del.icio.us]</title><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/UuShOqNEGJo/anton18" /><updated>2009-10-14T00:00:00-07:00</updated><id>http://del.icio.us/anton18#2009-10-13</id><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;a href="http://atlanta.bizjournals.com/atlanta/stories/2009/10/12/daily23.html"&gt;Barracuda Networks buys Purewire - Atlanta Business Chronicle:&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/UuShOqNEGJo" height="1" width="1"/&gt;</content><feedburner:origLink>http://del.icio.us/anton18#2009-10-13</feedburner:origLink></entry><entry gd:etag="W/&quot;CkAGSXgzfip7ImA9WxNWFEs.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-2970360127824786963</id><published>2009-10-13T12:05:00.001-07:00</published><updated>2009-10-13T12:05:28.686-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-13T12:05:28.686-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="compliance" /><category scheme="http://www.blogger.com/atom/ns#" term="intrusion" /><category scheme="http://www.blogger.com/atom/ns#" term="incident" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="PCI" /><title>MUST Read on Walmart Intrusion</title><content type="html">&lt;p&gt;Move over “Heartland-gate”, make room for “Walmart-gate” :-)&lt;/p&gt;  &lt;p&gt;Wired uncovers a &lt;strong&gt;very&lt;/strong&gt; fun story &lt;a href="http://www.wired.com/threatlevel/2009/10/walmart-hack/"&gt;here&lt;/a&gt;. The juiciest quotes follow below:&lt;/p&gt;  &lt;p&gt;On intruder goals:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“hackers targeted the development team in charge of the chain’s point-of-sale system and siphoned source code and other sensitive data”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;On practices:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“at least four years’ worth of customer purchasing data, including names, card numbers and expiration dates, were housed on company networks in unencrypted form.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;On intrusion discovery (Was is … an IDS maybe? Ha, not funny!):&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“a fortuitous server crash led administrators to a password-cracking tool that had been surreptitiously installed on one of its servers”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;On logging:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“The company’s server logs recorded only unsuccessful log-in attempts, not successful ones, frustrating a detailed analysis.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Please read the above line again! Again! &lt;strong&gt;AGAIN&lt;/strong&gt;!&lt;/p&gt;  &lt;p&gt;On some spoils of war:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“one of the documents that flew off to Minsk from a programmer’s machine was titled“POS Store Systems Technical Specifications TLOG Encryption and Financial Flows.” […] The hackers also stole or accessed files containing point-of-sale source code and executables, as well as additional proprietary documentation detailing the company’s transaction processing network.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;On PCI role:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“Wal-Mart says it received a number of [&lt;a href="http://chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; compliance validation] deadline extensions […] … became certified as PCI-compliant in August 2006 by VeriSign. After it discovered the breach in November 2006 …”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.wired.com/threatlevel/2009/10/walmart-hack/"&gt;Read the whole thing&lt;/a&gt;, will ya?!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-2970360127824786963?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/IpDoEF_OtTWAqXUZIN_SJ-qWX4k/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IpDoEF_OtTWAqXUZIN_SJ-qWX4k/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/IpDoEF_OtTWAqXUZIN_SJ-qWX4k/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IpDoEF_OtTWAqXUZIN_SJ-qWX4k/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Q7_fEAZfDeU:5TuBTF3A0bg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Q7_fEAZfDeU:5TuBTF3A0bg:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Q7_fEAZfDeU:5TuBTF3A0bg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/Q7_fEAZfDeU" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/2970360127824786963?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/2970360127824786963?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/Q7_fEAZfDeU/must-read-on-walmart-intrusion.html" title="MUST Read on Walmart Intrusion" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/must-read-on-walmart-intrusion.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0IEQX84fyp7ImA9WxNWFE4.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-5980304604198639176</id><published>2009-10-13T05:05:00.000-07:00</published><updated>2009-10-13T05:05:00.137-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-13T05:05:00.137-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="evangelism" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="vendors" /><category scheme="http://www.blogger.com/atom/ns#" term="PCI" /><title>More On Security Vendors and PCI DSS</title><content type="html">&lt;div style="margin: 1em; width: 250px; display: block; float: right" class="zemanta-img" jquery1255371026953="104513"&gt;&lt;a href="http://www.flickr.com/photos/93453114@N00/2906633775"&gt;&lt;img style="border-bottom: medium none; border-left: medium none; display: block; border-top: medium none; border-right: medium none" alt="Information Security Wordle: PCI Data Security..." src="http://farm4.static.flickr.com/3244/2906633775_632e28d3e0_m.jpg" width="240" height="158" /&gt;&lt;/a&gt;    &lt;p style="font-size: 0.8em" class="zemanta-img-attribution"&gt;Image by &lt;a href="http://www.flickr.com/photos/93453114@N00/2906633775"&gt;purpleslog&lt;/a&gt; via Flickr&lt;/p&gt; &lt;/div&gt;  &lt;p&gt;This is a forced follow-up to my “&lt;a href="http://chuvakin.blogspot.com/2009/09/top-pci-dss-security-marketing.html"&gt;Top PCI DSS Security Marketing Annoyances&lt;/a&gt;” post. What forced this is that a lot of folks are googling for &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=pci-dss+market+analysis&amp;amp;aq=f&amp;amp;oq=&amp;amp;aqi="&gt;“pci-dss market analysis”&lt;/a&gt;&amp;#160; (&lt;strong&gt;double&lt;/strong&gt; laugh, if you &lt;a href="http://chuvakin.blogspot.com/2009/09/top-pci-dss-security-marketing.html"&gt;read my previous post&lt;/a&gt;)!&lt;/p&gt;  &lt;p&gt;So, let’s analyze this a bit: what creates such tidal wave of PCI security marketing stupidity is a mindset of some vendors. They keep thinking “how to sell our shit using PCI?” and not “how to help organizations with PCI challenges?” This is what drives people to buy encryption instead of not storing the data, to deploy IDS sensors with alerts going to &lt;em&gt;/dev/null&lt;/em&gt;, to scan web sites and never fix them, etc.&lt;/p&gt;  &lt;p&gt;It is not uncommon for a security vendor to review a report that says that “only 6% of companies under &lt;a href="http://chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; use a technology X mentioned in the standard” (and that said vendor happens to produce) and then think “Wow, those merchants are stupid! They really should buy out shit NOW!”&amp;#160; A quick question to merchants reading this: do you guys like it? :-)&lt;/p&gt;  &lt;p&gt;The answer is obviously “NO!” You probably want said vendor to actually understand your problems with PCI DSS and then offer, well, SOLUTIONS! It is very hard for some vendor to shift to that helpful mode if they keep obsessing about the following: “Problems? What do you mean “what problems we solve?” – out bottom-line is our problem! ‘&lt;strong&gt;PCI-says-YOU-MUST-BUY!’&lt;/strong&gt;” :-(&amp;#160; &lt;/p&gt;  &lt;p&gt;Yes, PCI DSS does mandate the use of many security technologies and it is prudent to mention that fact, whether you are vendor looking to help others or an end user looking to gain management support. Admittedly, I’ve long called PCI our sledgehammer of both awareness and budget for information security. But you can build a house with a hammer or .. you know how this metaphor goes :-) PCI DSS has a lot of energy to motivate people to improve security, please help them do just that!&lt;/p&gt;  &lt;p&gt;But what if a merchant’s only perceived challenge is to “make QSA go away and take his PCI thing with it?” Obviously, the other side of the coin is merchants buying something (like a Dell box with the the label “FIREWALL” taped on [source &lt;a href="http://www.mail-archive.com/funsec@linuxbox.org/msg10057.html"&gt;here&lt;/a&gt;]) just to fake validation. This is where you as a vendor must evangelize! As &lt;a href="http://blog.guykawasaki.com/marketing_sales_and_evangelism/"&gt;Guy would explain&lt;/a&gt;, “evangelism” is not the same as “shouting the loudest” or “lying the vilest,” it is educating and then eventually converting the customer base to your way of thinking, which also happen to be the most useful one &lt;em&gt;for them&lt;/em&gt; as well…&lt;/p&gt;  &lt;p&gt;Finally, if you did get here after googling for “&lt;em&gt;pci-dss market analysis&lt;/em&gt;,” please keep in mind:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Payment card security standard is called “PCI DSS”, not “PCI-DSS.” &lt;/li&gt;    &lt;li&gt;There is no such thing as “PCI market” so there is nothing to “analyze”; PCI is not for sale :-)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;h5&gt;&lt;a href="http://chuvakin.blogspot.com/2009/09/top-pci-dss-security-marketing.html"&gt;Top PCI DSS Security Marketing Annoyances&lt;/a&gt;&lt;/h5&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;div style="margin-top: 10px; height: 15px" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/46e85537-555a-47c6-9902-89011d164ee6/"&gt;&lt;img style="border-bottom-style: none; border-right-style: none; border-top-style: none; float: right; border-left-style: none" class="zemanta-pixie-img" alt="Reblog this post [with Zemanta]" src="http://img.zemanta.com/reblog_e.png?x-id=46e85537-555a-47c6-9902-89011d164ee6" /&gt;&lt;/a&gt;&lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-5980304604198639176?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/RJHxYOpaICFEY0QJIV4uuP27EbM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RJHxYOpaICFEY0QJIV4uuP27EbM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/RJHxYOpaICFEY0QJIV4uuP27EbM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RJHxYOpaICFEY0QJIV4uuP27EbM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=sN_DMX6MWY8:kfQFsrweEMY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=sN_DMX6MWY8:kfQFsrweEMY:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=sN_DMX6MWY8:kfQFsrweEMY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/sN_DMX6MWY8" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/5980304604198639176?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/5980304604198639176?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/sN_DMX6MWY8/more-on-security-vendors-and-pci-dss.html" title="More On Security Vendors and PCI DSS" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/more-on-security-vendors-and-pci-dss.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C08HSHs-fSp7ImA9WxNWE0s.&quot;"><id>tag:blogger.com,1999:blog-19553129.post-514224491206171136</id><published>2009-10-12T08:37:00.001-07:00</published><updated>2009-10-12T08:37:19.555-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-12T08:37:19.555-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="log management" /><category scheme="http://www.blogger.com/atom/ns#" term="logs" /><category scheme="http://www.blogger.com/atom/ns#" term="security management" /><category scheme="http://www.blogger.com/atom/ns#" term="logging" /><category scheme="http://www.blogger.com/atom/ns#" term="incident" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="presentation" /><title>Another Old Presentation: FIRST 2006 Logs and Incident Response</title><content type="html">&lt;p&gt;I am releasing &lt;a href="http://www.slideshare.net/anton_chuvakin/first-2006-fullday-tutorial-on-logs-for-incident-response"&gt;another one&lt;/a&gt; of my old &lt;a href="http://chuvakin.blogspot.com/search/label/presentation"&gt;presentations&lt;/a&gt; that I don't plan to reuse in whole: “&lt;a href="http://www.slideshare.net/anton_chuvakin/first-2006-fullday-tutorial-on-logs-for-incident-response"&gt;Log Data Analysis for Incident Response&lt;/a&gt;.” &lt;/p&gt;  &lt;p&gt;It was presented at &lt;a href="http://www.first.org/conference/2006/"&gt;FIRST Conference in 2006 in Baltimore, MD&lt;/a&gt; as a half-day tutorial.&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;div style="width:425px;text-align:left" id="__ss_2137050"&gt;&lt;a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin/first-2006-fullday-tutorial-on-logs-for-incident-response" title="FIRST 2006 Full-day Tutorial on Logs for Incident Response"&gt;FIRST 2006 Full-day Tutorial on Logs for Incident Response&lt;/a&gt;&lt;object style="margin:0px" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=first2006presologsincidentpublic-091006011213-phpapp01&amp;amp;stripped_title=first-2006-fullday-tutorial-on-logs-for-incident-response" /&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowScriptAccess" value="always" /&gt;&lt;embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=first2006presologsincidentpublic-091006011213-phpapp01&amp;amp;stripped_title=first-2006-fullday-tutorial-on-logs-for-incident-response" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;"&gt;View more &lt;a style="text-decoration:underline;" href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a style="text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin"&gt;Anton Chuvakin&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;  &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-514224491206171136?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/sWQuXCgCTFzdvL8ghiZacZvRZkY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/sWQuXCgCTFzdvL8ghiZacZvRZkY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/sWQuXCgCTFzdvL8ghiZacZvRZkY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/sWQuXCgCTFzdvL8ghiZacZvRZkY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=HAbI7a8bT8U:8-1IC52hQ2w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=HAbI7a8bT8U:8-1IC52hQ2w:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=HAbI7a8bT8U:8-1IC52hQ2w:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/HAbI7a8bT8U" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/514224491206171136?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/19553129/posts/default/514224491206171136?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/HAbI7a8bT8U/another-old-presentation-first-2006.html" title="Another Old Presentation: FIRST 2006 Logs and Incident Response" /><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="03448526107335281630" /></author><feedburner:origLink>http://chuvakin.blogspot.com/2009/10/another-old-presentation-first-2006.html</feedburner:origLink></entry><entry><title type="text">Links for 2009-10-02 [del.icio.us]</title><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/YIyhdJ-Ssqc/anton18" /><updated>2009-10-03T00:00:00-07:00</updated><id>http://del.icio.us/anton18#2009-10-02</id><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.boston.com/news/health/blog/2009/10/ig_nobels_hold.html"&gt;Ig Nobels mix serious and silly science tonight - White Coat Notes - Boston.com&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/YIyhdJ-Ssqc" height="1" width="1"/&gt;</content><feedburner:origLink>http://del.icio.us/anton18#2009-10-02</feedburner:origLink></entry><entry><title type="text">Links for 2009-09-30 [del.icio.us]</title><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/Xj1JdwdMxFk/anton18" /><updated>2009-10-01T00:00:00-07:00</updated><id>http://del.icio.us/anton18#2009-09-30</id><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;a href="http://sanjose.bizjournals.com/sanjose/stories/2009/09/28/daily9.html"&gt;Barracuda Networks takes controlling interest in phion - Silicon Valley / San Jose Business Journal:&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/Xj1JdwdMxFk" height="1" width="1"/&gt;</content><feedburner:origLink>http://del.icio.us/anton18#2009-09-30</feedburner:origLink></entry><entry><title type="text">Links for 2009-09-27 [del.icio.us]</title><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/coiACHic7cI/anton18" /><updated>2009-09-28T00:00:00-07:00</updated><id>http://del.icio.us/anton18#2009-09-27</id><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.emergentchaos.com/archives/2008/02/computer_capers_and_progr.html"&gt;Emergent Chaos: Computer Capers and Progress - Little change in 30 (!) years in security?:-)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/coiACHic7cI" height="1" width="1"/&gt;</content><feedburner:origLink>http://del.icio.us/anton18#2009-09-27</feedburner:origLink></entry></feed>
