<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Dr Anton Chuvakin Blog PERSONAL Blog</title><link>http://chuvakin.blogspot.com/</link><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/AntonChuvakinPersonalBlog" /><description>This is my PERSONAL blog, as as of August 1, 2011, it focuses on personal matters and various things I find to be fun.</description><language>en</language><managingEditor>noreply@blogger.com (Dr Anton Chuvakin)</managingEditor><lastBuildDate>Tue, 07 Feb 2012 00:00:00 PST</lastBuildDate><generator>Blogger http://www.blogger.com</generator><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1595</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">25</openSearch:itemsPerPage><feedburner:info uri="antonchuvakinpersonalblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><media:copyright>(C) Anton Chuvakin and Andrew Hay</media:copyright><media:thumbnail url="http://www.chuvakin.org/images/lovelogs.jpg" /><media:keywords>logs,log,management,log,analysis,SIEM,SEM,SIM,security,information,security,infosec</media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology</media:category><itunes:owner><itunes:email>anton@chuvakin.org</itunes:email><itunes:name>Anton Chuvakin</itunes:name></itunes:owner><itunes:author>Anton Chuvakin</itunes:author><itunes:explicit>no</itunes:explicit><itunes:image href="http://www.chuvakin.org/images/lovelogs.jpg" /><itunes:keywords>logs,log,management,log,analysis,SIEM,SEM,SIM,security,information,security,infosec</itunes:keywords><itunes:subtitle>LogChat: Andrew Hay and Anton Chuvakin talk about logging, log management and related topics</itunes:subtitle><itunes:summary>LogChat: Andrew Hay and Anton Chuvakin talk about system logging, log management, SIEM and related topics</itunes:summary><itunes:category text="Technology" /><feedburner:emailServiceId>AntonChuvakinPersonalBlog</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><title>Links for 2012-02-06 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/FhVEfp0lGdQ/anton18</link><pubDate>Tue, 07 Feb 2012 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2012-02-06</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/rob-addy/2012/02/06/prediction-provides-questions-not-answers/"&gt;Prediction Provides Questions; Not Answers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/FhVEfp0lGdQ" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2012-02-06</feedburner:origLink></item><item><title>Links for 2012-02-04 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/7ZwEv7Xa_fc/anton18</link><pubDate>Sun, 05 Feb 2012 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2012-02-04</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.infosecisland.com/blogview/19919-The-Valley-of-Death-Between-IT-and-Security.html"&gt;The Valley of Death Between IT and Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/7ZwEv7Xa_fc" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2012-02-04</feedburner:origLink></item><item><title>Monthly Blog Round-Up – January 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/7wfztbLYkpo/monthly-blog-round-up-january-2012.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Wed, 01 Feb 2012 14:37:25 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-5561808584679202970</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist below (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;)  &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top – the checklist is still a very useful tool for many people  &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/08/updated-with-community-feedback-sans_06.html"&gt;Updated With Community Feedback SANS Top 7 Essential Log Reports DRAFT2&lt;/a&gt;”, “&lt;a href="http://chuvakin.blogspot.com/2010/07/sans-top-5-essential-log-reports-update.html"&gt;SANS Top 5 Essential Log Reports Update!&lt;/a&gt;” and their predecessor&amp;nbsp; &lt;a href="http://chuvakin.blogspot.com/2010/07/sans-top-5-essential-log-reports-update.html"&gt;“Top5 SANS Log Reports Update DRAFT”&lt;/a&gt; also show up close to the top. &lt;b&gt;&lt;i&gt;IF YOU WANT TO VOLUNTEER TO&amp;nbsp;FINISH&amp;nbsp;THIS DOCUMENT- PLEASE EMAIL ME!&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular.  &lt;/li&gt;
&lt;li&gt;My classic PCI DSS log review series is last on my Top 5: “&lt;a href="http://chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;Complete PCI DSS Log Review Procedures&lt;/a&gt;.”&lt;/li&gt;
&lt;/ol&gt;
In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;:&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;“&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/01/21/cloud-security-monitoring-for-iaas-paas-saas/"&gt;Cloud Security Monitoring for IaaS, PaaS, SaaS&lt;/a&gt;”&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/01/14/more-on-security-monitoring-of-public-cloud-assets/"&gt;More On Security Monitoring of Public Cloud Assets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/01/09/cloud-security-monitoring/"&gt;Cloud Security Monitoring!&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;. &lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I&amp;nbsp;&lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt;&amp;nbsp;on Aug 1, 2011 and is solely my personal view&amp;nbsp;&lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go&amp;nbsp;&lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/01/monthly-blog-round-up-december-2011.html"&gt;Monthly Blog Round-Up – December 2011&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-5561808584679202970?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/6ZHq4YLrtk7vCDIoHXpY-qJsa18/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6ZHq4YLrtk7vCDIoHXpY-qJsa18/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/6ZHq4YLrtk7vCDIoHXpY-qJsa18/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6ZHq4YLrtk7vCDIoHXpY-qJsa18/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=7wfztbLYkpo:uYpx2ozj7Es:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=7wfztbLYkpo:uYpx2ozj7Es:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=7wfztbLYkpo:uYpx2ozj7Es:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/7wfztbLYkpo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-02-01T14:37:25.015-08:00</app:edited><georss:featurename xmlns:georss="http://www.georss.org/georss">Fremont, CA, USA</georss:featurename><georss:point xmlns:georss="http://www.georss.org/georss">37.5482697 -121.9885719</georss:point><georss:box xmlns:georss="http://www.georss.org/georss">37.447555699999995 -122.1465004 37.6489837 -121.8306434</georss:box><feedburner:origLink>http://chuvakin.blogspot.com/2012/02/monthly-blog-round-up-january-2012.html</feedburner:origLink></item><item><title>Links for 2012-01-25 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/ZnOmvY-P3jY/anton18</link><pubDate>Thu, 26 Jan 2012 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2012-01-25</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://techcrunch.com/2012/01/25/finally-someone-makes-shit-silicon-valley-says/"&gt;Someone Finally Makes &amp;ldquo;Shit Silicon Valley Says&amp;rdquo;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/ZnOmvY-P3jY" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2012-01-25</feedburner:origLink></item><item><title>Links for 2012-01-12 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/GFp_NTiW_Ag/anton18</link><pubDate>Fri, 13 Jan 2012 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2012-01-12</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="https://overhack.wordpress.com/2011/12/14/hunting-trips-network-traffic-log-analysis/"&gt;Hunting trips: network traffic log analysis | Overhack&lt;/a&gt;&lt;br/&gt;
First, and most importantly, always keep in mind that we’re only identifying anomalies, not automatically classifying “bad” traffic.&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/GFp_NTiW_Ag" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2012-01-12</feedburner:origLink></item><item><title>Links for 2012-01-11 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/HLYoyP3YLyI/anton18</link><pubDate>Thu, 12 Jan 2012 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2012-01-11</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://paulsparrows.wordpress.com/2012/01/08/browsing-security-predictions-for-2012/"&gt;Browsing Security Predictions for 2012 &amp;laquo; Il Blog di Paolo Passeri&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.wired.com/threatlevel/2012/01/pci-lawsuit/"&gt;Rare Legal Fight Takes On Credit Card Company Security Standards and Fines&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/HLYoyP3YLyI" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2012-01-11</feedburner:origLink></item><item><title>Links for 2012-01-09 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/HToC2wVEooM/anton18</link><pubDate>Tue, 10 Jan 2012 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2012-01-09</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://nakedsecurity.sophos.com/2012/01/09/paybacks-are-hell-parental-spying-prompts-infiltration-of-german-police-system/"&gt;Paybacks are hell: Parental spying prompts infiltration of German police system&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/HToC2wVEooM" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2012-01-09</feedburner:origLink></item><item><title>Annual Blog Round-Up – 2011</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/EY1xyV27Klk/annual-blog-round-up-2011.html</link><category>Annual</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Wed, 04 Jan 2012 11:11:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7780016146015454659</guid><description>&lt;p&gt;Here is my &lt;strong&gt;annual &lt;a href="http://chuvakin.blogspot.com"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 10 popular posts/topics in 2011. This list covers the posts most popular in 2011, not necessarily only those written in 2011.&lt;/p&gt; &lt;p&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;/font&gt;&lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;&lt;font color="#ff0000"&gt;joined Gartner&lt;/font&gt;&lt;/a&gt;&lt;font color="#ff0000"&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;/font&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;&lt;font color="#ff0000"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;font color="#ff0000"&gt;.&lt;/font&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” was again the most popular this year. The checklist, a list of critical things to look for while reviewing&amp;nbsp; system, network and security logs when responding to a security incident &lt;/li&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review series&lt;/a&gt; of posts take the #2 spot; they are about planning and executing PCI DSS-driven log review at an organization&lt;/li&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is another &lt;em&gt;perma-popular&lt;/em&gt; post, presenting a companion resource to the log checklist above&lt;/li&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular. &lt;/li&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is pretty much what it is. How to do log management under extreme budget AND time constraints? &lt;/li&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” is an &lt;em&gt;EXAMPLE&lt;/em&gt; criteria list for choosing a SIEM.&lt;/li&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/03/siem-resourcing-or-how-much-friggin.html"&gt;SIEM Resourcing or How Much the Friggin’ Thing Would REALLY Cost Me?&lt;/a&gt;” is a quick approach of planning SIEM costs&lt;/li&gt; &lt;li&gt;A humorous post “&lt;a href="http://chuvakin.blogspot.com/2011/01/top-10-things-your-log-management.html"&gt;Top 10 Things Your Log Management Vendor Won't Tell You&lt;/a&gt;”&lt;/li&gt; &lt;li&gt;2009 post called “&lt;a href="http://chuvakin.blogspot.com/2009/12/log-management-siem.html"&gt;Log Management + SIEM = ?&lt;/a&gt;” gives some quick architecture advice on combining SIEM and log management&lt;/li&gt; &lt;li&gt;Finally, “&lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;The Last Blog Post!&lt;/a&gt;” also made the top 10 list – it announced my departure from consulting (and blogging) in order to join Gartner.&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-7780016146015454659?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/e4hmWTIxSiGb4ZyM3rjIAemA7Xg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e4hmWTIxSiGb4ZyM3rjIAemA7Xg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/e4hmWTIxSiGb4ZyM3rjIAemA7Xg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e4hmWTIxSiGb4ZyM3rjIAemA7Xg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=EY1xyV27Klk:noCzM2cypE0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=EY1xyV27Klk:noCzM2cypE0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=EY1xyV27Klk:noCzM2cypE0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/EY1xyV27Klk" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-04T11:11:00.252-08:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html</feedburner:origLink></item><item><title>Links for 2012-01-03 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/ouzbZy3u_zI/anton18</link><pubDate>Wed, 04 Jan 2012 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2012-01-03</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://erratasec.blogspot.com/2012/01/predictions-for-2012.html"&gt;Errata Security: Predictions for 2012&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blog.logrhythm.com/uncategorized/top-2012-predictions/"&gt;Top 2012 Predictions | the dialog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.mcafee.com/enterprise/security-connected/10-security-predictions-for-2012-top-trends-2"&gt;10 Security Predictions for 2012: Top Trends | Blog Central&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.computerweekly.com/blogs/david_lacey/2011/12/six_security_forecasts_for_201.html"&gt;Six security forecasts for 2012 - David Lacey's IT Security Blog&lt;/a&gt;&lt;br/&gt;
"Social networks get secure" &lt;- get me some of the stuff he is inhaling!&lt;/li&gt;
&lt;li&gt;&lt;a href="http://threatpost.com/en_us/blogs/slideshow-five-security-predicitions-2012-122711"&gt;Slideshow: Five Security Predictions for 2012 | threatpost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://research.zscaler.com/2011/12/2012-security-predictions.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+zscaler%2Fresearch+%28Zscaler+Research%29"&gt;Zscaler Research: 2012 Security Predictions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blog.fortinet.com/2012-threat-predictions/"&gt;2012 Threat Predictions | Fortinet Security Blog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blog.damballa.com/?p=1461"&gt;2012 Security Predictions &amp;laquo; The Day Before Zero&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blog.imperva.com/2011/12/top-cyber-security-trends-for-2012-1.html"&gt;Top Cyber Security Trends for 2012: #1 - Imperva Data Security Blog&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/ouzbZy3u_zI" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2012-01-03</feedburner:origLink></item><item><title>Monthly Blog Round-Up – December 2011</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/9yGByODEf7Y/monthly-blog-round-up-december-2011.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Tue, 03 Jan 2012 08:59:21 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-921205082117636029</guid><description>&lt;p&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month.  &lt;p&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.  &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist below (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;)  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top; it is the case this month – the checklist is still a very useful tool for many people  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is pretty much what it is. How to do log management under extreme budget AND time constraints? &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” is an &lt;em&gt;EXAMPLE&lt;/em&gt; criteria list for choosing a SIEM. &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;In addition, I’d like to draw your attention to a few posts from my Gartner blog:&lt;/p&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://blogs.gartner.com/anton-chuvakin/2011/10/06/on-vulnerability-prioritization-and-scoring/"&gt;On Vulnerability Prioritization and Scoring&lt;/a&gt;”  &lt;li&gt;“&lt;a href="http://blogs.gartner.com/anton-chuvakin/2011/10/31/on-large-scale-vulnerability-management/"&gt;On LARGE Scale Vulnerability Management&lt;/a&gt;”  &lt;li&gt;“&lt;a href="http://blogs.gartner.com/anton-chuvakin/2011/10/17/on-scanning-new-environments/"&gt;On Scanning “New” Environments&lt;/a&gt;”&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;. &lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/12/monthly-blog-round-up-november-2011.html"&gt;Monthly Blog Round-Up – November 2011&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-921205082117636029?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/GOF5GLu6YCYL5-OD2SnQv-AAf-4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GOF5GLu6YCYL5-OD2SnQv-AAf-4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/GOF5GLu6YCYL5-OD2SnQv-AAf-4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GOF5GLu6YCYL5-OD2SnQv-AAf-4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=9yGByODEf7Y:NR9saFM8dw4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=9yGByODEf7Y:NR9saFM8dw4:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=9yGByODEf7Y:NR9saFM8dw4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/9yGByODEf7Y" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-03T08:59:21.730-08:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/01/monthly-blog-round-up-december-2011.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – November 2011</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/8Pl6Jr45tk8/monthly-blog-round-up-november-2011.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Thu, 01 Dec 2011 07:36:33 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-1092736118062278683</guid><description>&lt;p&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month.  &lt;p&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.  &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist below (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;)  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top; it is the case this month – the checklist is still a very useful tool for many people  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” is an &lt;em&gt;EXAMPLE&lt;/em&gt; criteria list for choosing a SIEM.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is pretty much what it is. How to do log management under extreme budget AND time constraints?&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;In addition, I’d like to draw your attention to a few fun posts from my new Gartner blog:&lt;/p&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://blogs.gartner.com/anton-chuvakin/2011/10/06/on-vulnerability-prioritization-and-scoring/"&gt;On Vulnerability Prioritization and Scoring&lt;/a&gt;”  &lt;li&gt;“&lt;a href="http://blogs.gartner.com/anton-chuvakin/2011/10/31/on-large-scale-vulnerability-management/"&gt;On LARGE Scale Vulnerability Management&lt;/a&gt;”  &lt;li&gt;“&lt;a href="http://blogs.gartner.com/anton-chuvakin/2011/10/17/on-scanning-new-environments/"&gt;On Scanning “New” Environments&lt;/a&gt;”&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;. &lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/11/monthly-blog-round-up-october-2011.html"&gt;Monthly Blog Round-Up – October 2011&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-1092736118062278683?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/oB49IAmJCpmVP3XulodAp_kHpNw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oB49IAmJCpmVP3XulodAp_kHpNw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/oB49IAmJCpmVP3XulodAp_kHpNw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oB49IAmJCpmVP3XulodAp_kHpNw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=8Pl6Jr45tk8:UM7lcquwx1g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=8Pl6Jr45tk8:UM7lcquwx1g:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=8Pl6Jr45tk8:UM7lcquwx1g:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/8Pl6Jr45tk8" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-01T07:36:33.753-08:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/12/monthly-blog-round-up-november-2011.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – October 2011</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/aC31d-g-Xoo/monthly-blog-round-up-october-2011.html</link><category>blogging</category><category>security</category><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Tue, 01 Nov 2011 07:49:24 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-420403096031896983</guid><description>&lt;p&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month.  &lt;p&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.  &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top; it is the case this month – the checklist is still a very useful tool for many people &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the above checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;)  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” is an &lt;em&gt;EXAMPLE&lt;/em&gt; criteria list for choosing a SIEM.&amp;nbsp; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is pretty much what it is. How to do log management under extreme budget AND time constraints?&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;In addition, I’d like to draw your attention to a few fun posts from my new Gartner blog:&lt;/p&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://blogs.gartner.com/anton-chuvakin/2011/10/06/on-vulnerability-prioritization-and-scoring/"&gt;On Vulnerability Prioritization and Scoring&lt;/a&gt;”&lt;/li&gt; &lt;li&gt;“&lt;a href="http://blogs.gartner.com/anton-chuvakin/2011/10/31/on-large-scale-vulnerability-management/"&gt;On LARGE Scale Vulnerability Management&lt;/a&gt;”&lt;/li&gt; &lt;li&gt;“&lt;a href="http://blogs.gartner.com/anton-chuvakin/2011/10/17/on-scanning-new-environments/"&gt;On Scanning “New” Environments&lt;/a&gt;”&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;. &lt;/p&gt; &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-420403096031896983?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/vjtQcGMqDj4SLXybwvHSyOsErIc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vjtQcGMqDj4SLXybwvHSyOsErIc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/vjtQcGMqDj4SLXybwvHSyOsErIc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vjtQcGMqDj4SLXybwvHSyOsErIc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=aC31d-g-Xoo:_KfRX6oa_fQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=aC31d-g-Xoo:_KfRX6oa_fQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=aC31d-g-Xoo:_KfRX6oa_fQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/aC31d-g-Xoo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-01T07:49:24.774-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/11/monthly-blog-round-up-october-2011.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – September 2011</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/joRyLNrD2gs/monthly-blog-round-up-september-2011.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 03 Oct 2011 10:35:59 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-2039419756928955903</guid><description>&lt;p&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month.  &lt;p&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;. &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top; it is the case this month &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is pretty much what it is. How to do log management under extreme budget AND time constraints?  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” is an &lt;em&gt;EXAMPLE&lt;/em&gt; criteria list for choosing a SIEM.&amp;nbsp; &lt;li&gt; “&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the above checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;) &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;The Last Blog Post!&lt;/a&gt;” is still popular. It announces my departure from &lt;a href="http://www.securitywarriorconsulting.com/"&gt;consulting business&lt;/a&gt; in order to join Gartner as a Research Director with &lt;a href="http://srmsblog.burtongroup.com/"&gt;IT1 SRMS team&lt;/a&gt;.&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – 2006, &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;. &lt;/p&gt; &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-2039419756928955903?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Bkj0x7AoyoBWO-xOUX17c0tLi6g/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Bkj0x7AoyoBWO-xOUX17c0tLi6g/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Bkj0x7AoyoBWO-xOUX17c0tLi6g/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Bkj0x7AoyoBWO-xOUX17c0tLi6g/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=joRyLNrD2gs:jYVHrFTy6gM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=joRyLNrD2gs:jYVHrFTy6gM:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=joRyLNrD2gs:jYVHrFTy6gM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/joRyLNrD2gs" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-03T10:35:59.008-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/10/monthly-blog-round-up-september-2011.html</feedburner:origLink></item><item><title>Cloud HELP NEEDED: Cloud PCI Class Trainer(s)!</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/uKOOrMmULSM/cloud-help-needed-cloud-pci-class.html</link><category>compliance</category><category>PCI</category><category>consulting</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Fri, 23 Sep 2011 10:20:06 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7204195116540798918</guid><description>&lt;p&gt;&lt;strong&gt;Are proficient in &lt;u&gt;&lt;em&gt;BOTH&lt;/em&gt;&lt;/u&gt; PCI DSS compliance and cloud computing security?&lt;/strong&gt; If yes, you can help &lt;a href="https://cloudsecurityalliance.org/education/training/"&gt;Cloud Security Alliance&lt;/a&gt; as well as build your security reputation &lt;strong&gt;AND&lt;/strong&gt; make some money in the process!&lt;/p&gt; &lt;p&gt;Here is how: a few months ago, when I was still &lt;a href="www.securitywarriorconsulting.com"&gt;consulting&lt;/a&gt;, I have created a comprehensive full-day class on PCI DSS and cloud computing. More information is &lt;a href="http://chuvakin.blogspot.com/2011/05/pci-dss-in-cloud-computing.html"&gt;here&lt;/a&gt; and a brief description is pasted below:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;“The first ever class dedicated to assessing and implementing PCI DSS controls in cloud computing environments covers how to think of and how to do PCI DSS in various cloud computing environments. Focused primarily on people familiar with PCI DSS, it starts from the “hype-free” cloud computing facts and then delves into &lt;strong&gt;key scenarios where PCI DSS and clouds overlap in the real world&lt;/strong&gt;. You will learn where to look while assessing such environments and what pitfalls and mistakes to avoid. It will also cover the shared responsibility between service providers and merchants in implementing PCI DSS controls. Specifically, we will discuss how PCI DSS Requirement 12.8 applies to various cloud scenarios.&lt;/p&gt; &lt;p&gt;The class would be most useful to PCI DSS QSA, organizations offering PCI DSS consulting as well as merchants planning or implementing PCI compliance.”&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;At this point, I am unable to teach the class due to my employment. CSA is looking for instructors to teach this class in various locations. &lt;p&gt;Please contact me &lt;a href="mailto:anton@chuvakin.org"&gt;offline&lt;/a&gt; and then will share the current class materials privately as well as explain what this work entails (and connect you to the right people at CSA). &lt;p&gt;Finally, if you are only &lt;em&gt;CURIOUS&lt;/em&gt; about PCI and/or cloud, please save the time you'd otherwise spend typing an e-mail to me….&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-7204195116540798918?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/trCATOYOgk2ogdPyq5caRIQ-uZc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/trCATOYOgk2ogdPyq5caRIQ-uZc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/trCATOYOgk2ogdPyq5caRIQ-uZc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/trCATOYOgk2ogdPyq5caRIQ-uZc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=uKOOrMmULSM:pp69Cgzt3Tk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=uKOOrMmULSM:pp69Cgzt3Tk:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=uKOOrMmULSM:pp69Cgzt3Tk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/uKOOrMmULSM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-23T10:20:06.332-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/09/cloud-help-needed-cloud-pci-class.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – August 2011</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/PTxwr73HsE8/monthly-blog-round-up-august-2011.html</link><category>SIEM</category><category>security management</category><category>security</category><category>SEM</category><category>Monthly</category><category>SIM</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Sat, 03 Sep 2011 11:51:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-6434107984218387106</guid><description>&lt;p&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month.  &lt;p&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I joined Gartner on Aug 1, 2011 and is solely my personal view at the time of writing.  &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;The Last Blog Post!&lt;/a&gt;” is obviously BY FAR the most popular post in August. It announces my departure from &lt;a href="http://www.securitywarriorconsulting.com/"&gt;consulting business&lt;/a&gt; in order to join Gartner as a Research Director with SRMS team. &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” is an EXAMPLE criteria list for choosing a SIEM.&amp;nbsp; Also see “&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” which is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular. &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/on-siem-services.html"&gt;On SIEM Services&lt;/a&gt;” is a quick overview of services that you really should be getting with that SIEM purchase &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is pretty much what it is. How to do log management under extreme budget AND time constraints? &lt;li&gt;A very old post (2009), “&lt;a href="http://chuvakin.blogspot.com/2009/12/log-management-siem.html"&gt;Log Management + SIEM = ?&lt;/a&gt;", is about architecting SIEM together with log management.&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual “Top Posts”&lt;/a&gt; - &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;). &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-6434107984218387106?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/I77nuTbGUgwsb7ziKJyrC_oG9rQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/I77nuTbGUgwsb7ziKJyrC_oG9rQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/I77nuTbGUgwsb7ziKJyrC_oG9rQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/I77nuTbGUgwsb7ziKJyrC_oG9rQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=PTxwr73HsE8:LzeQBR-C22I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=PTxwr73HsE8:LzeQBR-C22I:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=PTxwr73HsE8:LzeQBR-C22I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/PTxwr73HsE8" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-03T11:51:00.521-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/09/monthly-blog-round-up-august-2011.html</feedburner:origLink></item><item><title>Quick Blogging Update</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/zEhwhtGr2eE/quick-blogging-update.html</link><category>personal</category><category>news</category><category>blogging</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Wed, 31 Aug 2011 08:18:40 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-5742233605474352579</guid><description>&lt;p&gt;As I mentioned, due to my &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joining Gartner&lt;/a&gt;, I am not blogging on security here anymore. However, a quick announcement is in order:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;You can follow what I am reading at &lt;a href="http://www.google.com/reader/shared/anton.chuvakin"&gt;http://www.google.com/reader/shared/anton.chuvakin&lt;/a&gt; (&lt;a href="http://www.google.com/reader/public/atom/user%2F01602743592290730660%2Fstate%2Fcom.google%2Fbroadcast"&gt;RSS&lt;/a&gt;, &lt;a href="https://plus.google.com/104051623244958334514/buzz"&gt;Google Reader Likes&lt;/a&gt;) and &lt;a href="http://www.delicious.com/anton18"&gt;http://www.delicious.com/anton18&lt;/a&gt; (&lt;a href="http://feeds.delicious.com/v2/rss/anton18?count=15"&gt;RSS&lt;/a&gt;)&lt;/li&gt; &lt;li&gt;My &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;Gartner blog is almost ready&lt;/a&gt; (there are no posts yet, but feel free to subscribe anyway – &lt;a href="http://blogs.gartner.com/anton-chuvakin/feed/"&gt;RSS&lt;/a&gt;)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-5742233605474352579?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/NjsZSltt-KJQS47ED8JdJxKXpdI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NjsZSltt-KJQS47ED8JdJxKXpdI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/NjsZSltt-KJQS47ED8JdJxKXpdI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NjsZSltt-KJQS47ED8JdJxKXpdI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zEhwhtGr2eE:hrNVbKC12XI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zEhwhtGr2eE:hrNVbKC12XI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zEhwhtGr2eE:hrNVbKC12XI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/zEhwhtGr2eE" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-31T08:18:40.526-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/08/quick-blogging-update.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – July 2011</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/iL6Ev4vSWKQ/monthly-blog-round-up-july-2011.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Fri, 02 Sep 2011 11:45:14 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-2014949510046469916</guid><description>&lt;p&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month.  &lt;p&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I joined Gartner on Aug 1, 2011 and is solely my personal view at the time of writing. &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is pretty much what it is. How to do log management under extreme budget AND time constraints &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/06/pci-dss-in-cloud-by-council.html"&gt;PCI DSS in the Cloud … By the Council&lt;/a&gt;” post is my quick review of recent &lt;a href="http://chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; guidance on virtualization, focusing on cloud computing guidance.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” is an EXAMPLE criteria list for choosing a SIEM.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular. A related read is “&lt;a href="http://chuvakin.blogspot.com/2011/03/siem-resourcing-or-how-much-friggin.html"&gt;SIEM Resourcing or How Much the Friggin’ Thing Would REALLY Cost Me?&lt;/a&gt;”, check it out as well. While reading this, also check &lt;a href="http://www.slideshare.net/anton_chuvakin/something-fun-about-using-siem-by-dr-anton-chuvakin"&gt;this presentation&lt;/a&gt;.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is still one of the most popular posts on my blog. Grab the log review checklist &lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;here&lt;/a&gt;, if you have not done so already. It is perfect to hand out to junior sysadmins who are just starting up with logs. A related “&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;UPDATED Free Log Management Tools&lt;/a&gt;” is also still on top - it is a repost of &lt;a href="http://www.securitywarriorconsulting.com/logtools"&gt;my free log tools list&lt;/a&gt; to the blog. &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual “Top Posts”&lt;/a&gt; - &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;).   &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-2014949510046469916?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/RW5g-3tWX2fAj3PLCBsnn9w32c4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RW5g-3tWX2fAj3PLCBsnn9w32c4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/RW5g-3tWX2fAj3PLCBsnn9w32c4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RW5g-3tWX2fAj3PLCBsnn9w32c4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=iL6Ev4vSWKQ:_TvX7DqLDAU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=iL6Ev4vSWKQ:_TvX7DqLDAU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=iL6Ev4vSWKQ:_TvX7DqLDAU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/iL6Ev4vSWKQ" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-02T11:45:14.417-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/08/monthly-blog-round-up-july-2011.html</feedburner:origLink></item><item><title>The Last Blog Post!</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/CMF-iJhJBOg/last-blog-post.html</link><category>Gartner</category><category>personal</category><category>news</category><category>jobs</category><category>career</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Sun, 31 Jul 2011 23:59:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-6117883024746815483</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
This is my last blog post –for the foreseeable future. It is dated 7/31/2011 at 11:59PM. What happens tomorrow? A new life, of course! &lt;br /&gt;
&lt;br /&gt;
As only very few of you know, I have accepted a position of &lt;strong&gt;Research Director&lt;/strong&gt; with &lt;strong&gt;Gartner, Inc&lt;/strong&gt;. Tomorrow I am joining a stellar team lead by &lt;a href="http://www.linkedin.com/pub/phil-schacter/9/b8/41b"&gt;Phil Schacter&lt;/a&gt;, formerly from &lt;a href="http://www.burtongroup.com/"&gt;Burton Group&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
I spent two VERY successful years &lt;a href="http://www.securitywarriorconsulting.com/"&gt;consulting&lt;/a&gt;, working with companies like Novell, RSA, LogLogic, NitroSecurity, eGestalt, ObserveIT, Tripwire, AlienVault, “Big MSSP”, “Big Insurance Company”, “SaaS Log Management Company”, “IT Management Software Company”, “SMB Security Company”, “Big Networking Equipment Company”&amp;nbsp; and others. I defined,&amp;nbsp; built, deployed, and marketed security products, mostly in the area of &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/log%20management"&gt;log management&lt;/a&gt;. I helped organizations with security and &lt;a href="http://chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; strategy. I advised security vendor management on compliance strategy for their products. I have spoken at clients’ events and have written more whitepapers than I care to admit… as well as did a lot of other fun things!&lt;br /&gt;
&lt;br /&gt;
It was fun and I loved it - and as my clients can attest, I was good at it. Also, I was more busy than I thought I’d be, and occasionally more than I wanted to be. However, at some point I started to feel that I need another step up. And so I am making that step now!&lt;br /&gt;
&lt;br /&gt;
In accordance with my future employer policy, I have resigned from the Advisory Boards of &lt;a href="http://www.dasient.com/"&gt;Dasient&lt;/a&gt;, &lt;a href="http://www.securonix.com/"&gt;Securonix&lt;/a&gt;, &lt;a href="http://www.nextiernetworks.com/"&gt;nexTier Networks&lt;/a&gt;, &lt;a href="http://www.savantprotection.com/en/index.php"&gt;Savant Protection&lt;/a&gt;, &lt;a href="http://www.egestalt.com/"&gt;eGestalt&lt;/a&gt;, and &lt;a href="http://www.rapid.io/"&gt;Rapid.IO&lt;/a&gt;. Good luck to all of you!&lt;br /&gt;
&lt;br /&gt;
In all likelihood, I will eventually resurface at &lt;a href="http://blogs.gartner.com/"&gt;Gartner blogs&lt;/a&gt; – please look for me there.&amp;nbsp; And finally, those who love my personal blogging (all &lt;strong&gt;4007 &lt;/strong&gt;of you as of today), don’t despair – I will still occasionally blog here on non-infosec subjects: think good books, laser weapons, hypnosis, skiing, travel and my other weird hobbies &lt;img alt="Smile" class="wlEmoticon wlEmoticon-smile" src="http://lh4.ggpht.com/-5NLcbUu4QmU/TjI45X7YgdI/AAAAAAAAQQU/DAJ5Tj7THqU/wlEmoticon-smile2.png?imgmax=800" style="border-bottom-style: none; border-left-style: none; border-right-style: none; border-top-style: none;" /&gt;&lt;br /&gt;
&lt;br /&gt;
Finally, I want to give very special thanks to &lt;a href="http://www.ljkushner.com/"&gt;Lee Kushner&lt;/a&gt; for his &lt;strong&gt;super&lt;/strong&gt;-&lt;strong&gt;valuable&lt;/strong&gt; career counseling that helped me make this difficult career choice.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Possibly related posts – my past “career decisions” blog posts:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/leaving-vendorland-or-consulting-full.html"&gt;Going to Consulting&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2008/10/qualys.html"&gt;Going to Qualys&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2006/03/logblog-log-guru-joins-loglogic.html"&gt;Going to LogLogic&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-6117883024746815483?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/-Rp0yWdME82M2Q0o016rxT44EbQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-Rp0yWdME82M2Q0o016rxT44EbQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/-Rp0yWdME82M2Q0o016rxT44EbQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-Rp0yWdME82M2Q0o016rxT44EbQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=CMF-iJhJBOg:cAI6c9NjDcs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=CMF-iJhJBOg:cAI6c9NjDcs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=CMF-iJhJBOg:cAI6c9NjDcs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/CMF-iJhJBOg" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-31T23:59:00.437-07:00</app:edited><media:thumbnail url="http://lh4.ggpht.com/-5NLcbUu4QmU/TjI45X7YgdI/AAAAAAAAQQU/DAJ5Tj7THqU/s72-c/wlEmoticon-smile2.png?imgmax=800" height="72" width="72" /><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/last-blog-post.html</feedburner:origLink></item><item><title>On SIEM Services</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/Pjc675Fgw_A/on-siem-services.html</link><category>SIEM</category><category>log management</category><category>logs</category><category>security management</category><category>logging</category><category>security</category><category>SEM</category><category>SIM</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Sun, 31 Jul 2011 11:11:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-3246938790914257701</guid><description>&lt;p&gt;&lt;strong&gt;Executive summary&lt;/strong&gt;: you need to procure services when you buy a &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; tool, if you don’t – you’d be sorry later.&lt;/p&gt;  &lt;p&gt;Even if you are amazingly intelligent and have extensive SIEM experience – see above.&amp;#160; Even if you saw a successful SIEM project that didn’t include vendor or 3rd party services with your very eyes – see above. Even if your SIEM vendor tells you “you don’t need services” – see above.&lt;strong&gt; See above! See above!! See above!!! &lt;img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://lh3.ggpht.com/-aO13wTxY_80/TjJrd4SRHhI/AAAAAAAAQQo/Z01g8jZf_vI/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" /&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-vAeQ4Pm1poM/TjJrhYC3G9I/AAAAAAAAQQs/p0xpV6MS3DQ/s1600-h/image%25255B2%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 3px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" align="right" src="http://lh6.ggpht.com/-m6wGdFjqIaU/TjJrmFxr2gI/AAAAAAAAQQw/jrh9vyvZyIY/image_thumb.png?imgmax=800" width="244" height="188" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Let’s analyze this “SIEM services paradox.” A lot of organizations – way too many, in fact – balk at the need to procure related services before, during and after their SIEM purchase. The thinking often goes like this: we need a SIEM and this box &amp;lt;points at the appliance still in the box&amp;gt; is a SIEM. That’s all we need. What services? Why services? Huh?&lt;/p&gt;  &lt;p&gt;In reality -&amp;#160; and this is what I sometimes call “secret to SIEM magic” – that box is not a SIEM. That box, when racked and connected to your network, is STILL not quite a SIEM. Only when you “operationalize” it (see picture), then you can say that you have Security Information and Event Management (SIEM) capability in your organization and that you do “real-time” security monitoring.&lt;/p&gt;  &lt;p&gt;Now, be honest, do you know how to deploy a SIEM tool and then figure out the shortest path to its operational success? Probably not… thus services/consultants who will work WITH you to make it a reality by arriving at the best possible way of benefitting from SIEM in your environment. Which use case give you the best bang for the SIEM buck? Which one will show a “quick win” to your management? Which one is more likely to detect an attacker in your network?&lt;/p&gt;  &lt;p&gt;When a SIEM vendor tries to sell you services, it is NOT vendor greed – but simply common sense. And if you say “no”, it is not “saving money” – but being stupid. SIEM success&amp;#160; out-of-the-box (while real, in some cases!) is a pale shadow of what a well-thought through deployment looks like! My [broken] analogy is: you buying a nice shiny Aston Martin and then only using it to commute to a train station 1 mile from home. Will it work? Yes. Is this a good investment and a good experience? Hell&amp;#160; no!&lt;/p&gt;  &lt;p&gt;So, no, SIEM is NOT useless without services, but it is unlikely to reach its full potential. &lt;a href="http://www.slideshare.net/anton_chuvakin/something-fun-about-using-siem-by-dr-anton-chuvakin"&gt;Pitfalls to SIEM success are many&lt;/a&gt;, and navigating them requires help.&lt;/p&gt;  &lt;p&gt;And, no, outsiders alone cannot do it. You will need &lt;strong&gt;to help them&amp;#160; help you&lt;/strong&gt;.&lt;/p&gt;  &lt;p&gt;This also leads to the rise of managed or co-managed SIEM options (which are NOT MSSPs, BTW!) as more people realize that a) they need a SIEM and b) they cannot handle a SIEM. Future &lt;a href="http://chuvakin.blogspot.com/2009/10/open-source-cloud-siem-anybody.html"&gt;cloud SIEM&lt;/a&gt; will (when it emerges) try to tackle the same problem of being simpler to operate and thus simpler to operationalize.&lt;/p&gt;  &lt;p&gt;Today, most SIEM vendors offer an extensive menu of services to go with a product, and there are also &lt;a href="http://www.thevigilant.com/security_monitoring_lifecycle_services"&gt;some smart third parties&lt;/a&gt;.&amp;#160; Many services around SIEM can be organized as follows.&lt;/p&gt;  &lt;p&gt;Pre-sale services examples:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Product selection help &lt;/li&gt;    &lt;li&gt;Vendor differentiation analysis and shortlist definition &lt;/li&gt;    &lt;li&gt;Regulation analysis and business cases review &lt;/li&gt;    &lt;li&gt;Product strengths/weaknesses analysis &lt;/li&gt;    &lt;li&gt;Product fit for type of project &lt;/li&gt;    &lt;li&gt;Product fit for vertical / business type&lt;/li&gt;    &lt;li&gt;RFP definition assistance &lt;/li&gt;    &lt;li&gt;Current tools vs requirements gap analysis &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Services offered during SIEM acquisition and deployment:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;SIEM implementation &lt;/li&gt;    &lt;li&gt;SIEM project planning &lt;/li&gt;    &lt;li&gt;Proof-of-concept deployment management &lt;/li&gt;    &lt;li&gt;Product testing in production environment &lt;/li&gt;    &lt;li&gt;Data source integration and collection architecture&lt;/li&gt;    &lt;li&gt;Default contents tuning &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Post-sale, operational services:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;SIEM analyst training &lt;/li&gt;    &lt;li&gt;Performance tuning and capacity planning&lt;/li&gt;    &lt;li&gt;SIEM project management &lt;/li&gt;    &lt;li&gt;Custom content creation &lt;/li&gt;    &lt;li&gt;Custom device integration&lt;/li&gt;    &lt;li&gt;SOC building &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Vendors and consulting firms offer other types of services as well all the way up to “co-managed SIEM” where a 3&lt;sup&gt;rd&lt;/sup&gt; party firm manages your SIEM deployment for you. Will future SIEM work better out of the box? Yes, I think so. Will SIEM ever be as simple as a firewall? No, never: it is inherent complexity of security monitoring that cannot be squeezed out even by creative engineering…&lt;/p&gt;  &lt;p&gt;Enjoy ... &lt;em&gt;as this was my final blog post on SIEM&lt;/em&gt;.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts on SIEM:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;On Broken SIEM Deployments &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/06/algorithmic-siem-correlation-is-back.html"&gt;Algorithmic SIEM &amp;quot;Correlation&amp;quot; Is Back?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/06/how-do-i-get-best-siem.html"&gt;How Do I Get The Best SIEM?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/05/log-management-graduation-criteria.html"&gt;Log Management-&amp;gt;SIEM Graduation Criteria: Violate at Your Own Peril!&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/05/how-to-replace-siem.html"&gt;How to Replace a SIEM?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/03/siem-resourcing-or-how-much-friggin.html"&gt;SIEM Resourcing or How Much the Friggin’ Thing Would REALLY Cost Me?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/11/how-to-write-ok-siem-rfp.html"&gt;How to Write an OK SIEM RFP?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/10/so-what-should-i-want-or-how-not-to.html"&gt;&amp;quot;So, What Should I Want?&amp;quot; or How NOT to Pick a SIEM-III?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/03/myth-of-siem-as-analyst-in-box-or-how.html"&gt;The Myth of SIEM as &amp;quot;An Analyst-in-the-box&amp;quot; or How NOT to Pick a SIEM-II?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/01/i-want-to-buy-correlation-or-how-not-to.html"&gt;I Want to Buy Correlation” or How NOT to Pick a SIEM?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/12/log-management-siem.html"&gt;Log Management + SIEM = ?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/on-siem-complexity.html"&gt;On SIEM Complexity&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;SIEM Bloggables&lt;/a&gt;: &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; Use Cases and &lt;a href="http://chuvakin.blogspot.com/2010/08/new-siem-whitepaper-on-use-cases-in.html"&gt;Whitepaper with detailed SIEM use cases&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/03/log-management-siem-users-minimalist-vs.html"&gt;Log Management / SIEM Users: &amp;quot;Minimalist&amp;quot; vs &amp;quot;Analyst&amp;quot;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;All posts labeled SIEM&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-3246938790914257701?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/reL7d-RMuXXmS6p2Xvq3vkvPVQ0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/reL7d-RMuXXmS6p2Xvq3vkvPVQ0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/reL7d-RMuXXmS6p2Xvq3vkvPVQ0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/reL7d-RMuXXmS6p2Xvq3vkvPVQ0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Pjc675Fgw_A:1KVYiVv4jnQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Pjc675Fgw_A:1KVYiVv4jnQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Pjc675Fgw_A:1KVYiVv4jnQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/Pjc675Fgw_A" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-31T11:11:00.129-07:00</app:edited><media:thumbnail url="http://lh3.ggpht.com/-aO13wTxY_80/TjJrd4SRHhI/AAAAAAAAQQo/Z01g8jZf_vI/s72-c/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" height="72" width="72" /><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/on-siem-services.html</feedburner:origLink></item><item><title>Old Content Posted: Presentations, Documents, etc</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/zeoUrUZlURI/old-content-posted-presentations.html</link><category>personal</category><category>news</category><category>paper</category><category>chuvakin</category><category>presentation</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Sat, 30 Jul 2011 23:11:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-1910315367394597394</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;In preparation for a career change (stand by for an announcement on midnight July 31, 2011), I am posting A LOT of my old presentations and documents online for the community.&lt;br /&gt;
&lt;br /&gt;
See &lt;a href="http://www.slideshare.net/anton_chuvakin/presentations"&gt;http://www.slideshare.net/anton_chuvakin/presentations&lt;/a&gt; for such gems as my &lt;a href="http://www.slideshare.net/anton_chuvakin/security-chasm-hitb-2010-keynote-by-dr-anton-chuvakin"&gt;HITB 2010 keynote “Security Chasm”&lt;/a&gt;,&amp;nbsp; &lt;a href="http://www.slideshare.net/anton_chuvakin/siem-primer"&gt;Brief SIEM Primer&lt;/a&gt;, &lt;a href="http://www.slideshare.net/anton_chuvakin/making-log-data-useful-siem-and-log-management-together-by-dr-anton-chuvakin"&gt;“Making Log Data Useful”&lt;/a&gt;&amp;nbsp;as well as the most recent "&lt;a href="http://www.slideshare.net/anton_chuvakin/five-best-and-five-worst-practices-for-siem-by-dr-anton-chuvakin-8721331"&gt;Five Best and Five Worst SIEM Practices&lt;/a&gt;"&lt;br /&gt;
&lt;br /&gt;
See &lt;a href="http://www.docstoc.com/profile/anton1chuvakin"&gt;http://www.docstoc.com/profile/anton1chuvakin&lt;/a&gt; for a bunch of older documents on security, logging, &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; – including such gems as &lt;a href="http://www.docstoc.com/docs/87103550/LoggingHaiku_2005"&gt;Logging Haiku&lt;/a&gt;,&amp;nbsp; &lt;a href="http://www.docstoc.com/docs/87103451/firewall-logging-paper"&gt;firewall logging primer&lt;/a&gt;, etc&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-1910315367394597394?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/2G2DjaNRfyqOozbKs0sy7dqVeDc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2G2DjaNRfyqOozbKs0sy7dqVeDc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/2G2DjaNRfyqOozbKs0sy7dqVeDc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2G2DjaNRfyqOozbKs0sy7dqVeDc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zeoUrUZlURI:Vm_-hLIi1dk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zeoUrUZlURI:Vm_-hLIi1dk:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zeoUrUZlURI:Vm_-hLIi1dk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/zeoUrUZlURI" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-30T23:11:00.140-07:00</app:edited><georss:featurename xmlns:georss="http://www.georss.org/georss">San Francisco, CA, USA</georss:featurename><georss:point xmlns:georss="http://www.georss.org/georss">37.7749295 -122.41941550000001</georss:point><georss:box xmlns:georss="http://www.georss.org/georss">37.7206295 -122.50881550000001 37.8292295 -122.33001550000002</georss:box><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/old-content-posted-presentations.html</feedburner:origLink></item><item><title>On Broken SIEM Deployments</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/T7CNZsqTqWs/on-broken-siem-deployments.html</link><category>SIEM</category><category>log management</category><category>logs</category><category>security management</category><category>security</category><category>SEM</category><category>SIM</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Fri, 29 Jul 2011 11:23:01 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-2602615485063724210</guid><description>&lt;p&gt;Imagine you own a broken, dilapidated, failing &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt;&amp;#160;&lt;strike&gt;crap&lt;/strike&gt; deployment. What? &lt;em&gt;Really… that, like, never happens, dude! SIEM is what makes unicorns shine and be happy all the time, right?&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Well…mmm… no comment. In this post, I want to address one common&amp;#160; &lt;a href="http://www.slideshare.net/anton_chuvakin/something-fun-about-using-siem-by-dr-anton-chuvakin"&gt;#FAIL scenario&lt;/a&gt;: a SIEM that is failing because it was deployed with a goal of real-time security monitoring, all the while the company was nowhere near ready (not mature enough) to have any monitoring process and operations (&lt;a href="http://chuvakin.blogspot.com/2011/05/log-management-graduation-criteria.html"&gt;criteria for it&lt;/a&gt;).&amp;#160; On my log/SIEM maturity scale (presented &lt;a href="http://chuvakin.blogspot.com/2010/02/logging-log-management-and-log-review.html"&gt;here&lt;/a&gt;, also see &lt;a href="http://raffy.ch/blog/2010/06/07/maturity-scale-for-log-management-and-analysis/"&gt;this related post&lt;/a&gt; from Raffy), they are either in the ignorance phase or maybe log collection phase.&lt;/p&gt;  &lt;p&gt;And herein lies the problem: if you deployed one of the legacy, born in the 1990s SIEMs that are not based on a solid &lt;a href="http://chuvakin.blogspot.com/search/label/log%20management"&gt;log management&lt;/a&gt; platform, the tool will actually suck at the very fundamental level: log collection. The specific issue here is that most of these early tools were designed to only &lt;em&gt;selectively&lt;/em&gt; collect what was deemed necessary for real-time security monitoring (vs all log data). In essence, you have a tool with monitoring features (that you don’t use) and with weak collection features (that you can use, but they are weak).&lt;/p&gt;  &lt;p&gt;What to do? You have these options:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;strong&gt;Leave it to rot&lt;/strong&gt;; you can always keep it just to boast to your friends (and PCI QSAs) that “&lt;em&gt;ye own one of ‘em olde SIEMs&lt;/em&gt;” &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Blow it away &lt;/strong&gt;and join the “&lt;em&gt;SIEM doesn’t work&lt;/em&gt;” crowd – and maybe buy a &lt;a href="http://www.splunk.com/"&gt;simple&lt;/a&gt; &lt;a href="http://www.loglogic.com"&gt;log&lt;/a&gt; management tool later &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Deploy a log management tool to &lt;a href="http://chuvakin.blogspot.com/2009/12/log-management-siem.html"&gt;“undergird” your crappy SIEM&lt;/a&gt;&lt;/strong&gt;; you have a choice of buying from the same SIEM vendor (if they have it) or a different vendor &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Built your own log management layer&lt;/strong&gt; on syslog and open source tools &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;I have seen people take either of the above four. Personally, I have seen much more success with the option #3 (buy log management) and not infrequently with #4 (built log management) – BTW, &lt;a href="http://www.slideshare.net/anton_chuvakin/choosing-your-log-management-approach-buy-build-or-outsource"&gt;this deck&lt;/a&gt; might help you choose. You want to move your SIEM setup from “get some logs – ignore all logs” model to “collect all/more logs – review some logs” which is typically much more aligned with your level of maturity. And then grow and solve more problems with your SIEM and demonstrate “quick wins.” While you are at it, review some architecture choices discussed &lt;a href="http://chuvakin.blogspot.com/2009/12/log-management-siem.html"&gt;here&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Enjoy &lt;em&gt;…while it lasts.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts on SIEM:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/06/algorithmic-siem-correlation-is-back.html"&gt;Algorithmic SIEM &amp;quot;Correlation&amp;quot; Is Back?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/06/how-do-i-get-best-siem.html"&gt;How Do I Get The Best SIEM?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/05/log-management-graduation-criteria.html"&gt;Log Management-&amp;gt;SIEM Graduation Criteria: Violate at Your Own Peril!&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/05/how-to-replace-siem.html"&gt;How to Replace a SIEM?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/03/siem-resourcing-or-how-much-friggin.html"&gt;SIEM Resourcing or How Much the Friggin’ Thing Would REALLY Cost Me?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/11/how-to-write-ok-siem-rfp.html"&gt;How to Write an OK SIEM RFP?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/10/so-what-should-i-want-or-how-not-to.html"&gt;&amp;quot;So, What Should I Want?&amp;quot; or How NOT to Pick a SIEM-III?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/03/myth-of-siem-as-analyst-in-box-or-how.html"&gt;The Myth of SIEM as &amp;quot;An Analyst-in-the-box&amp;quot; or How NOT to Pick a SIEM-II?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/01/i-want-to-buy-correlation-or-how-not-to.html"&gt;I Want to Buy Correlation” or How NOT to Pick a SIEM?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/12/log-management-siem.html"&gt;Log Management + SIEM = ?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/on-siem-complexity.html"&gt;On SIEM Complexity&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;SIEM Bloggables&lt;/a&gt;: &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; Use Cases and &lt;a href="http://chuvakin.blogspot.com/2010/08/new-siem-whitepaper-on-use-cases-in.html"&gt;Whitepaper with detailed SIEM use cases&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/03/log-management-siem-users-minimalist-vs.html"&gt;Log Management / SIEM Users: &amp;quot;Minimalist&amp;quot; vs &amp;quot;Analyst&amp;quot;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;All posts labeled SIEM&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-2602615485063724210?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/WbChC8VFamhraGNiFoaQkwQJK2o/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/WbChC8VFamhraGNiFoaQkwQJK2o/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/WbChC8VFamhraGNiFoaQkwQJK2o/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/WbChC8VFamhraGNiFoaQkwQJK2o/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=T7CNZsqTqWs:ndyymmtpTpA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=T7CNZsqTqWs:ndyymmtpTpA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=T7CNZsqTqWs:ndyymmtpTpA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/T7CNZsqTqWs" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-29T11:23:01.907-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/on-broken-siem-deployments.html</feedburner:origLink></item><item><title>Got A Pile of Logs from an Incident: What to Do?</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/KCYL4gOyY7g/got-pile-of-logs-from-incident-what-to.html</link><category>log management</category><category>logs</category><category>incident response</category><category>security</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Wed, 27 Jul 2011 21:28:31 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-4663785211662026881</guid><description>&lt;p&gt;As I am going through my backlog of topics I wanted to blog about (but didn’t have time for the last 4-6 months), this is the one I really wanted to explore. Here is the scenario:&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/--6Y7eM2LxIA/TjDlJ5couUI/AAAAAAAAQPo/GptLr0k-R2g/s1600-h/image2.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" align="right" src="http://lh5.ggpht.com/-wZYSznCMavM/TjDlP7ul4NI/AAAAAAAAQPs/MtfU8vQ5vp8/image_thumb.png?imgmax=800" width="244" height="182" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Something blows up, hits the fan, starts to smell bad, &amp;lt;insert your favorite incident metaphor&amp;gt; … either in your IT environment or at one of your clients’ &lt;/li&gt;
&lt;li&gt;Logs (mostly) and other evidence is taken from all the components of the affected system and packaged for offline analysis &lt;/li&gt;
&lt;li&gt;You get a nice 10MB-10GB pile of juicy log data – and they wants “&lt;strong&gt;answers&lt;/strong&gt;” &lt;/li&gt;
&lt;li&gt;What do you do FIRST? With what tools? &lt;/li&gt;
&lt;/ol&gt;&lt;p&gt;Let’s explore this situation. I know most of you would say “&lt;strong&gt;just pile’em into splunk&lt;/strong&gt;”&amp;#160; and, of course, I will do that. However, that is not a full story. As I point out in this 2007 blog post (“&lt;a href="http://chuvakin.blogspot.com/2007/03/do-you-enjoy-searching.html"&gt;Do You Enjoy Searching?&lt;/a&gt;”), to succeed with search you need to know what to search for. At this point of our incident investigation, we actually don’t! Meanwhile, the volume of log data beyond a few megabytes makes “trial and error” approach of searching for common clues fairly ineffective. &lt;/p&gt;&lt;p&gt;If you received any hints with the log pile (“I think the user ‘&lt;em&gt;jsmith&lt;/em&gt;’ did it” or “it seems&amp;#160; like &lt;em&gt;10.1.3.2&lt;/em&gt; IP was involved”), then you can search for this (and then branch out to co-occurring and related issues and drill-down as needed), but then your investigation will suffer from “tunnel vision” of only seeing this initially reported issue and that is, obviously, a bad idea.&lt;/p&gt;&lt;p&gt;Let’s take a step back and think: &lt;strong&gt;what do we want here? what is our problem?&lt;/strong&gt;&amp;#160; We want a way to &lt;strong&gt;explore&lt;/strong&gt; &lt;strong&gt;ALL the logs in&amp;#160; a pile, across log types, across devices, across all time AND then also following a timeline of events&lt;/strong&gt;. In other words, we ain’t in “searchland” here, buddy… &lt;/p&gt;&lt;p&gt;If you have an enterprise &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; sitting around (and one with well-engineered support for diverse historical log imports – which is NOT a certainty, BTW), you should definitely load the logs there as well. I like this approach since you can then run cross-device summary reports over the entire set, slice the set in various ways (type of log source, log source instance, type of log entry – categorized, time period filter, time trend, etc) and data visualization tools (treemaps, trend lines, link maps, and other advanced visuals on parsed, normalized and categorized) help get a big picture view of our pile.&lt;/p&gt;&lt;p&gt;Looking at the &lt;a href="http://www.securitywarriorconsulting.com/logtools/"&gt;open source log tools&lt;/a&gt;, does anything look promising for the task? &lt;a href="http://alienvault.com/community"&gt;OSSIM&lt;/a&gt; can do the trick (even though their historical log import is not my favorite), but nothing else does. In some cases, I used &lt;a href="http://www.sawmill.net/"&gt;sawmill&lt;/a&gt; (free trial) for my “big picture first look”, but it is not cross-device and only shows reports for each log type individually. If I were feeling really adventurous (and was on hourly billing), I could actually send all the logs via a syslog streamer into &lt;a href="http://www.ossec.net/"&gt;OSSEC&lt;/a&gt; (in order to see the log entries the tool will flag as interesting/alertable), but this is not really something I’d enjoy doing. I am almost tempted to say that you can use something like &lt;a href="http://afterglow.sourceforge.net/"&gt;afterglow&lt;/a&gt;, but it relies on parsed data that you’d sill need to cook somehow (such as again using a SIEM). &lt;a href="http://www.log2timeline.net/"&gt;Log2timeline&lt;/a&gt; is useful, but only for one dimension – and the one that splunk actually addresses pretty well already.&lt;/p&gt;&lt;p&gt;To generalize, &lt;strong&gt;you need (a) a search tool and (b) an exploration tool&lt;/strong&gt;. The search tool should help you quickly answer SPECIFIC questions. The exploration tool should use data to generate “hints” on WHAT questions you should start asking…&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-4663785211662026881?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/0ctoJCVS7yAAT8KdDf_IfhqEPB0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0ctoJCVS7yAAT8KdDf_IfhqEPB0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/0ctoJCVS7yAAT8KdDf_IfhqEPB0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0ctoJCVS7yAAT8KdDf_IfhqEPB0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=KCYL4gOyY7g:Ur6eBKd9C0o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=KCYL4gOyY7g:Ur6eBKd9C0o:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=KCYL4gOyY7g:Ur6eBKd9C0o:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/KCYL4gOyY7g" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-27T21:28:31.904-07:00</app:edited><media:thumbnail url="http://lh5.ggpht.com/-wZYSznCMavM/TjDlP7ul4NI/AAAAAAAAQPs/MtfU8vQ5vp8/s72-c/image_thumb.png?imgmax=800" height="72" width="72" /><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/got-pile-of-logs-from-incident-what-to.html</feedburner:origLink></item><item><title>Top 10 Criteria for a SIEM?</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/DTXFcnDdQEw/top-10-criteria-for-siem.html</link><category>SIEM</category><category>security management</category><category>security</category><category>SEM</category><category>SIM</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Wed, 27 Jul 2011 11:11:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-2850617601150882313</guid><description>&lt;p&gt;OK, this WILL be taken the wrong way! I spent years whining about how &lt;strong&gt;use cases&lt;/strong&gt; and &lt;strong&gt;your requirements&lt;/strong&gt; should be THE MAIN thing driving your &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; purchase. And suddenly Anton shows up with a simple ‘Top 10 list’, so…. blame it &lt;u&gt;&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;on that cognac&lt;/a&gt;&lt;/u&gt;.&lt;/p&gt;  &lt;p&gt;This list is &lt;em&gt;AN EXAMPLE. SAMPLE. ILLUSTRATION&lt;/em&gt;. It is here &lt;strong&gt;FOR FUN&lt;/strong&gt;. If you use it to buy a SIEM for your organization, your girlfriend will sleep with your plumber.&amp;#160; All sorts of bad things can and likely will happen to you and/or your dog – and even your pet squirrel might go nuts. Please look up the word “EXAMPLE” in the dictionary before proceeding!&lt;/p&gt;  &lt;p&gt;On top of this, this list was built with some underlying assumptions which I am not at liberty to disclose. Think large, maybe think SOC, think complex environment, etc. Obviously,&amp;#160; an environment with its own peculiarities … just like yours.&lt;/p&gt;  &lt;p&gt;With that out of the way, Top 10 Criteria for Choosing a SIEM … EXAMPLE!&lt;/p&gt;  &lt;p&gt;1. &lt;b&gt;User interface and analyst experience&lt;/b&gt; in general: ease of performing common tasks, streamlined workflows, small number of clicks to critical functions and efficient and quick information lookups (including external information) when needed during the investigation&lt;/p&gt;  &lt;p&gt;2. &lt;b&gt;Correlation&lt;/b&gt;: correlation engine performance, ease of rule creation and modification, canned rule content, cross-device correlation based on normalized/categorized data; additional analytics methods including analysis of stored/historical log data; ability to test rules before production deployment&lt;/p&gt;  &lt;p&gt;3. &lt;b&gt;Log source coverage&lt;/b&gt;: full integration of most (better: all) needed log sources before operational deployment, detailed parsing and normalization of all fields needed for the analysts’ work; coverage of device, OS and application logs; wide use of real-time log collection methods, even at a cost of using agents&lt;/p&gt;  &lt;p&gt;4. &lt;b&gt;Dashboards and analyst views&lt;/b&gt;: availability of required analyst views, flexibility and customization, drilldown capability to see additional details, ease of modification and tuning, real-time operation (not periodic polling)&lt;/p&gt;  &lt;p&gt;5. &lt;b&gt;Reporting:&lt;/b&gt; report performance, visual clarity, ease of modification and default/canned report content, ability to create custom reports on all data in a flexible manner without knowing the SIEM product internal structures and other esoterica&lt;/p&gt;  &lt;p&gt;6. &lt;b&gt;Search and query:&lt;/b&gt; high (seconds) performance of searches and queries when investigating an incident, access to raw log data via an efficient search command, tied to the main interface&lt;/p&gt;  &lt;p&gt;7. &lt;b&gt;Escalation, shift and analyst collaboration support&lt;/b&gt;: a system to manage collaborative investigations of security issues, take notes, add details and review/approve the workflow; likely this requires an advanced case management / ticketing system to be built in&lt;/p&gt;  &lt;p&gt;8. Ability to &lt;b&gt;gradually expand storage on demand&lt;/b&gt; when the environment is growing; this applies to both parsed/normalized data storage as well as raw log storage&lt;/p&gt;  &lt;p&gt;9. &lt;b&gt;Complete log categorization and normalization&lt;/b&gt; for cross-device correlation that enables the analysts to “cross-train” and not “device-train” before using the SIEM well.&lt;/p&gt;  &lt;p&gt;10. &lt;b&gt;New log source integration technology and process:&lt;/b&gt; ability to either quickly integrate new log sources or have vendor do it promptly (days to few weeks) upon request &lt;/p&gt;  &lt;p&gt;Got any comments?&lt;/p&gt;  &lt;p&gt;If not, well, enjoy it …&lt;em&gt; while it lasts.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt; &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/06/algorithmic-siem-correlation-is-back.html"&gt;Algorithmic SIEM &amp;quot;Correlation&amp;quot; Is Back?&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/06/how-do-i-get-best-siem.html"&gt;How Do I Get The Best SIEM?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/05/log-management-graduation-criteria.html"&gt;Log Management-&amp;gt;SIEM Graduation Criteria: Violate at Your Own Peril!&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/05/how-to-replace-siem.html"&gt;How to Replace a SIEM?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/03/siem-resourcing-or-how-much-friggin.html"&gt;SIEM Resourcing or How Much the Friggin’ Thing Would REALLY Cost Me?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/11/how-to-write-ok-siem-rfp.html"&gt;How to Write an OK SIEM RFP?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/10/so-what-should-i-want-or-how-not-to.html"&gt;&amp;quot;So, What Should I Want?&amp;quot; or How NOT to Pick a SIEM-III?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/03/myth-of-siem-as-analyst-in-box-or-how.html"&gt;The Myth of SIEM as &amp;quot;An Analyst-in-the-box&amp;quot; or How NOT to Pick a SIEM-II?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/01/i-want-to-buy-correlation-or-how-not-to.html"&gt;I Want to Buy Correlation” or How NOT to Pick a SIEM?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/12/log-management-siem.html"&gt;Log Management + SIEM = ?&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/on-siem-complexity.html"&gt;On SIEM Complexity&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;SIEM Bloggables&lt;/a&gt;: &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; Use Cases and &lt;a href="http://chuvakin.blogspot.com/2010/08/new-siem-whitepaper-on-use-cases-in.html"&gt;Whitepaper with detailed SIEM use cases&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/03/log-management-siem-users-minimalist-vs.html"&gt;Log Management / SIEM Users: &amp;quot;Minimalist&amp;quot; vs &amp;quot;Analyst&amp;quot;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;All posts labeled SIEM&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;div style="margin-top: 10px; height: 15px" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"&gt;&lt;img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=91e08d2e-07e7-4192-8ab2-425ffa19bb8b" /&gt;&lt;/a&gt;&lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-2850617601150882313?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/sGwjGsZiS-pd_vTo-OzAArDvQag/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/sGwjGsZiS-pd_vTo-OzAArDvQag/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/sGwjGsZiS-pd_vTo-OzAArDvQag/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/sGwjGsZiS-pd_vTo-OzAArDvQag/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=DTXFcnDdQEw:T9IJiY1ZDHs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=DTXFcnDdQEw:T9IJiY1ZDHs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=DTXFcnDdQEw:T9IJiY1ZDHs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/DTXFcnDdQEw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-27T11:11:00.062-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html</feedburner:origLink></item><item><title>NIST EMAP Workshop–Aug 2011</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/qu27BBJ5JjM/nist-emap-workshopaug-2011.html</link><category>CEE</category><category>logs</category><category>news</category><category>standards</category><category>logging</category><category>NIST</category><category>EMAP</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Tue, 26 Jul 2011 11:11:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7544836763376172415</guid><description>&lt;p&gt;A lot of good work on logging standards as well as standards for the “surrounding areas” (correlation rules, parsing rules, etc) will happen at this &lt;a href="http://scap.nist.gov/events/index.html#emapdeveloperworkshop2011"&gt;first-ever NIST workshop on EMAP&lt;/a&gt;.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Please mark your calendars to save the date for an &lt;b&gt;EMAP Developer Workshop to be held August 29-30, 2011&lt;/b&gt; at the NIST Campus in Gaithersburg, Maryland.&amp;#160; We are still formalizing the agenda, but topics to be covered will include:&lt;u&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;    &lt;p&gt;&lt;u&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;    &lt;p&gt;&lt;u&gt;&lt;/u&gt;· &lt;u&gt;&lt;/u&gt;Discussion of target use cases and requirements as identified by EMAP working group.&lt;u&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;    &lt;p&gt;&lt;u&gt;&lt;/u&gt;· &lt;u&gt;&lt;/u&gt;CEE Overview and in-depth discussion of current issues.&lt;u&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;    &lt;p&gt;&lt;u&gt;&lt;/u&gt;· &lt;u&gt;&lt;/u&gt;Discussion of EMAP component specifications and issues/questions for the community.&lt;u&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;    &lt;p&gt;&lt;u&gt;&lt;/u&gt;· &lt;u&gt;&lt;/u&gt;Discussion of EMAP roadmap and connections with other efforts within security automation.&lt;u&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;    &lt;p&gt;&lt;u&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;    &lt;p&gt;We are in the process of standing up &lt;a href="http://scap.nist.gov/events/index.html#emapdeveloperworkshop2011"&gt;a registration page&lt;/a&gt; and creating the agenda.&amp;#160; A teleconference line will be provided for those who cannot attend in person.&amp;#160; More details to come in the near future, we hope to see you there.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;If you are dealing with logs and &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; (such as building, or even using the tools) and care about standards, please consider attending – but only if you will contribute!&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/06/nist-emap-out.html"&gt;NIST EMAP is Out&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/CEE"&gt;CEE posts&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-7544836763376172415?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/b1ugISqrZDxR987hGOUwxDX9v7M/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/b1ugISqrZDxR987hGOUwxDX9v7M/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/b1ugISqrZDxR987hGOUwxDX9v7M/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/b1ugISqrZDxR987hGOUwxDX9v7M/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=qu27BBJ5JjM:ThWvcAfBtcw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=qu27BBJ5JjM:ThWvcAfBtcw:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=qu27BBJ5JjM:ThWvcAfBtcw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/qu27BBJ5JjM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-26T11:11:00.136-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/nist-emap-workshopaug-2011.html</feedburner:origLink></item><item><title>Speaking at Catalyst 2011 in San Diego Tomorrow</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/8rc-581r5xY/speaking-at-catalyst-2011-in-san-diego.html</link><category>SIEM</category><category>security management</category><category>security</category><category>SEM</category><category>presentation</category><category>SIM</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 25 Jul 2011 23:06:25 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-2353893309146621138</guid><description>&lt;p&gt;Just FYI, I am speaking at &lt;a href="http://www.gartner.com/technology/summits/na/catalyst/"&gt;Gartner Catalyst 2011&lt;/a&gt; event in San Diego tomorrow. The topic is “&lt;a href="http://agendabuilder.gartner.com/CATUS2/WebPages/SessionDetail.aspx?EventSessionId=861"&gt;Five Best and Five Worst Practices for SIEM&lt;/a&gt;.”&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“Implementing SIEM sounds straightforward, but reality sometimes begs to differ. In this session, Dr. Anton Chuvakin will share the five best and worst practices for implementing SIEM as part of security monitoring and intelligence. Understanding how to avoid pitfalls and create a successful SIEM implementation will help maximize security and compliance value, and avoid costly obstacles, inefficiencies, and risks.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;strong&gt;Time&lt;/strong&gt;: Tuesday, 26 July 2011    &lt;br /&gt;02:45 PM to 03:20 PM&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Location&lt;/strong&gt;:&amp;#160;&amp;#160; Hilton San Diego Bayfront    &lt;br /&gt;1 Park Boulevard    &lt;br /&gt;San Diego, CA 92101&lt;/p&gt;  &lt;p&gt;If you are around, come see me &lt;a href="http://agendabuilder.gartner.com/CATUS2/WebPages/SessionList.aspx?Speaker=704707"&gt;here&lt;/a&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-2353893309146621138?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/H-wuOJfUpCRel_z2oZkki2PCWT8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/H-wuOJfUpCRel_z2oZkki2PCWT8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/H-wuOJfUpCRel_z2oZkki2PCWT8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/H-wuOJfUpCRel_z2oZkki2PCWT8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=8rc-581r5xY:E1etHWpPrDE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=8rc-581r5xY:E1etHWpPrDE:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=8rc-581r5xY:E1etHWpPrDE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/8rc-581r5xY" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-25T23:06:25.929-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/speaking-at-catalyst-2011-in-san-diego.html</feedburner:origLink></item><item><title>Log Management at $0 and 1hr/week?</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/ypZ9yie_XFw/log-management-at-0-and-1hrweek.html</link><category>SIEM</category><category>log management</category><category>logs</category><category>security management</category><category>logging</category><category>security</category><category>SEM</category><category>SIM</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 25 Jul 2011 02:09:50 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-8119721229852283325</guid><description>&lt;p&gt;As I was drinking cognac on the upper deck of a 747, flying TPE-SFO back from a client meeting, the following idea crossed my mind:&amp;#160; &lt;strong&gt;CAN one REALLY do a decent job with &lt;/strong&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/log%20management"&gt;&lt;strong&gt;log management&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; (including log review) if their budget is $0 AND their “time budget” is 1 hour/week?&lt;/strong&gt; I got asked that when I was teaching my &lt;u&gt;&lt;a href="http://www.sans.org/sec434-beta-2011/description.php?tid=4532"&gt;SANS SEC434&lt;/a&gt;&lt;/u&gt; class a few months ago and the idea stuck in my head – and now cognac, courtesy of China Airlines, helped&amp;#160; stimulate it into a full blog post.&lt;/p&gt;  &lt;p&gt;So, $0 budget points to using &lt;u&gt;&lt;a href="http://www.securitywarriorconsulting.com/logtools/"&gt;open-source,&amp;#160; free tools&lt;/a&gt;&lt;/u&gt; (duh!), but 1hr/week points in exactly the opposite direction: commercial or even outsourced model.&lt;/p&gt;  &lt;p&gt;The only &lt;em&gt;slightly plausible&lt;/em&gt; way it that I came up with is:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Spend your 1st hour building a syslog server; it can be done, especially if starting from a old Linux box that you found in the basement (at $0); don’t forget &lt;em&gt;logrotate&lt;/em&gt; or equivalent &lt;/li&gt;    &lt;li&gt;Spend a few next weeks (i.e. hours) configuring various Unix, Linux and network devices (essentially, all syslog log sources) to log to it &lt;/li&gt;    &lt;li&gt;Consider deploying Snare on a few Windows boxes (if needed); it would likely be easier to do than doing remote pull – too much tuning might be needed &lt;/li&gt;    &lt;li&gt;Next, drop a default &lt;u&gt;&lt;a href="http://www.ossec.net/"&gt;OSSEC&lt;/a&gt;&lt;/u&gt; install on your log server and – gasp! – enable all alerts &lt;/li&gt;    &lt;li&gt;Spend the next&amp;#160; few hours (in the next few weeks) turning off the ones that are too numerous, irrelevant or don’t trigger any action in your environment. &lt;/li&gt;    &lt;li&gt;If you log volume fits within a free &lt;a href="http://www.splunk.com"&gt;splunk&lt;/a&gt; license size (500MB/day), also spend an hour deploying splunk on your log server and have it index all gathered logs &lt;/li&gt;    &lt;li&gt;Now you’d be spending your “one log hour each week” on reviewing alerts and (if installed) digging in splunk for additional details &lt;/li&gt;    &lt;li&gt;Congrats! $0 and 1hr/week gave you semblance of log management and even monitoring…. &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;What do you think? It just might work for organizations with severe time AND money constraints. &lt;/p&gt;  &lt;p&gt;Enjoy the post … while it lasts.&lt;/p&gt;  &lt;p&gt;BTW, on a completely unrelated note:&amp;#160; do you think EVERY organization above a certain size &lt;strong&gt;NEEDS&lt;/strong&gt; a &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt;? Or &lt;strong&gt;WILL NEED&lt;/strong&gt; a SIEM in the future?&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-8119721229852283325?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/GK3JDlDbsaARp73Z_5jAEq6CMSo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GK3JDlDbsaARp73Z_5jAEq6CMSo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/GK3JDlDbsaARp73Z_5jAEq6CMSo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GK3JDlDbsaARp73Z_5jAEq6CMSo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=ypZ9yie_XFw:YpkqqlXl3uQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=ypZ9yie_XFw:YpkqqlXl3uQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=ypZ9yie_XFw:YpkqqlXl3uQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/ypZ9yie_XFw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-25T02:09:50.972-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html</feedburner:origLink></item><item><title>Job: Director of Product Marketing at SIEM Vendor</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/8GjxsWC8zDY/job-director-of-product-marketing-at.html</link><category>jobs</category><category>security</category><category>career</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 18 Jul 2011 10:57:31 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-4024279143285149706</guid><description>&lt;p&gt;I am posting this as a small favor to my friends at NitroSecurity.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;The Director, Product Marketing is responsible for developing, planning and executing externally-focused product marketing strategies, plans &amp;amp; programs for the industry leading NitroView SIEM, log management, database monitoring, application monitoring and IDS/IPS solution. They will research &amp;amp; understand security market trends by working with industry analysts and engaging prospects &amp;amp; customers, closely monitor &amp;amp; analyze competitor offerings and develop value propositions, product positioning and messages for enterprise and government markets worldwide. They will drive and lead all new product launch and introduction activities, and support on-going product and solution campaigns and programs. &lt;/p&gt;    &lt;p&gt;Candidates in metro Boston, metro Washington DC or open to virtual, home office arrangements are welcomed to apply to &lt;a href="mailto:jobs@nitrosecurity.com"&gt;jobs@nitrosecurity.com&lt;/a&gt;.      &lt;br /&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;Responsibilities:        &lt;br /&gt;&lt;/b&gt;      &lt;br /&gt;a. Work closely with Product Management, Engineering and Operations to fully understand current and planned technologies, products and solutions&lt;/p&gt;    &lt;p&gt;b. Conduct competitive research and provide analysis on competitive advantages &amp;amp; competitor claims relative to customer needs.&lt;/p&gt;    &lt;p&gt;c. Determine product positioning &amp;amp; product messaging and create &amp;amp; manage a broad range of product and solution collateral, on-line content, white papers, blogs &amp;amp; sales tools&lt;/p&gt;    &lt;p&gt;d. Develop and deliver new product training to field sales, systems engineers and channel partner and technology partner organizations&lt;/p&gt;    &lt;p&gt;e. Key company spokesperson, presenting to prospects, customers, partners, press and analysts in person, via webcasts and at industry conferences. &lt;/p&gt;    &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;Experience and Qualifications:&lt;/b&gt;      &lt;br /&gt;a. 10+ years of product marketing experience in security/networking assignments      &lt;br /&gt;b. 5+ years security industry experience&lt;/p&gt;    &lt;p&gt;c. Excellent speaking, writing and presentation skills      &lt;br /&gt;d. Strong analytical skills, including business, markets and competition&lt;/p&gt;    &lt;p&gt;e. Team player with proven success in high growth environments &lt;/p&gt;    &lt;p&gt;f. Technical undergraduate degree preferred or equivalent, MBA or equivalent advanced degree preferred&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Apply via: &lt;a href="mailto:jobs@nitrosecurity.com"&gt;jobs@nitrosecurity.com&lt;/a&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-4024279143285149706?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/gs0-at24p9IsMFH5wKnVrMZU9kU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gs0-at24p9IsMFH5wKnVrMZU9kU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/gs0-at24p9IsMFH5wKnVrMZU9kU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gs0-at24p9IsMFH5wKnVrMZU9kU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=8GjxsWC8zDY:Jrz34mjLJRc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=8GjxsWC8zDY:Jrz34mjLJRc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=8GjxsWC8zDY:Jrz34mjLJRc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/8GjxsWC8zDY" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-18T10:57:31.335-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/job-director-of-product-marketing-at.html</feedburner:origLink></item><item><title>PCI in the Cloud Class July 8: Location Finalized</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/aUFNG6LXXk4/pci-in-cloud-class-july-8-location.html</link><category>compliance</category><category>cloud</category><category>news</category><category>security</category><category>PCI</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 04 Jul 2011 17:57:48 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-1409380620238145992</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;Just&amp;nbsp; a quick announcements about &lt;a href="http://chuvakin.blogspot.com/2011/05/pci-dss-in-cloud-computing.html"&gt;my “PCI in the cloud” class&lt;/a&gt; that I am teaching this week.&amp;nbsp; The location has been finalized:&lt;br /&gt;
&lt;strong&gt;Location (&lt;/strong&gt;&lt;a href="http://maps.google.com/maps?q=910+Hermosa+Court+,Sunnyvale+CA&amp;amp;gl=us&amp;amp;z=16"&gt;map&lt;/a&gt;&lt;strong&gt;)&lt;/strong&gt;:&lt;br /&gt;
&lt;em&gt;Ariba Silicon Valley Office      &lt;br /&gt;
Sequoia Conference Room&lt;/em&gt;&lt;br /&gt;
&lt;em&gt;910 Hermosa Court,     &lt;br /&gt;
Sunnyvale, CA&lt;/em&gt;&lt;br /&gt;
(please use the main entrance and tell receptionist&amp;nbsp; that you are there for CSA PCI class, lunch and coffee will be provided)&lt;br /&gt;
&lt;strong&gt;Date&lt;/strong&gt;: Friday July 8, 2011 at 9AM&lt;br /&gt;
There are still, I think, 2-3 seats left at $20/seat (beta price! must provide class feedback!!), so go and register &lt;a href="http://csa-pci.eventbrite.com/"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE&lt;/b&gt;: 7/4/2011 5:50PM Sorry, sold out! I will check with the host tomorrow about the room size and there is a slight chance that we can fit more than 25 people, but it is not a certainty.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/05/pci-dss-in-cloud-computing.html"&gt;PCI DSS in Cloud Computing Environments–THE Training&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-1409380620238145992?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/mdqJAXJF1iSIJEc2HC08Q_Kjcao/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mdqJAXJF1iSIJEc2HC08Q_Kjcao/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/mdqJAXJF1iSIJEc2HC08Q_Kjcao/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mdqJAXJF1iSIJEc2HC08Q_Kjcao/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=aUFNG6LXXk4:nEUbqbdX3JU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=aUFNG6LXXk4:nEUbqbdX3JU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=aUFNG6LXXk4:nEUbqbdX3JU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/aUFNG6LXXk4" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-04T17:57:48.405-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/pci-in-cloud-class-july-8-location.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – June 2011</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/fd3U9wrEdgo/monthly-blog-round-up-june-2011.html</link><category>blogging</category><category>security</category><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Fri, 01 Jul 2011 09:36:11 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-5139083323829569155</guid><description>&lt;p&gt;Blogs are &amp;quot;stateless&amp;quot; and people often pay attention only to what they see &lt;em&gt;today&lt;/em&gt;. Thus a lot of useful security reading material gets lost. These &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly round-ups&lt;/a&gt; is my way of reminding people about interesting and useful blog content. If you are “too busy to read the blogs,” at least read &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;these&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;So, here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;&amp;quot;Security Warrior&amp;quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month.     &lt;br /&gt;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/06/pci-dss-in-cloud-by-council.html"&gt;PCI DSS in the Cloud … By the Council&lt;/a&gt;” posts is my quick review of recent &lt;a href="http://chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; guidance on virtualization, focusing on cloud computing guidance.&lt;/li&gt;    &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” tops the charts again this month. The post is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular. A related read is “&lt;a href="http://chuvakin.blogspot.com/2011/03/siem-resourcing-or-how-much-friggin.html"&gt;SIEM Resourcing or How Much the Friggin’ Thing Would REALLY Cost Me?&lt;/a&gt;”, check it out as well. While reading this, also check &lt;a href="http://www.slideshare.net/anton_chuvakin/something-fun-about-using-siem-by-dr-anton-chuvakin"&gt;this presentation&lt;/a&gt;. &lt;/li&gt;    &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is still one of the most popular posts on my blog. Grab the log review checklist &lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;here&lt;/a&gt;, if you have not done so already. It is perfect to hand out to junior sysadmins who are just starting up with logs. A related “&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;UPDATED Free Log Management Tools&lt;/a&gt;” is also still on top - it is a repost of &lt;a href="http://www.securitywarriorconsulting.com/logtools"&gt;my free log tools list&lt;/a&gt; to the blog. &lt;/li&gt;    &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/06/algorithmic-siem-correlation-is-back.html"&gt;Algorithmic SIEM “Correlation” Is Back?&lt;/a&gt;” is a post that I never thought would make it to my monthly top as it covers a bit of &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; esoterica. Surprise!&lt;/li&gt;    &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/06/nist-emap-out.html"&gt;NIST EMAP Out&lt;/a&gt;” is my quick announcement/summary of the NIST EMAP standard efforts, the log/event “brother” of SCAP and an extension of &lt;a href="http://chuvakin.blogspot.com/search/label/CEE"&gt;CEE&lt;/a&gt; work&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Also, as a tradition, I am thanking my top 3 referrers this month (those who are people, not organizations). So, thanks a lot to the following people whose blogs sent the most visitors to my blog: &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;a href="http://pciguru.wordpress.com/about/"&gt;Anonymous “PCI Guru”&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://dorlov.blogspot.com/"&gt;Dmitry Orlov&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://blog.zeltser.com"&gt;Lenny Zeltzer&lt;/a&gt;&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual “Top Posts”&lt;/a&gt; - &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;). Next, &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;see you&lt;/a&gt; in July for the next monthly top list.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Possibly related posts / past monthly popular blog round-ups:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/06/monthly-blog-round-up-may-2011.html"&gt;Monthly Blog Round-Up – May 2011&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/05/monthly-blog-round-up-april-2011.html"&gt;Monthly Blog Round-Up – April 2011&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/04/monthly-blog-round-up-march-2011.html"&gt;Monthly Blog Round-Up – March 2011&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/03/monthly-blog-round-up-february-2011.html"&gt;Monthly Blog Round-Up – February 2011&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/02/monthly-blog-round-up-january-2011.html"&gt;Monthly Blog Round-Up – January 2011&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;Previous ones&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-5139083323829569155?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/dWnv3vA3XWZM4lKPyka3tfikkzw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/dWnv3vA3XWZM4lKPyka3tfikkzw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/dWnv3vA3XWZM4lKPyka3tfikkzw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/dWnv3vA3XWZM4lKPyka3tfikkzw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=fd3U9wrEdgo:xRYl0TeE6XU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=fd3U9wrEdgo:xRYl0TeE6XU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=fd3U9wrEdgo:xRYl0TeE6XU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/fd3U9wrEdgo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-01T09:36:11.338-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2011/07/monthly-blog-round-up-june-2011.html</feedburner:origLink></item><item><title>PCI DSS in the Cloud … By the Council</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/w_S-TRSrLQo/pci-dss-in-cloud-by-council.html</link><category>security management</category><category>compliance</category><category>cloud</category><category>virtualization</category><category>security</category><category>PCI</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Thu, 16 Jun 2011 09:36:34 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-1739459455089815964</guid><description>&lt;p&gt;The long-awaited PCI Council guidance on virtualization &lt;a href="https://www.pcisecuritystandards.org/documents/Rth87Wp/Virtualization_InfoSupp_v2.pdf"&gt;has been released [PDF]&lt;/a&gt;. Congrats to the Virtualization SIG for the mammoth effort! I rather liked the document, but let the virtualization crowd (and press!) analyze it ad infinitum – I’d concentrate elsewhere: on the cloud! This guidance does not focus on cloud computing, but contains more than a few mentions, all of them pretty generic.&lt;/p&gt;  &lt;p&gt;Here are some of the highlights and my thoughts on them.&lt;/p&gt;  &lt;p&gt;Section 2.2.6 “Cloud Computing” does contain some potentially usable (if obvious) scope guidance: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“Entities planning to use cloud computing for their PCI DSS environments should&amp;#160; first ensure that they &lt;strong&gt;thoroughly understand the details of the services being offered&lt;/strong&gt;, and perform&amp;#160; a detailed assessment of the unique risks associated with each service. Additionally, as with any&amp;#160; managed service, it is crucial that the hosted entity and provider &lt;strong&gt;clearly define and document the&amp;#160; responsibilities assigned to each party for maintaining PCI DSS requirements&lt;/strong&gt; and any other&amp;#160; controls that could impact the security of cardholder data.“ [&lt;em&gt;emphasis by &lt;/em&gt;&lt;a href="http://www.chuvakin.org"&gt;&lt;em&gt;A.C.&lt;/em&gt;&lt;/a&gt;]&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Now, after spending the last few months working on &lt;a href="http://chuvakin.blogspot.com/2011/05/pci-dss-in-cloud-computing.html"&gt;a training class on PCI DSS in the cloud&lt;/a&gt; for &lt;a href="https://cloudsecurityalliance.org/education/training/"&gt;Cloud Security Alliance&lt;/a&gt; (in fact, I am still finishing the exercises for our &lt;a href="http://chuvakin.blogspot.com/2011/05/pci-dss-in-cloud-computing.html"&gt;July 8 beta run&lt;/a&gt;), the above sounds like a total no-brainer. However, I know A LOT of merchants “plan” to make the mistake of “we use PCI-OK cloud provider –&amp;gt; then we are compliant”, which is obviously completely insane (just as PA-DSS payment app does not make you PCI DSS compliant…and never did).&lt;/p&gt;  &lt;p&gt;Further, the council guidance clarifies the above with:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;”The cloud provider should &lt;strong&gt;clearly identify which PCI DSS requirements, system components, and services are covered by the cloud provider’s PCI DSS compliance program&lt;/strong&gt;. Any aspects of the&amp;#160; service &lt;strong&gt;not covered by the cloud provider should be identified, and it should be clearly&amp;#160; documented in the service agreement that these aspects, system components, and PCI DSS requirements are the responsibility of the hosted entity&lt;/strong&gt; [&lt;em&gt;aka “merchant” – A.C.&lt;/em&gt;] to manage and assess. The cloud provider       &lt;br /&gt;should provide &lt;strong&gt;sufficient evidence and assurance that all processes and components under their&amp;#160; control are PCI DSS compliant&lt;/strong&gt;.” [&lt;em&gt;emphasis in bold by &lt;/em&gt;&lt;a href="http://www.chuvakin.org"&gt;&lt;em&gt;A.C.&lt;/em&gt;&lt;/a&gt;]&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The above is actually a gem, a nicely condensed version of a pile of challenges and hard problems, all nicely summarized. Indeed, “PCI in the cloud” is largely about the above paragraph, but … there is &lt;em&gt;A LOT OF DEVIL&lt;/em&gt; in the details &lt;img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://lh6.ggpht.com/-LoR-x0jXEfU/TfoxCGIDWjI/AAAAAAAAPg4/FXLB1RUzTJ8/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" /&gt; I’d like to draw your attention to the fact that providers have to “provide sufficient evidence and assurance” as opposed to just saying “&lt;a href="http://aws.amazon.com/about-aws/whats-new/2010/12/07/aws-achieves-pci-dss-level-1-compliance/"&gt;we got PCI Level 1&lt;/a&gt;.” There is a big lesson for cloud providers in&amp;#160; it…&lt;/p&gt;  &lt;p&gt;In further sections (section 4.3, mostly), there is some additional useful guidance, such as:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“In a public cloud, some &lt;strong&gt;part of the underlying systems and infrastructure is always&amp;#160; controlled by the cloud service provider&lt;/strong&gt;. The specific components &lt;strong&gt;remaining under the control &lt;/strong&gt;&lt;a href="http://lh6.ggpht.com/-pSIkIVEagv0/TfoxD-7whjI/AAAAAAAAPg8/-TGMnsbj4ho/s1600-h/image%25255B2%25255D.png"&gt;&lt;strong&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" align="right" src="http://lh5.ggpht.com/-ELb_8aBm98g/TfoxEZzhEAI/AAAAAAAAPhA/5GcYhkVd6vk/image_thumb.png?imgmax=800" width="244" height="124" /&gt;&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;of the cloud provider will vary according to the type of service&lt;/strong&gt;—for example, Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS). […] &lt;strong&gt;Physical separation&amp;#160; between tenants is not practical in a public cloud environment because, by its very nature, all&amp;#160; resources are shared by everyone&lt;/strong&gt;.” [&lt;em&gt;emphasis by A.C. again; this reminds us that PCI does NOT in fact require such ‘physical’ separation of assets&lt;/em&gt;]&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;On top of this, the Council folks also highlight some of the additional cloud security challenges, affecting PCI DSS, such as (page 24, section 4.3):&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;“The hosted entity has limited or &lt;strong&gt;no visibility into the underlying infrastructure&lt;/strong&gt; and related security controls.&lt;/li&gt;    &lt;li&gt;“The hosted entity has no knowledge of ―who‖ they are sharing resources with, or &lt;strong&gt;the potential risks their hosted neighbors may be introducing to the host system&lt;/strong&gt;, data stores, or other resources shared across a multi-tenant environment.” [&lt;em&gt;the section in bold is kind of a hidden big deal! think about it – your payment environment may blow up since your cloud neighbor just annoyed LulzSec by something they said on Twitter…&lt;/em&gt;]&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;The guidance counters these and other challenges with additional controls:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“In a public cloud environment, &lt;strong&gt;additional controls &lt;u&gt;&lt;em&gt;must&lt;/em&gt;&lt;/u&gt; be implemented to compensate for the inherent risks and lack of visibility into the public cloud architecture&lt;/strong&gt;. A public cloud environment could, for example, host hostile out-of-scope workloads on the same virtualization infrastructure as a cardholder data environment. &lt;strong&gt;More stringent preventive, detective, and corrective controls are&lt;/strong&gt; &lt;u&gt;&lt;strong&gt;&lt;em&gt;required&lt;/em&gt;&lt;/strong&gt;&lt;/u&gt; to offset the additional risk that a public cloud, or similar environment, could introduce to an entity’s CDE.” [&lt;em&gt;notice MUST, not “may” or “should”; also notice REQUIRED and not “suggested” or “oh wow, would it be nice if…” &lt;img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://lh6.ggpht.com/-LoR-x0jXEfU/TfoxCGIDWjI/AAAAAAAAPg4/FXLB1RUzTJ8/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" /&gt;]&lt;/em&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;And if you don’t have such additional controls, then: “These challenges &lt;strong&gt;may make it impossible for some cloud-based services to operate in a PCI DSS compliant manner&lt;/strong&gt;.”&lt;/p&gt;  &lt;p&gt;In any case, it was definitely a fun and useful read; hopefully future detailed guidance on PCI in the cloud is coming (given that virtualization SIG took a few years, I am looking forward to 2017 or later here)&lt;/p&gt;  &lt;p&gt;BTW, my &lt;a href="http://chuvakin.blogspot.com/search/label/PCI"&gt;PCI DSS&lt;/a&gt; in the cloud training class will happen on July 8 in Bay Area and you &lt;a href="http://csa-pci.eventbrite.com/"&gt;can still sign up&lt;/a&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-1739459455089815964?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/br-0791daX3x2x1gICxJIMJMKSM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/br-0791daX3x2x1gICxJIMJMKSM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/br-0791daX3x2x1gICxJIMJMKSM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/br-0791daX3x2x1gICxJIMJMKSM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=w_S-TRSrLQo:XQFcq4VeW_Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=w_S-TRSrLQo:XQFcq4VeW_Y:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=w_S-TRSrLQo:XQFcq4VeW_Y:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/w_S-TRSrLQo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-16T09:36:34.111-07:00</app:edited><media:thumbnail url="http://lh6.ggpht.com/-LoR-x0jXEfU/TfoxCGIDWjI/AAAAAAAAPg4/FXLB1RUzTJ8/s72-c/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" height="72" width="72" /><feedburner:origLink>http://chuvakin.blogspot.com/2011/06/pci-dss-in-cloud-by-council.html</feedburner:origLink></item><item><title>Algorithmic SIEM “Correlation” Is Back?</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/hlAbegp7hFQ/algorithmic-siem-correlation-is-back.html</link><category>SIEM</category><category>security management</category><category>correlation</category><category>security</category><category>SEM</category><category>SIM</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Tue, 14 Jun 2011 11:11:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-802506752424086940</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;Back in 2002 when I was at a &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; vendor that shall remain nameless (at least until they finally die), I fell in love with algorithmic "correlation." Yes, I can write correlation rules like there is no tomorrow (and have fun doing it!), but that’s just me – I am funny that way. A lot of organizations today will rely on default correlation rules (hoping that SIEM is some kinda “&lt;em&gt;improved host IDS&lt;/em&gt;” of yesteryear … remember &lt;a href="http://www.intrusion-detection-system-group.co.uk/dragon.htm"&gt;those&lt;/a&gt;?) and then quickly realize that logs are too darn diverse across environments to make such naïve pattern matching useful for many situations. Other organizations will just start hating SIEM in general for all the false default rule alerts and fall back in the rathole of log search aka “we can figure out what happened in days , not months” mindset.&lt;br /&gt;
&lt;br /&gt;
That problem becomes even more dramatic especially when they try to use mostly simple filtering rules (&lt;em&gt;IF username=root AND ToD&amp;gt;10:00PM AND ToD&amp;lt;7:00AM AND Source_Country=China, THEN ALERT “Root Login During Non-Biz Hours from Foreign IP”&lt;/em&gt;) and not stateful correlation rules, written with their own applications in mind. As a result, you'd be stuck with ill-fitting default rules and no ability to create&amp;nbsp; custom, site-specific rules or even intelligently modify the default rules to fit your use cases better. Not a good situation - well, unless you are a consultant offering &lt;a href="http://www.securitywarriorconsulting.com/"&gt;rule correlation tuning services&lt;/a&gt; ;-)&lt;br /&gt;
&lt;br /&gt;
One of the ways out, in my opinion, is in wide use of event scoring algorithms and other ruleless methods. &amp;nbsp;These methods, while not without known limitations, can be extremely useful in environment where correlation rule tuning is not likely to happen, no matter how many times we say it should happen. By the way, algorithmic or "statistical" correlation has typically little to do with correlation or statistics. A more useful way to think about is weighted event scoring or weighted object (such as IP address, port, username, asset or a combination of these) scoring&lt;br /&gt;
&lt;br /&gt;
So, in many cases back then people used a naïve risk scoring where:&lt;br /&gt;
&lt;em&gt;risk (for each destination IP inside) &amp;nbsp;=&amp;nbsp; threat (=event severity derivative) x value (=user-entered for each targeted “asset” - obviously a major Achilles heel in the real world implementations) x vulnerability (=derived from&amp;nbsp; vulnerability scan results)&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
It mostly failed to work when used for real-time visualization (not historical profiling) and was also really noisy for alerting. But even such simplistic algorithm, however, still presents a very useful starting point to develop better methods, post-process and baseline the data, add dimensions, etc. It was also commonly not integrated with rules, extended asset data, user identity, etc. &lt;br /&gt;
&lt;br /&gt;
Let’s now fast forward to 2011. People still &lt;a href="http://chuvakin.blogspot.com/2010/08/pathetic-analytics-epiphany.html"&gt;hate the rules&lt;/a&gt; AND&amp;nbsp; rules still remain a mainstay of SIEM technology. However, it seems like the algorithmic ruleless methods are making a comeback, with better analysis, profiling, baselining and with better rule integration. For example, this recent whitepaper from NitroSecurity (&lt;a href="http://www.nitrosecurity.com/resources/whitepapers/detecting-insider-external-threats-with-risk-score-correlation/"&gt;here, with registration&lt;/a&gt;) covers the technology they acquired when LogMatrix/OpenService crashed and now integrated into NitroESM. The paper covers some methods of event scoring that I &lt;a href="http://www.slideshare.net/anton_chuvakin/baselining-logs"&gt;personally know&lt;/a&gt; to work well. For example, a trick I used to call “2D baselining”: not just tracking the user actions over time and activities on destination assets over time, but tracking pair of user&amp;lt;-&amp;gt;asset over time. So, “jsmith” might be a frequent user on “server1”, but only rarely goes to “server2”, and such pair scoring will occasionally show some fun things from the “OMG, he is really doing it!” category &lt;img alt="Smile" class="wlEmoticon wlEmoticon-smile" src="http://lh3.ggpht.com/-8oHn3OE6zfI/TfaX9QSj6MI/AAAAAAAAPdY/i4hMNYsOixE/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" style="border-bottom-style: none; border-left-style: none; border-right-style: none; border-top-style: none;" /&gt;&lt;br /&gt;
&lt;br /&gt;
So, when you think SIEM, don’t just think “how many rules?” – think “what other methods for real-time and historical event analysis do they use?” &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Possibly related posts:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/06/how-do-i-get-best-siem.html"&gt;How Do I Get The Best SIEM?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/05/log-management-graduation-criteria.html"&gt;Log Management-&amp;gt;SIEM Graduation Criteria: Violate at Your Own Peril!&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/05/how-to-replace-siem.html"&gt;How to Replace a SIEM?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2011/03/siem-resourcing-or-how-much-friggin.html"&gt;SIEM Resourcing or How Much the Friggin’ Thing Would REALLY Cost Me?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/11/how-to-write-ok-siem-rfp.html"&gt;How to Write an OK SIEM RFP?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/10/so-what-should-i-want-or-how-not-to.html"&gt;"So, What Should I Want?" or How NOT to Pick a SIEM-III?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/03/myth-of-siem-as-analyst-in-box-or-how.html"&gt;The Myth of SIEM as "An Analyst-in-the-box" or How NOT to Pick a SIEM-II?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/01/i-want-to-buy-correlation-or-how-not-to.html"&gt;I Want to Buy Correlation” or How NOT to Pick a SIEM?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/12/log-management-siem.html"&gt;Log Management + SIEM = ?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/on-siem-complexity.html"&gt;On SIEM Complexity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;SIEM Bloggables&lt;/a&gt;: &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; Use Cases and &lt;a href="http://chuvakin.blogspot.com/2010/08/new-siem-whitepaper-on-use-cases-in.html"&gt;Whitepaper with detailed SIEM use cases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/03/log-management-siem-users-minimalist-vs.html"&gt;Log Management / SIEM Users: "Minimalist" vs "Analyst"&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;All posts labeled SIEM&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-802506752424086940?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/WF5TAuHbz8J0_9jz2V40QvjlutQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/WF5TAuHbz8J0_9jz2V40QvjlutQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/WF5TAuHbz8J0_9jz2V40QvjlutQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/WF5TAuHbz8J0_9jz2V40QvjlutQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hlAbegp7hFQ:nD7WrjaiYro:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hlAbegp7hFQ:nD7WrjaiYro:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hlAbegp7hFQ:nD7WrjaiYro:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/hlAbegp7hFQ" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-14T11:11:00.358-07:00</app:edited><media:thumbnail url="http://lh3.ggpht.com/-8oHn3OE6zfI/TfaX9QSj6MI/AAAAAAAAPdY/i4hMNYsOixE/s72-c/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" height="72" width="72" /><feedburner:origLink>http://chuvakin.blogspot.com/2011/06/algorithmic-siem-correlation-is-back.html</feedburner:origLink></item><item><title>NIST EMAP Out</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/x2duNcbYPXE/nist-emap-out.html</link><category>CEE</category><category>log management</category><category>logs</category><category>standards</category><category>logging</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Wed, 08 Jun 2011 08:39:29 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-2649547495059747488</guid><description>&lt;p&gt;As those in the know already know, NIST has &lt;strong&gt;officially&lt;/strong&gt; released some EMAP materials the other day (see &lt;a href="http://scap.nist.gov/emap/"&gt;scap.nist.gov/emap/&lt;/a&gt;). EMAP stands for “Event Management Automation Protocol” and has the goal of “standardizing the communication of digital event data.” You can think of it as future “SCAP for logs/events” (&lt;a href="http://scap.nist.gov/"&gt;the SCAP itself&lt;/a&gt; is for configurations and vulnerabilities). Obviously, both twin standards will be “Siamese twins” and will have multiple connection points (such as through CVE, &lt;a href="http://cpe.mitre.org/"&gt;CPE&lt;/a&gt; and others).&lt;/p&gt;  &lt;p&gt;In reality, SCAP and EMAP are more like “standard umbrellas” and cover multiple constituent security data standards – such as CPE, CVE, CVSS, XCCDF, etc for SCAP and CEE for EMAP. As &lt;a href="http://scap.nist.gov/emap/"&gt;the new EMAP site&lt;/a&gt; states:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;The Event Management Automation Protocol (EMAP) is a suite of interoperable specifications designed to &lt;strong&gt;standardize the communication of event management data&lt;/strong&gt;. EMAP is an emerging protocol within the NIST Security Automation Program, and is a &lt;strong&gt;peer to similar automation protocols such as the Security Content Automation Protocol (SCAP&lt;/strong&gt;). Where SCAP standardizes the data models of configuration and vulnerability management domains, EMAP will focus on &lt;strong&gt;standardizing the data models relating to event and audit management&lt;/strong&gt;. At a high-level, the goal of EMAP is to enable standardized content, representation, exchange, correlation, searching, storing, prioritization, and auditing of event records within an organizational IT environment.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;em&gt;[emphasis by &lt;a href="http://www.chuvakin.org"&gt;me&lt;/a&gt;] &lt;/em&gt;&lt;/p&gt;  &lt;p&gt;While CEE team is continuing its work on the log formats, taxonomy, profiles and other fun details of logging events, the broader EMAP effort creates a framework around it as well as proposes a set of additional standards related to correlation, parsing rules, event log filtering, event log storage, etc. &lt;a href="http://scap.nist.gov/emap/emap-overview-usecases-requirements-20110606.pdf"&gt;The released deck [PDF]&lt;/a&gt; has these details as well as some use cases for EMAP such as Audit Management, Regulatory Compliance, Incident Handling, Filtered Event Record Sharing, Forensics, etc. &lt;/p&gt;  &lt;p&gt;In the future, I expect EMAP to include event log signing, maybe its own event transport (run under CEE component standard) as well as a bunch of standardized representation for correlation (via CERE component standard) and parsing rules (via OEEL) to simplify &lt;a href="http://chuvakin.blogspot.com/search/label/SIEM"&gt;SIEM&lt;/a&gt; interoperability as well as &lt;a href="http://chuvakin.blogspot.com/2011/05/how-to-replace-siem.html"&gt;migration&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Everything public to read on EMAP is linked &lt;a href="http://scap.nist.gov/events/2009/itsac/presentations/day2/Day2_CNMAL_CEE_Shields_Heinbockel.pdf"&gt;here&lt;/a&gt; (2009), &lt;a href="http://scap.nist.gov/events/2010/itsac/presentations/day1/Automation_Specifications-CEE.pdf"&gt;here&lt;/a&gt; (2010), &lt;a href="http://scap.nist.gov/events/2010/itsac/presentations/day3/EMAP_Workshop-EMAP_Status.pdf"&gt;here&lt;/a&gt;, etc [links are PDFs], if you are into that sort of reading. SIEM/&lt;a href="http://chuvakin.blogspot.com/search/label/log%20management"&gt;log management&lt;/a&gt; vendors, please pay attention &lt;img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://lh3.ggpht.com/-SjyoIEZMCG0/Te-Xr3Cg7GI/AAAAAAAAPbg/2Lx83v_5UCs/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" /&gt; - some of you have already started implementation of this stuff….&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19553129-2649547495059747488?l=chuvakin.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/5WQ-0370ME_aDQ5jLpvGmOUf4D4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/5WQ-0370ME_aDQ5jLpvGmOUf4D4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/5WQ-0370ME_aDQ5jLpvGmOUf4D4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/5WQ-0370ME_aDQ5jLpvGmOUf4D4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=x2duNcbYPXE:djdEgxS32M8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=x2duNcbYPXE:djdEgxS32M8:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=x2duNcbYPXE:djdEgxS32M8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/x2duNcbYPXE" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-08T08:39:29.117-07:00</app:edited><media:thumbnail url="http://lh3.ggpht.com/-SjyoIEZMCG0/Te-Xr3Cg7GI/AAAAAAAAPbg/2Lx83v_5UCs/s72-c/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" height="72" width="72" /><feedburner:origLink>http://chuvakin.blogspot.com/2011/06/nist-emap-out.html</feedburner:origLink></item><copyright>(C) Anton Chuvakin and Andrew Hay</copyright><media:credit role="author">Anton Chuvakin</media:credit><media:rating>nonadult</media:rating><media:description type="plain">LogChat: Andrew Hay and Anton Chuvakin talk about logging, log management and related topics</media:description></channel></rss>

