<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;CkECR3Y8eip7ImA9WhRRFEk.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052</id><updated>2011-11-27T18:37:46.872-06:00</updated><category term="SOC" /><category term="Log Logic" /><category term="NetWitness" /><category term="Security Operations" /><category term="ArcSight" /><category term="NSA" /><category term="Splunk" /><category term="SIEM Best Practices" /><category term="Log Management" /><category term="China" /><category term="SIEM" /><category term="Securosis" /><category term="Decurity" /><category term="Rocky" /><category term="Correlation" /><category term="Hackers for Charity" /><category term="Google" /><category term="APT" /><title>Security Operations by Visible Risk</title><subtitle type="html">Visible Risk, llc presents the Security Operations Blog.  Topics Include:  Security Operations, Security Information and Event Management (SIEM), Log Management, Advanced Persistent Threat (APT) and Incident Response.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://securityoperations.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>33</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/blogspot/OGTr" /><feedburner:info uri="blogspot/ogtr" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by-nc-nd/3.0/" /><entry gd:etag="W/&quot;C0cBQn88cCp7ImA9WxBbEkg.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-5857821116729225119</id><published>2010-03-10T13:57:00.000-06:00</published><updated>2010-03-10T13:57:33.178-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-03-10T13:57:33.178-06:00</app:edited><title>Moving Again (Visible Risk)</title><content type="html">So I think this is the last time I'll ask you to move with me....&amp;nbsp; I hope it is anyway....&lt;br /&gt;
&lt;br /&gt;
As of last week I've started a new venture.&amp;nbsp; My company is named "Visible Risk".&amp;nbsp; Visible Risk other than being a great name for a company, is my effort to help push information security forward over the next few years.&amp;nbsp; I'll be working with certain organizations on integrating intelligence and security operations, and a huge area of focus for me will be providing "live" use-case based content for security products (like SIEM).&lt;br /&gt;
&lt;br /&gt;
Additionally, I'm starting a new podcast and video/webcast under the Visible Risk brand over the next few weeks so please be on the look out for that as I'd love to involve you in it!&lt;br /&gt;
&lt;br /&gt;
Visible Risk Blog RSS Feed:&amp;nbsp; &lt;a href="http://www.visiblerisk.com/blog/rss.xml"&gt;http://www.visiblerisk.com/blog/rss.xml&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Thank you again to everyone who has helped me over the years to better understand my strengths and weaknesses and for always pushing me forward! &lt;br /&gt;
&lt;br /&gt;
If you're not already following my new blog here are links to some of my recent postings:&lt;br /&gt;
&lt;br /&gt;
1.&amp;nbsp; &lt;b&gt;A primer on starting a new company:&lt;/b&gt;&amp;nbsp; &lt;a href="http://www.visiblerisk.com/blog/2010/3/10/so-you-want-to-work-for-yourself.htm"&gt;http://www.visiblerisk.com/blog/2010/3/10/so-you-want-to-work-for-yourself.htm&lt;/a&gt;l&amp;nbsp;&amp;nbsp; or&amp;nbsp;&amp;nbsp; &lt;a href="http://bit.ly/aX7WWB"&gt;http://bit.ly/aX7WWB &lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
2.&amp;nbsp; &lt;b&gt;RSA Recap - Round 1&lt;/b&gt;: &lt;a href="http://www.visiblerisk.com/blog/2010/3/10/rsa-conference-2010-recap-round-1.htm"&gt;http://www.visiblerisk.com/blog/2010/3/10/rsa-conference-2010-recap-round-1.htm&lt;/a&gt;l&amp;nbsp; or&amp;nbsp;&amp;nbsp; &lt;a href="http://bit.ly/c3xmRQ"&gt;http://bit.ly/aPA63z&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-5857821116729225119?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/1RyghCzgCF3o7e7KvKew2hWmRGk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1RyghCzgCF3o7e7KvKew2hWmRGk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/1RyghCzgCF3o7e7KvKew2hWmRGk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1RyghCzgCF3o7e7KvKew2hWmRGk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=dbpmpvHV0Zk:dvEjiwV2Etg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=dbpmpvHV0Zk:dvEjiwV2Etg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=dbpmpvHV0Zk:dvEjiwV2Etg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=dbpmpvHV0Zk:dvEjiwV2Etg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=dbpmpvHV0Zk:dvEjiwV2Etg:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=dbpmpvHV0Zk:dvEjiwV2Etg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=dbpmpvHV0Zk:dvEjiwV2Etg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/dbpmpvHV0Zk" height="1" width="1"/&gt;</content><link rel="related" href="http://www.visiblerisk.com/blog" title="Moving Again (Visible Risk)" /><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/5857821116729225119/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=5857821116729225119&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/5857821116729225119?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/5857821116729225119?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/dbpmpvHV0Zk/moving-again-visible-risk.html" title="Moving Again (Visible Risk)" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2010/03/moving-again-visible-risk.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEcGRHYycCp7ImA9WxBVEkg.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-6168023004695305037</id><published>2010-02-15T11:43:00.001-06:00</published><updated>2010-02-15T11:47:05.898-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-02-15T11:47:05.898-06:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Rocky" /><category scheme="http://www.blogger.com/atom/ns#" term="Hackers for Charity" /><title>Supporting Hackers For Charity</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_7cKexWoDNAg/S3mEiBFOgmI/AAAAAAAAAHA/IFvKE-oqUd0/s1600-h/Picture+2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_7cKexWoDNAg/S3mEiBFOgmI/AAAAAAAAAHA/IFvKE-oqUd0/s320/Picture+2.png" /&gt;&lt;/a&gt;&lt;/div&gt;Something in the back of my head told me to check out Johnny Long's Hackers for Charity website today to get an update on what's been happening with him and his family.&amp;nbsp;&amp;nbsp; I hate to say it, but I let this go "out of site, out of mind" for me.&amp;nbsp; As I looked at the donor cloud and I noticed it was empty.  Really?!?! Empty?!?!(technical issue maybe? I just donated to test it) I can't imagine that hasn't been any sponsorships in a month.&lt;br /&gt;
&lt;br /&gt;
I realize there are multiple ways we all contribute to HFC (General Donations, Equipment, Software, Time/energy, Books, etc), but the donor cloud being empty worries me that maybe others have also let this go "out of site, out of mind" for them as well.&amp;nbsp; So consider this message a small reminder!&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.hackersforcharity.org/hackers-for-charity/get-involved/"&gt;Get Involved with Hackers For Charity!&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Whatever you can do, &lt;a href="http://www.hackersforcharity.org/store/"&gt;buy shirts&lt;/a&gt;, donate via Paypal, &lt;a href="http://www.hackersforcharity.org/hackers-for-charity/get-involved/#donate_hardware"&gt;donate equipment&lt;/a&gt;, &lt;a href="http://www.hackersforcharity.org/hackers-for-charity/get-involved/#informer"&gt;join Informer&lt;/a&gt; - every little bit helps a great deal over there.&lt;br /&gt;
&lt;br /&gt;
In case you didn't know Johnny Long and his family through HFC support a couple of incredible missions in East Africa&lt;br /&gt;
&lt;br /&gt;
1.  &lt;a href="http://www.hackersforcharity.org/food-program/"&gt;Food Program in Kenya &lt;/a&gt;(You can help via the Donor Cloud on his website).&lt;br /&gt;
&lt;br /&gt;
2.  &lt;a href="http://www.hackersforcharity.org/hackers-for-charity/about-us/"&gt;Classroom Initiative&lt;/a&gt; where with AOET they have built three classrooms already to help empower the Ugandans to learn and do for themselves!&lt;br /&gt;
&lt;br /&gt;
Since his first trip, Johnny has inspired me to be better and to do more wherever I can.&amp;nbsp; His story is amazing.&amp;nbsp; He gets energized by our (community) support!&amp;nbsp; Personally, I've done what I can over the years to help and will continue to do the best I can, but it's never enough.&amp;nbsp; I'm suggesting we all join in - with whatever you can.  $20/Month - $25 one time donation, whatever you can do.&amp;nbsp;&amp;nbsp;  To kick things off anew in 2010 - my family and I are planning on giving at least 50% of my first paycheck with whomever my new employer winds up being to HFC in March.&amp;nbsp; How will you help with this effort?&lt;br /&gt;
&lt;br /&gt;
Let's see how we can support his incredible mission!&lt;br /&gt;
&lt;br /&gt;
You can follow &lt;a href="http://www.facebook.com/ihackstuff"&gt;Johnny Long on Facebook&lt;/a&gt;  You can also find him on &lt;a href="http://twitter.com/ihackstuff/"&gt;Twitter&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-6168023004695305037?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Gs6Gmd-q6W-VoxzKvEDonqgHAkg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Gs6Gmd-q6W-VoxzKvEDonqgHAkg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Gs6Gmd-q6W-VoxzKvEDonqgHAkg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Gs6Gmd-q6W-VoxzKvEDonqgHAkg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Yo1DH-5DYNs:mXuD9a6nhkg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Yo1DH-5DYNs:mXuD9a6nhkg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=Yo1DH-5DYNs:mXuD9a6nhkg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Yo1DH-5DYNs:mXuD9a6nhkg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Yo1DH-5DYNs:mXuD9a6nhkg:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Yo1DH-5DYNs:mXuD9a6nhkg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=Yo1DH-5DYNs:mXuD9a6nhkg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/Yo1DH-5DYNs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/6168023004695305037/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=6168023004695305037&amp;isPopup=true" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/6168023004695305037?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/6168023004695305037?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/Yo1DH-5DYNs/supporting-hackers-for-charity.html" title="Supporting Hackers For Charity" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_7cKexWoDNAg/S3mEiBFOgmI/AAAAAAAAAHA/IFvKE-oqUd0/s72-c/Picture+2.png" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2010/02/supporting-hackers-for-charity.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0cMQHo-fSp7ImA9WxBWGU8.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-2214528780166292721</id><published>2010-02-11T14:44:00.000-06:00</published><updated>2010-02-11T14:44:41.455-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-02-11T14:44:41.455-06:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Rocky" /><title>Getting More "Connected" in 2010</title><content type="html">One of my goals in 2010 is to be more timely in my responses to everyone that takes the time to reach out to me.&amp;nbsp; It seems that I'm pretty much the worst person on earth when it comes to responding to phone messages or emails older than 24 hours.&amp;nbsp; I have a very small memory ring-buffer in my head.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
As part of me working on fixing this issue -&amp;nbsp; I'm opening up my entire "virtual" life to you all - If you want to reach out and talk (or collaborate on a project) about Security Operations, SIEM, Log Management, Security Monitoring and Analysis, Incident Response, etc - I've provided about every reasonable way I can think of to reach me and I'm committing to being as responsive as I can.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
In addition to my &lt;a href="http://securityoperations.blogspot.com/"&gt;blog&lt;/a&gt; - here are some of the best ways to reach me - or learn what I'm up to in 2010:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.twitter.com/Rockyd" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="52" src="http://1.bp.blogspot.com/_7cKexWoDNAg/S3Rh9Fy-Z4I/AAAAAAAAAGo/0KnhIIIOqNc/s200/Picture+5.png" width="200" /&gt;&lt;/a&gt;&lt;a href="http://www.twitter.com/Rockyd"&gt;Twitter "@RockyD"&amp;nbsp; &lt;/a&gt; DM me or at least "@rockyd" me and I'll probably see the message within a few minutes one my phone or desktop.&amp;nbsp; I'm addicted to Twitter (seriously I think I might need to go to Twitter Rehab).&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="skype:securityprofessional?add"&gt;&lt;img alt="Add me to Skype" height="52" src="http://download.skype.com/share/skypebuttons/buttons/add_blue_white_194x52.png" style="border: medium none;" width="194" /&gt;&lt;/a&gt; I'm almost always online via Skype either on my phone or at my desk.  I'm willing to Video/Voice and Chat as necessary.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.linkedin.com/in/securityprofessional"&gt;&lt;br /&gt;
&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.linkedin.com/in/securityprofessional" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_7cKexWoDNAg/S3RhCUwqZYI/AAAAAAAAAGQ/KXwwRoPuY0U/s320/Picture+1.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.linkedin.com/in/securityprofessional"&gt;Linkedin Profile&lt;/a&gt;  I use the Linkedin Groups feature to answer questions, though less so over the last few months.  I do post there every few days and I use Linkedin in advance of every single professional conversation I have to help have an understanding of who I am talking with.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.blogger.com/securityprofessional@googlewave.com" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_7cKexWoDNAg/S3RiKR_KFnI/AAAAAAAAAGw/eFVmyW-GjG8/s320/Picture+3.png" /&gt;&lt;/a&gt;&lt;a href="http://www.blogger.com/securityprofessional@googlewave.com"&gt;Google Wave "SecurityProfessional"&lt;/a&gt; I'm committing to trying this out for some projects I'm collaborating on and it is working great so far! &lt;br /&gt;
&lt;br /&gt;
&lt;script src="http://download.skype.com/share/skypebuttons/js/skypeCheck.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.google.com/profiles/securityprofessional" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="50" src="http://2.bp.blogspot.com/_7cKexWoDNAg/S3RheGKz58I/AAAAAAAAAGY/-vyfQx03K0Y/s200/Picture+2.png" width="200" /&gt;&lt;/a&gt;&lt;a href="http://www.google.com/profiles/securityprofessional"&gt; Google Buzz: Security Professional&lt;/a&gt;. My Information Security related "Buzz". Not committing 100% to Buzz yet, but I will try it out for a while and see how it goes. If you follow me on Buzz it does open up gmail and google chat as another communication opportunity.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_7cKexWoDNAg/S3RkJ9GCxFI/AAAAAAAAAG4/wV743bFGzEo/s1600-h/Picture+6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_7cKexWoDNAg/S3RkJ9GCxFI/AAAAAAAAAG4/wV743bFGzEo/s320/Picture+6.png" /&gt;&lt;/a&gt;&lt;/div&gt;Of course there is good old-fashioned email as well.&amp;nbsp; If you can't figure out my gmail with everything else I've provided above, please get off the internet.&amp;nbsp; If I don't respond to you within 24 hours - please feel free to ping me again.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Conferences:&lt;/b&gt;&amp;nbsp; I will be attending &lt;a href="http://www.rsaconference.com/2010/usa/index.htm"&gt;RSA&lt;/a&gt; and &lt;a href="http://www.securitybsides.com/BSidesSanFrancisco"&gt;B-SidesSF&lt;/a&gt; in March and perhaps BH/DC in July.&amp;nbsp; Always happy to talk in person!&amp;nbsp; My schedule fills up pretty quick, but I always leave evenings open! &lt;br /&gt;
&lt;br /&gt;
If you can't reach me with any of the above methods I'm either in-person meeting with someone (I don't usually answer to machines if I'm face-to-face with someone - it just seems rude) on an airplane, or I'm dead and if I can I'll either get back with you or haunt you whichever is appropriate.&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
In all seriousness, I look forward to talking/collaborating with you in 2010 and beyond.&amp;nbsp;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-2214528780166292721?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/XiygEW2-_ZhuH8kHHGkvRg0VRvY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XiygEW2-_ZhuH8kHHGkvRg0VRvY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/XiygEW2-_ZhuH8kHHGkvRg0VRvY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XiygEW2-_ZhuH8kHHGkvRg0VRvY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=XLqhI4ntss8:Tmu_6rH3QBg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=XLqhI4ntss8:Tmu_6rH3QBg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=XLqhI4ntss8:Tmu_6rH3QBg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=XLqhI4ntss8:Tmu_6rH3QBg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=XLqhI4ntss8:Tmu_6rH3QBg:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=XLqhI4ntss8:Tmu_6rH3QBg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=XLqhI4ntss8:Tmu_6rH3QBg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/XLqhI4ntss8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/2214528780166292721/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=2214528780166292721&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/2214528780166292721?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/2214528780166292721?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/XLqhI4ntss8/getting-more-connected-in-2010.html" title="Getting More &quot;Connected&quot; in 2010" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_7cKexWoDNAg/S3Rh9Fy-Z4I/AAAAAAAAAGo/0KnhIIIOqNc/s72-c/Picture+5.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2010/02/getting-more-connected-in-2010.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0IHSXs4eSp7ImA9WxBWGEw.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-3150285732446779332</id><published>2010-02-10T09:52:00.001-06:00</published><updated>2010-02-10T10:32:18.531-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-02-10T10:32:18.531-06:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SIEM" /><category scheme="http://www.blogger.com/atom/ns#" term="Rocky" /><category scheme="http://www.blogger.com/atom/ns#" term="Correlation" /><category scheme="http://www.blogger.com/atom/ns#" term="Securosis" /><title>Much Ado About Correlation</title><content type="html">Mike Rothman at Securosis posted &lt;a href="http://securosis.com/blog/network-security-fundamentals-correlation"&gt;Network Security Fundamentals: Correlation &lt;/a&gt; yesterday and did a good job explaining some common issues SIEM and "Correlation".  If you're in the market for SIEM you should read it and not just because it refers to some of my previous blogs :) (&lt;a href="http://securityoperations.blogspot.com/2009/08/just-in-time-for-back-to-school.html"&gt;SIEM 101&lt;/a&gt; and &lt;a href="http://securityoperations.blogspot.com/2010/01/siem-201-use-case-overview.html"&gt;SIEM 201&lt;/a&gt;) but because is very accurate.  You have to do the real work PRIOR to deploying the SIEM. It's all in the requirements.  If you can't define how you will use the output of the SIEM - stick with Log Management until your organization can mature into using SIEM properly. &lt;br /&gt;
&lt;br /&gt;
I really enjoyed Adrian's &lt;a href="http://securosis.com/blog/counterpoint-correlation-is-useful-but-threat-assessment-is-fundamental"&gt;follow up Post&lt;/a&gt; Where he describes in detail why SIEM is not the end-all be-all of Security Monitoring.  It's a good tool designed to do the best it can with what it is given.  Simply put there is only so much you can do with crappy logs.  Additional context is always required.  For more on my thoughts about what works for Security Monitoring see &lt;a href="http://securityoperations.blogspot.com/2008/09/best-practices-in-security-operations.html"&gt; Security Operations: Collection Post&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-3150285732446779332?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/nk_Ngz2tv0W578BzPbg-ARJyzRc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nk_Ngz2tv0W578BzPbg-ARJyzRc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/nk_Ngz2tv0W578BzPbg-ARJyzRc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nk_Ngz2tv0W578BzPbg-ARJyzRc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=5dRWAbd2nVI:KK5ePT1NDFw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=5dRWAbd2nVI:KK5ePT1NDFw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=5dRWAbd2nVI:KK5ePT1NDFw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=5dRWAbd2nVI:KK5ePT1NDFw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=5dRWAbd2nVI:KK5ePT1NDFw:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=5dRWAbd2nVI:KK5ePT1NDFw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=5dRWAbd2nVI:KK5ePT1NDFw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/5dRWAbd2nVI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/3150285732446779332/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=3150285732446779332&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/3150285732446779332?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/3150285732446779332?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/5dRWAbd2nVI/much-ado-about-correlation.html" title="Much Ado About Correlation" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2010/02/much-ado-about-correlation.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkcBQH8zfip7ImA9WxBWE00.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-3495065984211904158</id><published>2010-02-04T12:27:00.000-06:00</published><updated>2010-02-04T12:27:31.186-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-02-04T12:27:31.186-06:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Google" /><category scheme="http://www.blogger.com/atom/ns#" term="NSA" /><category scheme="http://www.blogger.com/atom/ns#" term="APT" /><title>NSA to Google wrt APT -  "We're here to help"</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_7cKexWoDNAg/S2sL3yEAoKI/AAAAAAAAAF0/sg0l8gPtixQ/s1600-h/NSA_GOOGLE.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="132" src="http://1.bp.blogspot.com/_7cKexWoDNAg/S2sL3yEAoKI/AAAAAAAAAF0/sg0l8gPtixQ/s400/NSA_GOOGLE.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;br /&gt;
The &lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2010/02/03/AR2010020304057.html"&gt;Washington Post&lt;/a&gt; reported that the NSA will be helping Google with the analysis of events related to the recent Chinese Espionage that affected Google and so many other US Companies.  &lt;br /&gt;
&lt;br /&gt;
Does this confirm the existence of APT, and that APT is a real danger? Duh, the world's scariest intelligence organization is focusing their talents on the problem - it IS a problem.  Is this the best way to combat it?  Well, we do need more exposure, information and collaboration so I can't really think of a better partnership of minds.  &lt;br /&gt;
&lt;br /&gt;
Sure the Privacy implications are huge.  NSA does go to great lengths to protect privacy of US Citizens.  The fact that this is public information does lend itself to more trust.  They are both being fairly transparent and the goal is in our (US-centric) best interest.  &lt;br /&gt;
&lt;br /&gt;
Some questions I have - I wonder who is going to have oversight authority?  I also wonder WHY this is public information?  Is NSA going to offer the same level of collaboration to other companies affected by APT (or non APT espionage)?  If so great news, if not then what is the threshold for involvement?&lt;br /&gt;
&lt;br /&gt;
I also wonder if this was coordinated through our new Cyber Coordinator and if so, why wouldn't he take the opportunity to announce the partnership?  &lt;br /&gt;
&lt;br /&gt;
What do you think?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-3495065984211904158?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/DTsVSI0HfEsur7uk63OTgIufoos/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DTsVSI0HfEsur7uk63OTgIufoos/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/DTsVSI0HfEsur7uk63OTgIufoos/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DTsVSI0HfEsur7uk63OTgIufoos/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=67vqW53Eabo:nVvIyIwVbko:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=67vqW53Eabo:nVvIyIwVbko:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=67vqW53Eabo:nVvIyIwVbko:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=67vqW53Eabo:nVvIyIwVbko:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=67vqW53Eabo:nVvIyIwVbko:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=67vqW53Eabo:nVvIyIwVbko:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=67vqW53Eabo:nVvIyIwVbko:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/67vqW53Eabo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/3495065984211904158/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=3495065984211904158&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/3495065984211904158?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/3495065984211904158?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/67vqW53Eabo/nsa-to-google-wrt-apt-were-here-to-help.html" title="NSA to Google wrt APT -  &quot;We're here to help&quot;" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_7cKexWoDNAg/S2sL3yEAoKI/AAAAAAAAAF0/sg0l8gPtixQ/s72-c/NSA_GOOGLE.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2010/02/nsa-to-google-wrt-apt-were-here-to-help.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkMEQHw6fip7ImA9WxBXEEQ.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-3753344194829782995</id><published>2010-01-21T10:13:00.000-06:00</published><updated>2010-01-21T10:13:21.216-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-21T10:13:21.216-06:00</app:edited><title>Call to Arms</title><content type="html">For the last several years I’ve been a position to help a number of organizations with their Incident Detection and Response programs. One thing that remains consistent across all of the organizations is that there is a very high rate of compromised systems. Whether these were compromised from the outside or popped by malware really doesn’t matter, what really matters is the rate at which information is leaving the organization is alarming and should be disturbing to everyone. It’s not just the big guys either – I’ve seen evidence of compromise and data extraction at nearly every organization I’ve encountered.&lt;br /&gt;
&lt;br /&gt;
In &lt;a href="http://fudsec.com/liberate-yourself-change-the-game-to-suit-you"&gt;this FUDSEC post&lt;/a&gt; one of the points I made was a call for leadership and action, because no one else is coming to save us – a point made even clearer by &lt;a href="http://fudsec.com/guerilla-security-leadership-0"&gt;Mike Rothman in his FUDSEC post&lt;/a&gt; earlier this month. I’m tired of sitting on the sidelines and watching our systems being ravaged. This sense of frustration really hit me over the last month as I’ve taken a look at my career and what I’ve accomplished and what I want to do next. I’ve done a lot for the companies I’ve worked for and their customers, no question – but it isn’t nearly enough. I need to do more. &lt;br /&gt;
&lt;br /&gt;
Watching the Google versus China situation and the apparent lack of response by our government combined with our utter futility in fighting these threats really has stirred a call for action within me. So much so, that I really believe if I was 10 years younger and 50 lbs lighter I’d re-enlist to go back and work at AFCERT or similar entity. Not as a contractor or consultant but as an Airman or Federal employee. I want to fight back or at least defend as vigorously as possible. I simply cannot and will not sit idle anymore.  There is still some warrior left in me.&lt;br /&gt;
&lt;br /&gt;
My question to you is this: Does anyone else feel nationalistic and have the urge to serve their country to fight in the information security arena, to protect our nation, or perhaps to strike back at those who seek to harm us? I do!&lt;br /&gt;
&lt;br /&gt;
To my friends at DHS, The White House, NSA, USAF, DoD, Secret Service and/or the FBI - if you have a way of using a resource with my background to help defend this country I stand here in Austin, TX ready, willing and able!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-3753344194829782995?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/6Xu0ArVClfBDxznWSvrePJWoGn4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6Xu0ArVClfBDxznWSvrePJWoGn4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/6Xu0ArVClfBDxznWSvrePJWoGn4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6Xu0ArVClfBDxznWSvrePJWoGn4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Fac19VBx9UY:_7sUv2z0GCE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Fac19VBx9UY:_7sUv2z0GCE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=Fac19VBx9UY:_7sUv2z0GCE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Fac19VBx9UY:_7sUv2z0GCE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Fac19VBx9UY:_7sUv2z0GCE:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Fac19VBx9UY:_7sUv2z0GCE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=Fac19VBx9UY:_7sUv2z0GCE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/Fac19VBx9UY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/3753344194829782995/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=3753344194829782995&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/3753344194829782995?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/3753344194829782995?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/Fac19VBx9UY/call-to-arms.html" title="Call to Arms" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2010/01/call-to-arms.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0YERHk7cCp7ImA9WxBQE0g.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-2597157927330063475</id><published>2010-01-12T19:27:00.001-06:00</published><updated>2010-01-12T21:58:25.708-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-12T21:58:25.708-06:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="China" /><category scheme="http://www.blogger.com/atom/ns#" term="Google" /><title>Google's New Approach to China - My Initial Reaction</title><content type="html">RE:&amp;nbsp; http://googleblog.blogspot.com/2010/01/new-approach-to-china.html&lt;br /&gt;
&lt;br /&gt;
I love the fact that Google publicly disclosed this incident.&amp;nbsp; I'm not going to comment on the human rights angle or the advertising angle or even the exact methods for exploitation other than to say - they are nothing more than variables in the equation. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We must acknowledge that even of the best security teams in the world are nearly irrelevant against those with time, motivation and expertise. &amp;nbsp;&amp;nbsp; At this point we can only hope to detect traces of this activity and begin the investigation from there.&amp;nbsp; Given current IT environment we can not stop this but we sure as hell need to be aware these threats exists and they are being actively exploited everywhere.&lt;br /&gt;
&lt;br /&gt;
What should our government do in response?&amp;nbsp; Given the expertise at Google I'm willing to take the facts as presented in their blog at face value and say they are correct in their assumptions of the aggressors in this scenario.&amp;nbsp; This isn't news on its own, we've always known that to be the case, but Google coming public with this information is amazing!&amp;nbsp; This activity should force heated discourse with our industry leaders, our government leaders, our intelligence/military leaders, etc.&amp;nbsp; We need to talk... then we need to Act.&lt;br /&gt;
&lt;br /&gt;
What a platform for the new cybersecurity coordinator to stand on... If this situation doesn't give him the ears of Congress nothing will. &amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
My Question of the day: What is the government going to do to protect our information, our companies and our people?&amp;nbsp; It is apparent that we can not protect everything ourselves, there needs to be a real deterrent (legal, military, etc) and we need real assistance not just rhetoric. &lt;br /&gt;
&lt;br /&gt;
Does it make sense yet?&amp;nbsp; We can't sit idle anymore, we must take pro-active measures to protect our company's our data and our people.&amp;nbsp; They are all being targeted for purposes you may not fully understand, but that doesn't mean you won't be compromised.&amp;nbsp; We can't solve the whole problem, but we must take a more substantive approach to Information Security.&lt;br /&gt;
&lt;br /&gt;
My congratulations to Google.&amp;nbsp; I know of no other company in the world that would consider risking the largest market in the world.&amp;nbsp; Prioritizing the "right thing" over financial gain is way beyond "do no evil".&amp;nbsp;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-2597157927330063475?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/5mY3XXfZ6DtTeW1iEghxvsK1LCY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/5mY3XXfZ6DtTeW1iEghxvsK1LCY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/5mY3XXfZ6DtTeW1iEghxvsK1LCY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/5mY3XXfZ6DtTeW1iEghxvsK1LCY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=YxNBka2y5Y8:b80YsW5KRVY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=YxNBka2y5Y8:b80YsW5KRVY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=YxNBka2y5Y8:b80YsW5KRVY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=YxNBka2y5Y8:b80YsW5KRVY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=YxNBka2y5Y8:b80YsW5KRVY:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=YxNBka2y5Y8:b80YsW5KRVY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=YxNBka2y5Y8:b80YsW5KRVY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/YxNBka2y5Y8" height="1" width="1"/&gt;</content><link rel="related" href="http://googleblog.blogspot.com/2010/01/new-approach-to-china.html" title="Google's New Approach to China - My Initial Reaction" /><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/2597157927330063475/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=2597157927330063475&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/2597157927330063475?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/2597157927330063475?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/YxNBka2y5Y8/googles-new-approach-to-china-my.html" title="Google's New Approach to China - My Initial Reaction" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2010/01/googles-new-approach-to-china-my.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEcARX8-fSp7ImA9WxBQE08.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-1403249345961173121</id><published>2010-01-12T13:54:00.000-06:00</published><updated>2010-01-12T13:54:04.155-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-12T13:54:04.155-06:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SIEM" /><title>The 2010 SIEM Winter Olympics Preview</title><content type="html">A "point in time" snapshot of how I think 2010-2012 looks in the SIEM Market.  A much more detailed analysis will be available soon (on request).&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_7cKexWoDNAg/S0zMsXtyXOI/AAAAAAAAAFY/Wj7GQIO0DA4/s1600-h/2010+SIEM+Olympics+Preview.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_7cKexWoDNAg/S0zMsXtyXOI/AAAAAAAAAFY/Wj7GQIO0DA4/s400/2010+SIEM+Olympics+Preview.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
Some highlights of the preview:&lt;br /&gt;
1. Many companies are focused on rationalizing recent acquisitions or focusing on making their current product scalable and/or bullet-proof.  I think that this is absolutely crucial for these organizations but it does create an opportunity for ArcSight to further separate from the pack in 2010.&lt;br /&gt;
&lt;br /&gt;
2. Formally "niche" players are taking the lead in 2010.  Q1, Tenable, Nitro all have a legitimate change to overtake their peers in terms of functionality and more importantly marketplace.  Each has their own approach, all are led by very capable teams - I'm interested to watch and see what the market does with these three.&lt;br /&gt;
&lt;br /&gt;
3. I don't expect all of these SIEM players to survive to the 2012 Winter Olympics.  In fact, I'd guess at least three of them will be consumed or fail completely.  Many have other products that have helped them sustain, but not necessarily grow when compared to SIEM competition.  &lt;br /&gt;
&lt;br /&gt;
4. Most of the larger organizations have had serious setbacks with their acquisitions in this space.  Based on functionality limitations and these organizations losing significant market share I expect some of these organizations to take a serious look at replacing those products (or portions of the products) with more competitive options in the market today.&lt;br /&gt;
&lt;br /&gt;
5.  SIEM will certainly grow into interesting areas in the next 24 months as vendors look toward cloud based solutions, supporting virtualized systems and networks, and as more mature users push these products to solve problems other than the basic Security Operations and Compliance based Use-Cases.&lt;br /&gt;
&lt;br /&gt;
6.  I do expect the larger picture to come in focus around SIEM soon.  RSA's acquisition of Archer is indicative of things to come.  The larger companies are focused on presenting Enterprise Risk to the business and not just speeds and feeds anymore.  Certainly better reporting, integration with enterprise apps and usage of other technologies will continue to evolve but I believe it will finally be centered on the user's functional purposes and not just marketing hype.&lt;br /&gt;
&lt;br /&gt;
7.  SIEM also needs to evolve downward as well.  Yes positioning relevant information upward in the business is the ultimate goal, but we can't forget the analyst.  The SIEM must continue to support the analytical needs of its core user base.  Deeper integration with other analytical tools and resources (Content Inspection, CMDB, Custom DB's, etc) and facility that interaction intuitively.&lt;strike&gt;&lt;strike&gt;&lt;/strike&gt;&lt;/strike&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-1403249345961173121?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/_onNTrz_-MaDBPwlrqlj9WcEzJg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_onNTrz_-MaDBPwlrqlj9WcEzJg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/_onNTrz_-MaDBPwlrqlj9WcEzJg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_onNTrz_-MaDBPwlrqlj9WcEzJg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=aqQFXnYVphI:HuuOuLRXsCY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=aqQFXnYVphI:HuuOuLRXsCY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=aqQFXnYVphI:HuuOuLRXsCY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=aqQFXnYVphI:HuuOuLRXsCY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=aqQFXnYVphI:HuuOuLRXsCY:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=aqQFXnYVphI:HuuOuLRXsCY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=aqQFXnYVphI:HuuOuLRXsCY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/aqQFXnYVphI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/1403249345961173121/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=1403249345961173121&amp;isPopup=true" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/1403249345961173121?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/1403249345961173121?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/aqQFXnYVphI/2010-siem-winter-olympics-preview.html" title="The 2010 SIEM Winter Olympics Preview" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_7cKexWoDNAg/S0zMsXtyXOI/AAAAAAAAAFY/Wj7GQIO0DA4/s72-c/2010+SIEM+Olympics+Preview.png" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2010/01/2010-siem-winter-olympics-preview.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUASHYzfyp7ImA9WxBRGEQ.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-4517987330828530434</id><published>2010-01-07T14:29:00.000-06:00</published><updated>2010-01-07T14:30:49.887-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-07T14:30:49.887-06:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Rocky" /><title>A week in and 2010 already has been a year of significant changes</title><content type="html">Personally,  I'll count 2009 as the year of lessons learned.  I'm happy to start 2010 and begin anew.  Many of you have reached out to me in twitter (@rockyd) or email, FB, etc and asked about my status, personally and professionally - for which I'm very thankful.  It is awesome to see some many people and organizations genuinely care about me - I'm humbled.  We did make some changes late in 2009 that for all intents and purposes brought an end to Decurity as it was known.  The full plan never quite panned out the way we all hoped it would.  I joined EMC/RSA for a while and worked alongside some fantastic people over there, but in the end it just wasn't the right place for me.  I resigned my position at RSA and took some time off to focus on my family, my health and to renew myself so that I could focus fully in 2010 and beyond.   &lt;br /&gt;&lt;br /&gt;Personally: I had let myself get way out of shape (mentally, spiritually and physically) and let my blood sugar reach levels that truly frightened everyone.  I thought I was just more sweet, but when doctors start wondering why you're not in a coma it's time to pay attention.  I joke about it a lot but I've learned to pay much closer attention now.  Eventually, I hope to make it to P90X type workouts but for now I'm happy to be able to walk a few miles, a few times a week.  It sucks when there is no one else to blame but yourself, but then again I know I can change my habits easier than trying to make many orgs think clearly about how to handle security risks.&lt;br /&gt;&lt;br /&gt;Professionally:  I'm currently in the midst of considering some fantastic opportunities from various organizations that have reached out to me. I can't tell you how lucky I feel to have so many believe in me.  I'm delaying making a final decision until I'm a little healthier (should only be a few days).  I want to ensure that whichever route I take it makes sense for me, the company, their user-base and the segment of the security industry I can influence.   I'll let everyone know where I wind up once things settle down.&lt;br /&gt;&lt;br /&gt;Another Note:  I'm moving my personal blogging efforts over to securityoperations.blogspot.com.  I'll probably dual post for a while as Decurity's blog has much more critical mass, but I'd imagine I'll keep up with securityoperations.blogspot.com more often from now on.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-4517987330828530434?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/GDQlxvfHo4MHf9LTF9EPE4x6ZsE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GDQlxvfHo4MHf9LTF9EPE4x6ZsE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/GDQlxvfHo4MHf9LTF9EPE4x6ZsE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GDQlxvfHo4MHf9LTF9EPE4x6ZsE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=pA3apBOiiP4:m89LJ64aaa0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=pA3apBOiiP4:m89LJ64aaa0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=pA3apBOiiP4:m89LJ64aaa0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=pA3apBOiiP4:m89LJ64aaa0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=pA3apBOiiP4:m89LJ64aaa0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=pA3apBOiiP4:m89LJ64aaa0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=pA3apBOiiP4:m89LJ64aaa0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/pA3apBOiiP4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/4517987330828530434/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=4517987330828530434&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/4517987330828530434?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/4517987330828530434?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/pA3apBOiiP4/week-in-and-2010-already-has-been-year.html" title="A week in and 2010 already has been a year of significant changes" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2010/01/week-in-and-2010-already-has-been-year.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0UMQXgyfyp7ImA9WxBRGUs.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-8816802556435448627</id><published>2009-12-04T13:09:00.001-06:00</published><updated>2010-01-08T10:48:00.697-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-08T10:48:00.697-06:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Rocky" /><title>FUDSEC Guest Post</title><content type="html">I was asked to provide a guest post for the FUDSEC Blog.  After reading so many of the other guest posts I felt a little overwhelmed to put my ramblings alongside those gems.  I'm thrilled Craig allowed me the opportunity and look forward to hearing your input.  Please enjoy ripping my thoughts into pieces, chewing on them and then letting me know how you really feel!&lt;br /&gt;
&lt;a href="http://fudsec.com/liberate-yourself-change-the-game-to-suit-you" title="FUDSEC: Liberate Yourself: Change The Game To Suit Your Needs"&gt;FUDSEC: Liberate Yourself: Change The Game To Suit Your Needs&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Comments are encouraged directly on FUDSEC or you can reach me on Twitter (@rockyd) or reach me on this Blog any way you chose to reach out I'd love to hear your input.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ORIGINAL TEXT FROM FUDSEC.COM POST FOLLOWS:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
December 4, 2009&lt;br /&gt;
Liberate Yourself: Change The Game To Suit Your Needs&lt;br /&gt;
&lt;br /&gt;
I'm very pleased to have Rocky as this weeks "Fudsec Friday" guest.  I've had the pleasure of meeting Rocky in a business context.  I quickly came to appreciate he is one of the minority: an information security professional providing true insight and solutions based on real world experience of what works.  To put it simply, Rocky "gets it".  If you read just one blog post today, read this one.  Thanks Rocky!&lt;br /&gt;
&lt;br /&gt;
By Rocky DeStefano&lt;br /&gt;
&lt;br /&gt;
Recently, I was fortunate enough to have the opportunity to listen in on a speech from General Hayden (former Director of the NSA and CIA, in addition to his service as a four star general in the US Air Force).  This man has executed at a level most of use only see through fiction writers and movies and he has done so for 30 + years.  I provide that backdrop only to say that when General Hayden speaks, I not only listen, I listen intently and replay his words and overall sentiment in my head very carefully.  What he said at this event was encapsulated very well by Richard Bejtlich in this blog post so I won’t go into all the areas described in this post.  In short, General Hayden’s speech sparked some long-dormant thought in my feeble brain.  His thoughts energized me to refocus my thoughts and actions to go beyond the day-to-day struggles we constantly fight.  I was stuck in a rut and didn’t even realize it.&lt;br /&gt;
&lt;br /&gt;
In order to navigate our world and interact with it and one another, we as humans had to learn to fly, we had to learn to navigate the oceans, and we had to learn to overcome distances and difficult terrain, by creating solutions to work with the landscape.   We’ve done something quite unique though, we created a new terrain and new domain.  The domain we’ve created is fundamentally different while at the same time it is every bit as tangible as the natural domains we exist in.  The difference is that this information domain is of human ingenuity and therefore in addition to building tools to work within the landscape, we can actually alter the landscape as we see it.  This information domain also exists separately as its own entity and as such evolves at a rate much different than the physical domains.  Perhaps most importantly this information domain evolves, dies or otherwise is influenced based on our human interactions.  It is moldable.  Sure I can agree that humans might affect the temperature of the planet every few thousand years by a fraction of a degree, but we can fundamentally change our information domain on a daily basis if we chose to.   Think about it, we all know that, it isn’t new, but at the same time it’s quite liberating to think about the fact that we can change the entire game to suit our needs, versus playing by rules we can’t change or worse yet play in an environment that highlights the strengths of our adversary.&lt;br /&gt;
&lt;br /&gt;
As this domain has evolved we have set in motion a series of evolutionary steps based on tactical requirements without really having a strategic plan for where it should be headed.  We made decisions along the way that were necessary to get us past a hurdle, but without much rational thought about the impact.  To put it simply there is no city planning going on.  We’re continually developing “solutions” to meet short term needs.  Granted these are real needs, no question, but who is providing the strategic vision of how our decisions will affect how we interact in the future?  For far too long we have applied “fixes” that fit the bounds of the information domain as it exists today.  It is time to start looking at how we can transform the domain itself to more appropriately suit our needs moving forward.  I’m convinced we are in the very earliest of stages in the evolution (perhaps on the doorstep of revolution) with regard to this domain, but unlike evolution on the natural plain this domain can’t and won’t change itself, we must act to influence it to better meet our needs.&lt;br /&gt;
&lt;br /&gt;
Much to my own amusement I see this domain much like a scene from a kids movie - when Jafar turns is transformed into genie in Disney’s Aladdin and he boasts something like “The Power, The absolute Power, The universe is mine to command, to control, to create” and we get it without the constraint of living in a bottle.  The constraints that apply only exist in our minds and actions.  We need to get out of the mindset of applying protection techniques based on physical realms and focus on evolving the entire environment to better suit our needs moving forward.&lt;br /&gt;
&lt;br /&gt;
I’m certain as we start this dialogue that more fundamental aspects will arise – which is exactly what I hope to elicit from this dialogue but here his where my current thought process has lead me to consider with regards to how to step out of our box and move our eyes towards the horizon.  I’ve bundled my thoughts into a few categories, leadership, research and information sharing.   I’m sure your thoughts will help us all to refine this into much more!&lt;br /&gt;
&lt;br /&gt;
Leadership:  I’ve come to realize that there is no one coming to save us from ourselves here.  No government czar, compliance initiative, nor vendor product suite is going to pave the way.   Homeland Security, NSA, Military, Congress, The White House – they’ll all continue to play their part, but let’s be honest here they have not and should not drive the overall thought process here.  We must all define how we chose to exist in this domain.&lt;br /&gt;
&lt;br /&gt;
Certainly we should encourage government and legal involvement along the way so that they can contribute as appropriate.  In the end the government should be involved to enable us to succeed in this domain, not to define how it should be crafted – at least not without our agreement.  Yet we wait the announcement of the all mighty czar… it’s crazy.  I believe that we can lead from right here, wherever here happens to be.  There are dozens of examples, but I chose just a few to highlight some of the decisions we’ve made and how we can start making better ones moving forward.&lt;br /&gt;
&lt;br /&gt;
1. Information Security Leadership.  We need to start pushing back at all levels here.  It’s my opinion that business’s need to care much less about being compliant and more about being fundamentally secure – or if you prefer having better visibility into real risk.  Risk to the mission, risk to the business not the risk to an asset.  We continue to create irrelevant measurements – irrelevant because they are point in time, against a less-than secure model and on a playing field that is skewed towards the success of our adversary. &lt;br /&gt;
&lt;br /&gt;
As information security professionals how on earth did we let the primary financial driver for security spending be compliance initiatives?  We sold our souls because we lacked the knowledge of the business and how to apply what we do in a meaningful way to the business.  We let compliance initiatives that promised “measurable” results have their way because we thought we could tag along for the ride and implement best possible solutions given the situation. As I see it we are no better off for this and now our teams have either competing agendas or more work to drive us away from protecting our organizations. Sure we’ve created some “building codes” but do “point in time” snapshots matter anymore when the attacker can mold his approach on a whim?&lt;br /&gt;
&lt;br /&gt;
Partners, Vendors play a critical role in helping us reach our goals; they should also play a role in the thought leadership moving forward. Product and solution vendors have done a great job in developing solutions to meet our defined needs along the way as we’ve evolved in our usage of information systems.  We’ve all witnessed some seriously cool steps forward over the last 15-20 years, but recently many of those solutions have been evolutionary in nature, not necessarily innovative, but more and more they are band-aid fixes for problems we’ve encountered or realized.  &lt;br /&gt;
&lt;br /&gt;
Don’t get me wrong it is a very necessary evolution, but we’ve hit a point that we need to start thinking about long-term health and welfare of how we interact as humans.  We need to find ways to encourage that vendor thought leadership onto a larger more strategic problem-set.  I would encourage those customer facing people with consulting and/or vendor organizations to take a very basic consultative approach on a daily basis: listen to your customer’s actual needs, not always what they state as a need (PCI Compliance, etc) but to the goals they are really trying to solve and communicate those findings inwardly to your organization (and in general terms externally to the community).  The more inputs for this information stream the more refined the thought process can be.  You can’t imagine the amount of information that some of these folks have in their heads they just haven’t been heard appropriately.   &lt;br /&gt;
&lt;br /&gt;
To those that manage consultants - please encourage your staff to listen and enable meaningful communications, in fact I would challenge you to incentive your staff to provide this input.  Give them the opportunity to buy in to more than just a single technology, but into solving a much greater problem.  This may mean some major internal change in thought about how to approach management of teams, customer engagements, support, product development, etc – that’s exactly the point – we need to learn to listen better to the larger picture and not the point in time snapshot.   &lt;br /&gt;
&lt;br /&gt;
Those were two very basic examples of how we can lead from wherever we sit in the organization there are literally thousands of other examples out there.   I hope you can see that I’m suggesting leadership by example – you can still enable business using these techniques, you just have to get past “the way its been done”. &lt;br /&gt;
&lt;br /&gt;
2. A key component in moving forward has to be a dedicated focus on Research and Development.  I mean significant investment in R&amp;D on a national and international scale, information sharing about current and proposed strategies across industries, etc.  We need to be pushing our employers, VC’s, governments into broader research initiatives.  We need an innovation revolution at this point, not just evolutionary point solutions. &lt;br /&gt;
&lt;br /&gt;
There are some very recent initiatives that show promise, like the announcements by Northrop Grumman that NG is sponsoring information research in conjunction with Carnegie Mellon, The Massachusetts Institute of Technology and Purdue University.&lt;br /&gt;
&lt;br /&gt;
If you will, think of these research opportunities as form of health care for our future, I don’t care how it’s justified but we need to act in support of efforts like this in every way we can, perhaps by offering state or federal tax credits?  Certainly I can agree that we need to watch spending and as such we should have to pay for performance, but we need to encourage strategic innovation versus tactical evolution (band-aids).  The investment in long-term strategy has been anemic at the federal level.  We’ll spend millions on watching the effect of gnat bites on mouse nuts, but we haven’t found the necessary stomach to pay for the ability to effectively comprehend where we’re headed as a species as it relates to communications, business and everyday life. &lt;br /&gt;
&lt;br /&gt;
3. Perhaps the most immediate thing we can influence is better Information Sharing.  We need to start thinking about how we can change the IT Domain into something that allows for a level playing field.   The old adage “The enemy of my enemy is my friend” applies very well here.  It’s ridiculous to think that our teams are better off not talking with industry competition about defensive strategies. The other side is free to share, adapt and overcome as they see fit, yet we tie our own hands and ask for beatings – and hope they don’t hurt too much.  I’m really not into S&amp;M.  I’d rather retake control – how about you?&lt;br /&gt;
&lt;br /&gt;
A few good examples to learn from already exist, the Defense Industrial Base (DIB) has an information sharing related to APT (Advanced Persistent Threat) detection profiles, and workshops like SANS “What Works” or IANS Summits are a great beginning to this conversation,  but in reality they are very limited in reach and only relevant at a point in time.  We need to develop more daily interaction at a deeper level.&lt;br /&gt;
&lt;br /&gt;
Summary:  I’m in no way suggesting I’m intelligent enough to have all the answers, or to have even fully described the problems, I’m simply stating that we need to elevate our thinking and we must invest in the thought process and commit to the information sharing required to make the decisions necessary so that we may shape our own destiny.  As I see it we must all act on the relevant fronts (Leadership, Research, Information Sharing, others?) to better comprehend the changes and position ourselves to be able to make the changes necessary in the future.  That’s my starting point, how will you enhance the conversation?&lt;br /&gt;
 &lt;br /&gt;
Disclaimer:&lt;br /&gt;
The opinions expressed here are my personal opinions. My views and opinions are subject to change based on the input I consume and the analysis I apply to those inputs.  Content published here is neither read nor approved in advance by my employer and does not necessarily reflect the views and opinions of my employer.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-8816802556435448627?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/tjg_QGbA4qUit3qvxswJB7bkvak/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tjg_QGbA4qUit3qvxswJB7bkvak/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/tjg_QGbA4qUit3qvxswJB7bkvak/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tjg_QGbA4qUit3qvxswJB7bkvak/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=SGm7QZdiD8g:SFEhgxraBqQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=SGm7QZdiD8g:SFEhgxraBqQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=SGm7QZdiD8g:SFEhgxraBqQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=SGm7QZdiD8g:SFEhgxraBqQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=SGm7QZdiD8g:SFEhgxraBqQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=SGm7QZdiD8g:SFEhgxraBqQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=SGm7QZdiD8g:SFEhgxraBqQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/SGm7QZdiD8g" height="1" width="1"/&gt;</content><link rel="related" href="http://fudsec.com/liberate-yourself-change-the-game-to-suit-you" title="FUDSEC Guest Post" /><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/8816802556435448627/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=8816802556435448627&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/8816802556435448627?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/8816802556435448627?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/SGm7QZdiD8g/fudsec-guest-post.html" title="FUDSEC Guest Post" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/04/fudsec-guest-post.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUIHRXY_cSp7ImA9WxBRGEQ.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-9053660402475159638</id><published>2009-10-27T13:45:00.000-05:00</published><updated>2010-01-07T13:45:34.849-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-07T13:45:34.849-06:00</app:edited><title>Low Level Information Collection</title><content type="html">This morning as my wife was leaving for work she noticed a extended cab pickup truck parked out in front of our neighbor's house.  As she began to pull out of the driveway she noted that the driver got out and was beginning to go through the neighbors trash.  My wife parked at the end of the street and then called me.  I dismissed it at first but as I observed for a few moments I was amazed at how thoroughly this gentleman was going through each bag.  His urgency and purpose was like he was looking for a lost wedding ring.&lt;br /&gt;&lt;br /&gt;Needing something to do today I walked up to him and inquired about what he was doing.  Obviously and physically taken aback by me confronting him, he  produced a toy out of his pocket and told me he "wasn't doing anything" that he was just looking for toys and gave me a sheepish grin.  My kids do a much better job of acting.&lt;br /&gt;&lt;br /&gt;Given the nature of the truck (at 50K+ it was probably either his employer's or stolen), the fact their was no car seat was in it, his "look-out",  and his overall demeanor I pressed a little harder.  I asked him about the pile of papers he was so carefully gathering.  Of course all of the sudden his knowledge of the english language ceased to exist and he was in a hurry to leave.  In spanish he yelled to his wife to get ready to go and that he didn't like the situation.  So I switched to spanish and surprised him even further.  I was able to retrieve the papers from him before he ran into his truck that his wife was starting to drive away in.   Damn,  I was just starting to have fun with him, well at least the cops should be able to retrieve the stolen truck pretty quickly.&lt;br /&gt;&lt;br /&gt;I'm fully cognizant of the fact that financially times are hard right now and people need to do what they can to survive.  I'm not against him looking for toys or taking broken household equipment to repair or any number of other things that people quickly retrieve from others discarded household items.  I'm very leery of how organized and thorough this team was.  1. The vehicle fit into it surroundings, except we live on a cul-de-sac with very low traffic.  2. He had an obvious "look-out" who was intently watching my wife  3. He dissected every bag, quickly and efficiently 4. Timing - he hit the garbage in the two hour window it sits outside.&lt;br /&gt;&lt;br /&gt;Yes I'm probably paranoid but I can almost guarantee that this team worked as part of a larger organization paid by the pound of paper they collect or otherwise compensated for what they found.  It's highly lucrative, insulates upper layers and incredibly simple to execute.  It could have been a precursor to a physical intrusion, but honestly that's not going to nearly as lucrative as the identify theft angle.  &lt;br /&gt;&lt;br /&gt;Recommendations:  &lt;br /&gt;&lt;br /&gt;1. Be aware of your surroundings.  If it seems out of place - find out why.  At a minimum observe and report to your local police department. &lt;br /&gt;&lt;br /&gt;2. Shred everything, no matter how "insignificant" it is.  If I'm honest with myself 've been horrible about this at home.  I have a shredder two feet from me that is going to be fed well today! &lt;br /&gt;&lt;br /&gt;3. Carefully screen who you let in your home.  Technicians, Cleaners, Painters.  There are so many ways to extend this type of collection activity it isn't even funny.&lt;br /&gt;&lt;br /&gt;4. Talk with your neighbors.  It's much easier if everyone is fully aware of what is going on and can help observe and act as necessary.  You can also get trusted recommendations for service help.  Plus the holidays are coming - just go out and be nice.&lt;br /&gt;&lt;br /&gt;5. Check your credit report from all three major players every month.  The odds are that your identity or at a minimum your credit/bank account will be compromised at least once.    The quicker you can identify it the easier the mess is to clean up.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-9053660402475159638?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/zvXnvX2c4Nx5H564MFZBgScRbW0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zvXnvX2c4Nx5H564MFZBgScRbW0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/zvXnvX2c4Nx5H564MFZBgScRbW0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zvXnvX2c4Nx5H564MFZBgScRbW0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=cztfNwGzafc:3_BpKQ-q08k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=cztfNwGzafc:3_BpKQ-q08k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=cztfNwGzafc:3_BpKQ-q08k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=cztfNwGzafc:3_BpKQ-q08k:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=cztfNwGzafc:3_BpKQ-q08k:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=cztfNwGzafc:3_BpKQ-q08k:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=cztfNwGzafc:3_BpKQ-q08k:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/cztfNwGzafc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/9053660402475159638/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=9053660402475159638&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/9053660402475159638?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/9053660402475159638?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/cztfNwGzafc/low-level-information-collection.html" title="Low Level Information Collection" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/10/low-level-information-collection.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0QHQHo8fSp7ImA9WxBQGEQ.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-3815472100697601133</id><published>2009-08-30T13:41:00.001-05:00</published><updated>2010-01-19T04:02:11.475-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-19T04:02:11.475-06:00</app:edited><title>SIEM 201 Use Case Overview</title><content type="html">&lt;b&gt;Part 2 of Decurity's "Back to School" Series:  SIEM 201: SIEM Use Case Definition&lt;/b&gt;  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Course Prerequisites:&lt;/b&gt; A while back I published a diagram and associated text illustrating the benefits of a &lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_best_practices_combined_log_management_and_siem_architecture_benefits/" title="combined SIEM and Log Management architecture"&gt;combined SIEM and Log Management architecture&lt;/a&gt;. This diagram/post did a good job of explaining the features and functionality of Log Management and SIEM at a very high level. If you haven't seen that post or if you haven’t read &lt;a href="http://blog.decurity.com/index.php/dec_template/more/BacktoSchool_SIEM_101/" title="Decurity's SIEM 101 "&gt;Decurity's SIEM 101 &lt;/a&gt;previously I would encourage you to go back and take a look. Basic concepts from those resources will help in understanding of Use-Cases and how they apply to SIEM .&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Introduction:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
In my experience I’ve noticed that SIEM customers use something like 30% of less of the functionality of the tool they bought. That number is actually probably pretty high when you consider the fact that a very high percentage of customers are only using the default content that came pre-installed or was "customized" during a professional services engagement. There are some very advanced users out there, no doubt and this post will help them as well, but it is really focused on providing a framework to advance the majority of SIEM users so they can gain better appreciation for how to maximize the value of their SIEM investment.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The process (and diagram) that follows, outlines how Decurity looks at use-cases related to SIEM. We are providing this information in the hopes that you'll internalize it as part of your SIEM operations.  Decurity will also be announcing in the very near future an online solution using this methodology so that you can track/update/share your use-cases/solutions - contact us if you're interested in learning more about that solution. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Use-Case Requirement:&lt;/b&gt; &lt;br /&gt;
The most simplistic advice I can give is that you should try to focus on the output first.  What is the point of the work effort?  What is the problem we are trying to solve? What is the intended action/output? Who benefits from this and more importantly why do they benefit from this solution?  Then you can move into questions like - what information is required to solve the problem?  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The information provided in this article will help to guide you through the process.    Implementing solutions in your SIEM in an ad-hoc manner will result in failure or at best very temporary and minimalistic gains.  If you don’t believe me you can ask any of the hundreds of organizations who tried it before you.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Use-Case Illustration:&amp;nbsp;&lt;/b&gt;&amp;nbsp; &lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_7cKexWoDNAg/S1WC-YzZr5I/AAAAAAAAAFk/0PO_G4Gk2zY/s1600-h/siem_usecase2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_7cKexWoDNAg/S1WC-YzZr5I/AAAAAAAAAFk/0PO_G4Gk2zY/s640/siem_usecase2.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;General:&lt;/b&gt;  &lt;br /&gt;
This is the most basic logistical information related to the use-case and related solution.  It provides a documentation framework. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
•    Author: Who was involved in the creation/authoring of the solution? &lt;br /&gt;
&lt;br /&gt;
•    ID, Version and Date: What is the current version and ID and last date of update. &lt;br /&gt;
&lt;br /&gt;
•    Objects, Artifacts: Link to objects (externalized or within solution) used within the solution for example, the configuration objects like report, rules, dashboards, etc.  &lt;br /&gt;
&lt;br /&gt;
•    Solution Description: Quick reference to the solution, using categorization that makes sense for your organization.   &lt;br /&gt;
&lt;br /&gt;
•    References: Corporate or External documents that act as reference material for your use-case and/or solution.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Business Justification:&lt;/b&gt; This is the problem being addressed from a corporate perspective.  One or more Business problems may apply, but each should be documented in some fashion. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
•    Business Problem Description: What are the specific problems that need to be addressed? &lt;br /&gt;
&lt;br /&gt;
•    Business Owner(s): Who owns the actions for output of the system? Who owns relevant Systems, Applications and Data? Who is requesting Assistance?  &lt;br /&gt;
&lt;br /&gt;
•    Business Perspective: Security, Compliance, Risk, Audit, Fraud, Legal, HR, Other? &lt;br /&gt;
&lt;br /&gt;
•    Current Solution: Today how is this problem addressed?  How can it be improved? &lt;br /&gt;
&lt;br /&gt;
•    Expectations: What is it that the business owners expect from the solution? &lt;br /&gt;
&lt;br /&gt;
•    Priority: What is the value of solving this issue, or conversely what is the cost of not solving this issue? &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Technical Requirements:&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
•    Need: Active Statements – “The system shall”, “We have to” *(DO SOMETHING)* Define that something. &lt;br /&gt;
&lt;br /&gt;
•    Action: Action(s) and/or Output(s) required from the system. &lt;br /&gt;
&lt;br /&gt;
•    Actor: Relative to a *(PERSON/TEAM)* &lt;br /&gt;
&lt;br /&gt;
•    Event: Specific scenario(s) to be evaluated.   &lt;br /&gt;
&lt;br /&gt;
•    Context: Relevant environmental conditions.  How does our knowledge of this environment affect how we can refine the analysis and output?  Some examples of context that should be considered are:  Organizational Structure, Business Units, Application and/or Data Categorizations, Network Segmentation, System Configurations, Users, “Hot Lists”, Vulnerability Data, Data/System/User Criticality, other environment specific information. &lt;br /&gt;
&lt;br /&gt;
•    Timing: Within, before, at, during, after. &lt;br /&gt;
&lt;br /&gt;
•    Logic: Boolean Logic Statements (T/F) using AND, OR, IF, THEN, NOT as conditions.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Collection: &lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
•    Data Source(s):  What data sources would provide the best context?  What information do we have already available?   &lt;br /&gt;
&lt;br /&gt;
•    Data Accessibility: Are there physical, logical, business, technical or political barriers to having the relevant data? &lt;br /&gt;
&lt;br /&gt;
•    Data Format: is the data readily comprehended by our solution, is customization of the data necessary or possible?  Do we need to update logging standards? &lt;br /&gt;
&lt;br /&gt;
•    Data Relevance:  &lt;br /&gt;
&lt;br /&gt;
o    Content: What elements of the data provide us the necessary context? Which exact fields are relevant?   &lt;br /&gt;
&lt;br /&gt;
o    Timing: Do we receive it often enough to be relevant to our proposed solution? &lt;br /&gt;
&lt;br /&gt;
•    Data Location: Does the data reside in a centralized, easily accessed location?   Is it already aggregated, normalized or filtered in a way that would adversely affect our proposed solution? &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Note:  You can and should use these questions and related answers as justification for your enterprise visibility project.   Logging Standards, Data Access and reliable access to the information are very often the proverbial “long pole”.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Proposed Solution:&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
•    Technology/Process:  Does SIEM make sense to solve this problem, given the data we have, our environment and the proposed solution?  Can we solve this using other technology or processes in a more efficient/effective manner?  SIEM is great, but not always the answer. &lt;br /&gt;
&lt;br /&gt;
•    Configuration:  What SIEM configuration(s) provide us with the most efficient and effective solution.  Is it simply a report or do we need to leverage advanced meta-correlation?  Does Statistical evaluation help?  Describe possibilities and known variables/obstacles.  Know the capabilities of your product will help you to understand how to configure it. Advanced Use-Cases, Custom Applications, Fraud Detection, etc require a non-traditional data set and logic approach - well at least non-traditional from the security administrator perspective. Having the flexibility to "compare" against user-defined fields is key to solving those use-cases. If you find yourself unable to solve a number of “Core” use-cases then it might be time to consider training, external advice or as a last resort a new solution. &lt;br /&gt;
&lt;br /&gt;
•    Expected Outcome: What is it that we expect to see from the system?  For example  (Within “n” Minutes, we should see “x” when “y” occurs.) &lt;br /&gt;
&lt;br /&gt;
•    Known False Positive:  How are false positives differentiated from known bad activities and how can we tune our systems/data/environment to reduce the number of valid activities we respond to? &lt;br /&gt;
&lt;br /&gt;
•    Known Gaps: Relative to the problem-set described what do we expect that this solution will miss?  How can we close those gaps? &lt;br /&gt;
&lt;br /&gt;
•    Alternative Methods:  Within the SIEM or external to SIEM what are alternative ways to address some subset of this problem?  Do related solutions already exist? &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;QA:&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
•    Performance:  is the solution Efficient?  Does it cause significant system degradation?   Have you built “content” to monitor for efficiency? &lt;br /&gt;
&lt;br /&gt;
•    Functionality: Is this providing an acceptable solution for the users and owners?  Are refinements required? &lt;br /&gt;
&lt;br /&gt;
•    Measurements: Technical effectiveness, Resource Utilization Measurements. &lt;br /&gt;
&lt;br /&gt;
•    Lab Validation:  Were Lab tests meaningful and successful? &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Note:  You might get the sense from my wording that QA is an ongoing activity, you’d be correct.  If you lab has irrelevant data/systems your tests are meaningless.  Testing new correlation scenarios against existing data set is invaluable. Knowing how the system is going to respond before you implement into production saves time, effort and headaches. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Operations:&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
•    Feedback:  You need a periodic feedback loop to ensure you are in touch with their needs and updating/planning around upcoming requirements. &lt;br /&gt;
&lt;br /&gt;
•    Monitor: Changes are inevitable, from process, people, environment to threats and data sets you will need to stay in touch with how your SIEM is supporting the evolving requirements.  &lt;br /&gt;
&lt;br /&gt;
•    Refine: simple refinements may be applied daily/weekly/monthly. &lt;br /&gt;
&lt;br /&gt;
•    Enhance: Do we need to add more/better data sets? Is there better Logic that can be applied? Do new or related use-cases offer better insight? &lt;br /&gt;
&lt;br /&gt;
•    Validations:  What is the “normal” operation look of this use-case look like and how would you know abnormal behavior of your solution?  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Course Summary:&lt;/b&gt;  &lt;br /&gt;
So it should be clear by now that we think SIEM is a great tool, with tons of potential to identify new activities you couldn’t previously consider and to automate “definable” activities and facilitate workflow.  It should also be obvious that SIEM requires planning, testing and ongoing operational support to be most effective for you and your organization.  This guide and related articles/posts will go a long way to assist you with your efforts.  If not, reach out and we’ll find other ways to help you! &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Remember that SIEM is a process not just a tool. If you aren't making changes to your SIEM on a daily basis (or having someone make changes for you) you are not getting the most from your SIEM. Threats constantly evolve, your networks/systems/data/users are always being modified, your understanding of your environment is always changing, shouldn’t your detection techniques also be enhanced on a daily basis? The more time you spend on use-cases as identified in this post the more value you'll receive out of your SIEM. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Disclaimer:&lt;/b&gt;  Not every vendor solves problems in the same manner. Due to technological differences, wildly varying skills of consultants and comprehension of actual problem and/or data you mileage will vary. That said the approach we are documenting here will work with any SIEM and should be used every time you think about solving new problems using your SIEM. It does mean effort has to be applied, but it also means you will have objective measurements of success when it comes to the value your SIEM is providing.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-3815472100697601133?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/1LTba45xcZbzwTsF53qUNrgn_RQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1LTba45xcZbzwTsF53qUNrgn_RQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/1LTba45xcZbzwTsF53qUNrgn_RQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1LTba45xcZbzwTsF53qUNrgn_RQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=QBEufYrO9lU:nU-NrOuo2NQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=QBEufYrO9lU:nU-NrOuo2NQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=QBEufYrO9lU:nU-NrOuo2NQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=QBEufYrO9lU:nU-NrOuo2NQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=QBEufYrO9lU:nU-NrOuo2NQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=QBEufYrO9lU:nU-NrOuo2NQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=QBEufYrO9lU:nU-NrOuo2NQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/QBEufYrO9lU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/3815472100697601133/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=3815472100697601133&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/3815472100697601133?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/3815472100697601133?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/QBEufYrO9lU/siem-201-use-case-overview.html" title="SIEM 201 Use Case Overview" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_7cKexWoDNAg/S1WC-YzZr5I/AAAAAAAAAFk/0PO_G4Gk2zY/s72-c/siem_usecase2.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2010/01/siem-201-use-case-overview.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE8MRX4yeCp7ImA9WxBQE0k.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-5794373277277951785</id><published>2009-08-24T13:40:00.001-05:00</published><updated>2010-01-12T18:34:44.090-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-12T18:34:44.090-06:00</app:edited><title>SIEM 101: an introduction to SIEM functionality</title><content type="html">Just in time for "Back to School" Decurity presents "SIEM 101": An introduction into SIEM functionality.  What is SIEM correlation? What does it deliver? What is the value to a business or organization?  What is aggregation, normalization, prioritization and how do they differ or enable correlation scenarios?&lt;br /&gt;
&lt;br /&gt;
Every SIEM Vendor seems to have a different definition and marketing spiel about the functionality of SIEM “correlation”.  Some times correlation is described in a manner that evokes thoughts of a magic trick, other times it is simply labeled as “too confusing” and therefore not relevant.  Obviously, this causes confusion and an inconsistent expectations, or should I say anticipation, of the results that correlation will (or won’t) deliver. This results in the prospective customer ending up with a skewed perspective and, in all likelihood dissatisfaction.   On the other hand it may also result in the customer not knowing the full extent of the power the solution makes available to them.  Neither situation benefits anyone involved.  The purpose of this posting is to help describe common SIEM functionality so that current and prospective users of SIEM can effectively compare the capabilities of different vendors purporting to support or deliver “correlation”.&lt;br /&gt;
&lt;br /&gt;
Some Basic SIEM Terminology.  Let's start by outlining some basic terminology and functionality included in most SIEM solutions to provide some context. After that, we will be able to dive deeper into what is correlation and its related functionality.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Collection:&lt;/u&gt; Collection refers to the process of obtaining the logged information from various event sources. The “battle” of agent versus agent-less is meaningless should just be ignored as marketing fluff.  Things like network architecture, Network speed/latency, event source platforms, security, compliance and your environment variables all drive the decision of where is the best place to locate an agent/collector to collect information.  It is simply a matter of your use-cases and environment that drive your deployment architecture decisions. &lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Event Sources: &lt;/u&gt; These are the devices/systems that generate events for consideration.  Inclusion of the "right" event sources, logging in the "right" way is absolutely critical to the success of your SIEM.  The SIEM can't consider information that does not exist or is not contextually relevant with other information in the system.  I'll spend more time on this topic in an upcoming "SIEM 201" blog post.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Normalization:&lt;/u&gt; This is the process, at either the collector (agent) or SIEM engine that makes sense of the event data being input into the system. The normalization process tries to map the different log event data formats into a common structure, or taxonomy, or in some cases indices, so that things common fields like names, activity type, timestamps and IP addresses, etc can be quickly compared using a simple taxonomy. Usually this means that the data is more accessible and efficiently stored for the SIEM solution. Each vendor performs this process differently in the background and the level of functionality, intelligence and capabilities associated with the process varies for each vendor, some do it well, some don’t.  Some vendor solutions don’t index/normalize on input into the system, they accomplish this task when the user requests output from the system.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Aggregation: &lt;/u&gt;This process summaries (counts) event data, based on (hopefully) flexible pre-defined fields. The purpose of this process is to reduce the event data load, either in terms of network traffic, data storage and/or SIEM engine efficiency.&lt;br /&gt;
&lt;br /&gt;
A typical example of this process can happen if the following situation is detected:&lt;br /&gt;
1.    "N" number of events&lt;br /&gt;
2.    That contain the same event characteristics&lt;br /&gt;
3.    For a given timeframe&lt;br /&gt;
&lt;br /&gt;
In this situation the aggregation process could send one event record with a count inside it, instead of sending all of the individual event records.  A flexible SIEM solution should allow you to decide which fields are leveraged in the aggregation process, allow you to specify the event field characteristics that must be similar, and what information should be included in the summarized event record. The downside to aggregation, if it is incorrectly configured or designed, is loss of important information (i.e. it could cause more Aggravation then Aggregation.).&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Thresholding:&lt;/u&gt; Some consider thresholding to be correlation.  I consider thresholding to be aggregation with alerting.   “N” events occurred in a sliding time window, then let someone know.  An example of this could be the popular “number of failed logins over a fixed period of time”.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Filtering:&lt;/u&gt; This is the ability to ignore, suppress or block certain event records or messages from being processed or displayed. Some consideration is required if you decide to start suppressing messages or event records. It can be a great way to reduce “noise”, but it is also a very good way to lose very important context from “previously unknown” activities. &lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Intelligent Filtering&lt;/u&gt; is the process by which you forward events from a Log Management device to a SIEM on a per Use-Case basis. Ensuring the full data set is fully searchable and easily available within the overall solution, without overloading the SIEM. Keeps costs down, increases efficiency and enhances solution value.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Simple Prioritization:&lt;/u&gt; This is the process of mapping of the message priority, assigned by a particular event source vendor, for an event record to the SIEM's message priority.&lt;br /&gt;
For example, IDS vendor "X" assigns an event with a priority of "1a". The mapping process takes this value and translates it to the SIEM Vendor's priority field and assigns a value of "10" which indicates that the priority is "High/Critical".  All similar events will always have similar priority. This functionality is typically mapped at the agent/collector, but can also be accomplished at the engine depending on the Vendor.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Advanced Prioritization:&lt;/u&gt; This is similar to simple prioritization, with the addition of context from the environment or from how SIEM has been configured. This offers more dynamic prioritization model for similar type events. An example is a priority schema that takes into account, current Vulnerability information for a targeted asset. If the target has a relevant vulnerability and a corresponding IDS Event is received, then the priority of the alerts is raised (it is relevant).  On the other hand, if the vulnerability (or system) does not exist, then the priority is reduced to "Informational", for this particular event. This functionality is typically performed at the SIEM Engine. This is one way to highlight known-bad activity and help prioritize workflow.  Advanced prioritization might be considered a form of very basic correlation by some.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Ok with that in mind, what is Correlation?&lt;br /&gt;
&lt;br /&gt;
As I see it correlation included the evaluation of collected data by using one or more of the following methods:&lt;br /&gt;
&lt;br /&gt;
(1) Pre-defined pattern matching&lt;br /&gt;
(2) Statistical analysis (anomaly detection)&lt;br /&gt;
(3) Basic conditional Boolean logic statements&lt;br /&gt;
(4) Contextually relevant and/or enhanced data set + Boolean logic&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Correlation output&lt;/u&gt;:  the goal of event correlation is to produce a meaningful ”event of interest” that is intended to create output for use by either other correlation criteria, or to influence and/or directly enable workflow creating actionable output (potential incident identification).&lt;br /&gt;
&lt;br /&gt;
Meaning either&lt;br /&gt;
(1) You have a higher degree of confidence that something bad has happened or,&lt;br /&gt;
(2) You now know something that you did not or could not know previously.&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additional functions used within Correlation:&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;Comparison List/Capability:&lt;/b&gt;&lt;/u&gt;  IP, Subnet, ASN, Domain Names, File Names, MAC Address, User names, Event IDs, Custom Attributes, etc. Being able to dynamically update and/or query these lists with or without Boolean logic allows your correlation scenarios to include "fresh" information all the time. Linking lists allows for even more flexibility in prioritization of events. Events can move between lists based on thresholding or other learned context. Move from suspicious to malicious or from malicious to normal based on how correlation scenarios are defined.  Decurity’s Threat Intelligence Offering keeps these current for you!&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;SIEM Boolean Logic:&lt;/u&gt; True/False and the use of IF, THEN, AND/OR, NOT variables.  This is the process where you articulate your logic statements.  More on this in the “201” blog post coming soon.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Statistical Evaluation:&lt;/u&gt; In my mind this is by far the most underutilized component of some SIEM solutions. Anomaly detection, Thresholding and even comparison can be accomplished in a very scalable and in most cases a low overhead manner using the correct set of statistical evaluations. The output of these evaluations can also be "events" for comparison is advanced correlation scenarios.  Expert usage only.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Contextual Comparison: &lt;/u&gt;Vulnerability Info, System (Computer or Network Node) Information, Application Information, User Information, or other categorized attributes describing how the network, systems, users, applications or data are used and/or organized.  The more context added to each correlation scenario the more refined (and meaningful) the output will be. In most cases, if accomplished correctly it also means the most efficient use of system resources.  A Simple example could be defining assets with PCI, PII relevance. &lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Meta Correlation: &lt;/u&gt;Using SIEM enhanced data from previously/currently correlated events to form new correlation scenarios. This can also use the output of Statistical evaluations. The meta-correlation can be between previous correlated events and new event stream data or multiple previous correlated events.  This is also how many systems handle basic scalability or higher tier deployment scenarios.  A baseline of content is deployed at lower tiers and matching events are forwarded upward for inclusion in “enterprise-wide” correlation scenarios. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Summary:&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
Correlation is a very powerful SIEM functions that can help you refine the identification of anomalous or malicious activity.  If your (the customer) can articulate your use-cases clearly, then most vendors can find a way to solve the defined problem using existing functionality within their product set.  It is my hope that you will be able to use this blog post as a way to map the various solution offerings to a common and understandable taxonomy so you can fully comprehend what you are getting with each solution. &lt;br /&gt;
&lt;br /&gt;
In the next post in this "Back to School" series (SIEM Correlation 201) we’ll talk about Use Case Definitions, Event Sources, Performance Impact, Flexibility and Scalability.&lt;br /&gt;
&lt;br /&gt;
"ring, ring" class dismissed until next week.&lt;br /&gt;
&lt;br /&gt;
-Rocky&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-5794373277277951785?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/R9udDbjxqzokNcjjemNAe_7_YKc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/R9udDbjxqzokNcjjemNAe_7_YKc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/R9udDbjxqzokNcjjemNAe_7_YKc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/R9udDbjxqzokNcjjemNAe_7_YKc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=QJqz-XTK3cM:prsrkWx2G_Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=QJqz-XTK3cM:prsrkWx2G_Q:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=QJqz-XTK3cM:prsrkWx2G_Q:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=QJqz-XTK3cM:prsrkWx2G_Q:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=QJqz-XTK3cM:prsrkWx2G_Q:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=QJqz-XTK3cM:prsrkWx2G_Q:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=QJqz-XTK3cM:prsrkWx2G_Q:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/QJqz-XTK3cM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/5794373277277951785/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=5794373277277951785&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/5794373277277951785?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/5794373277277951785?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/QJqz-XTK3cM/just-in-time-for-back-to-school.html" title="SIEM 101: an introduction to SIEM functionality" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/08/just-in-time-for-back-to-school.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUUHSHY9fyp7ImA9WxBRGEQ.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-8928989075347331634</id><published>2009-07-27T13:39:00.000-05:00</published><updated>2010-01-07T13:40:39.867-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-07T13:40:39.867-06:00</app:edited><title>Collection: Complete network awareness is finally an emerging market.</title><content type="html">Recent vendor press releases by NitroSecurity and NetWitness highlight the evolving requirement for full network packet collection, indexing and reconstruction for analysis.  These products and others (including Solera Networks) illustrate an emerging market in total network awareness.  Working in conjunction with Log Management (LogLogic, Splunk, ArcSight Logger, etc) and SIEM tools (RSA, EiQNetworks and of course ArcSight ESM) these tools provide invaluable insight into your network's behavior (not to mention the behavior of individual users and applications over the network).  NitroSecurity updated their capabilities to include what they term as "content aware SIEM" and NetWitness announced a milestone of 15,000 active users.  Both press releases highlighted quotes from Decurity, which we appreciate, but more important to us, the emergence and rapid growth of this market segment add further credibility  to Security Professionals having all of the right tools and information available.  Recent news about DHS Einstein and NSA Tutelage technologies also point towards an increased trend in better, more capable Collection tools.&lt;br /&gt;&lt;br /&gt;Security Operations and Incident Response capabilities can't continue to function in the dark and be expected to adequately protect the enterprise.  We need to make all of the applicable information available and apply intelligent analytical techniques against the data set so that we can more rapidly and accurately identify risks to the enterprise.  These tools when used properly can reduce analytical time required to identify incidents into time segments measured in seconds and can help understand the scope of the incident much more rapidly.  You can review the artifacts (documents, files, audio, video, web, email, chat, as well as interactive sessions (ftp, telnet, ssh, etc)) instantly and determine the legitimacy of the session.  You can extract information and search log management/SIEM for related events and set up alerts and workflow along the way.  All in a matter of clicks.  Of course you can accomplish the reverse and search for anomalies identified in SIEM/Log Management or IDS/IPS in your Network Awareness tool and understand quickly what occurred.  With this level of information available to you, the limitations of the they of analysis have more to do with the level of expertise of the user/analyst than the information.&lt;br /&gt;&lt;br /&gt;These use of these tools in the right hands allow for much more than just security "alerts" and incident identification.  They lend themselves to true security convergence concepts and overall enterprise intelligence and security operations.  More on those concepts over the next few months.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;References:&lt;/i&gt;&lt;br /&gt;NetWitness "July 27, 2009 | Security Experts Worldwide Rely Upon NetWitness® Investigator " Link: &lt;a href="http://www.netwitness.com/resources/pressreleases/Jul272009.aspx" title="http://www.netwitness.com/resources/pressreleases/Jul272009.aspx"&gt;http://www.netwitness.com/resources/pressreleases/Jul272009.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;NitroSecurity "NitroSecurity Heightens Enterprise Security Information Management with Real-Time Application Content and Protocol Analysis" Link: &lt;a href="http://www.nitrosecurity.com/information/news/pr/2009/20090722.psp" title="http://www.nitrosecurity.com/information/news/pr/2009/20090722.psp"&gt;http://www.nitrosecurity.com/information/news/pr/2009/20090722.psp&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Decurity Blog:  Dec 2008:  &lt;a href="http://blog.decurity.com/index.php/dec_template/more/netwitness_investigator_summary_1/" title="http://blog.decurity.com/index.php/dec_template/more/netwitness_investigator_summary_1/"&gt;http://blog.decurity.com/index.php/dec_template/more/netwitness_investigator_summary_1/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-8928989075347331634?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/E0Z78urj1Rlv_ftIrFBIjC1AF5A/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/E0Z78urj1Rlv_ftIrFBIjC1AF5A/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/E0Z78urj1Rlv_ftIrFBIjC1AF5A/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/E0Z78urj1Rlv_ftIrFBIjC1AF5A/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Rr4YC9C4KGM:_e5xe18Ka90:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Rr4YC9C4KGM:_e5xe18Ka90:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=Rr4YC9C4KGM:_e5xe18Ka90:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Rr4YC9C4KGM:_e5xe18Ka90:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Rr4YC9C4KGM:_e5xe18Ka90:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Rr4YC9C4KGM:_e5xe18Ka90:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=Rr4YC9C4KGM:_e5xe18Ka90:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/Rr4YC9C4KGM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/8928989075347331634/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=8928989075347331634&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/8928989075347331634?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/8928989075347331634?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/Rr4YC9C4KGM/collection-complete-network-awareness.html" title="Collection: Complete network awareness is finally an emerging market." /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/07/collection-complete-network-awareness.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QDQXk6fip7ImA9WxBRGUs.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-6136114156852575360</id><published>2009-07-02T10:48:00.001-05:00</published><updated>2010-01-08T10:49:30.716-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-08T10:49:30.716-06:00</app:edited><title>NSA, USCERT, EINSTEIN, TIC, Telecom Providers and the Future of Government Information Security</title><content type="html">Today Ellen Nakashima of &lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2009/07/02/AR2009070202771.html" title="The Washington Post published an article"&gt;The Washington Post published an article&lt;/a&gt; about DHS USCERT, NSA and Telecommunications providers collaborating to monitor Civilian Agency Internet traffic using DHS's planned Einstein 3 tool to help defend these civilian government entities.  The article correctly illustrates that NSA has the expertise and tools like Tutelage to know more about the context of the attacks.  It also states that DHS has the authorization to monitor using Einstein (enforced by the TIC program).  If you'll remember a while back I talked about Trusted Internet Connection (TIC) and its role in consolidating Internet points of presence and providing chokepoints to monitor and defend for the government. &lt;br /&gt;
 For reference see:  http://blog.decurity.com/index.php/dec_template/more/dhs_einstein_tic_overview/     and     http://blog.decurity.com/index.php/dec_template/more/dhs_blog_round_table/&lt;br /&gt;
&lt;br /&gt;
In short, TIC mandated government agencies to meet very stringent requirements in order to become a TICAP (provider) or  use pre-approved TICAP's (Telecom or other Agency) for all Internet traffic.  The monitoring capabilities of these TIC's is referenced in my earlier posts, but let's just say its EVERYTHING.  Not that I'm complaining, from a capabilities perspective I think NSA and Cyber Command should be making the most out of this information to help protect the government and as &lt;a href="http://taosecurity.blogspot.com/2009/07/nsa-to-screen-gov-now-i-predict-com.html" title="Richard Bejtlich speculates eventually &amp;quot;.com&amp;quot;"&gt;Richard Bejtlich speculates eventually ".com"&lt;/a&gt; .  NSA has the expertise and intelligence data while DHS has the authorization to monitor, the framework to force everyone to play (TIC) and a toolset that is evolving (Einstein v2 is still being rolled out, v3 is in development) On a side note, I do have to wonder why the government isn't using more capable tools like NetWitness or Solera in conjunction with NSA tools and building a META SIEM to incorporate Intelligence feeds, but that's a topic for a later post.  &lt;br /&gt;
&lt;br /&gt;
My biggest question is this.... I wonder how US-CERT and NSA are going to collaborate more effectively -  Is Einstein raw data going to be handled by NSA, if so what's the point of US-CERT in the future?&lt;br /&gt;
&lt;br /&gt;
Should be interesting to see what happens once the cyber czar is appointed, from what I can tell his/her kingdom has already layed a very clear path forward, the czar may simply be along for the ride while NSA drives over everyone else.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Update 1: &lt;/b&gt; (3 July 2009; 0930 EDT) SIOBHAN GORMAN of The Wall Street Journal also has an article on this topic "&lt;a href="http://online.wsj.com/article/SB124657680388089139.html" title="Troubles Plague Cyberspy Defense"&gt;Troubles Plague Cyberspy Defense&lt;/a&gt;" .  In this article takes more conservative approach in describing what is happening across government with regards to consolidated monitoring.  According to the article Einstein v3 will be updated/rebuilt to more closely align with NSA Tutelage and is at least 18 months out.   The idea is that it would start to develop full packet inspection capabilities (Like NetWitness, Solera and a few others).&lt;br /&gt;
&lt;br /&gt;
My Notes:   If this perspective is more accurate it seems US-CERT would monitor using technology enabled by NSA, instead of NSA accomplishing the monitoring.  IMHO - From what I've seen certain executive layers at DHS have not enabled the US-CERT to be effective enough to actually function as a true analytical center, even though USCERT has some very good people capable of executing on that misson.  In fact, I'd go as far as to say DHS is at risk of losing key staff if they don't figure out a better way to enable their team.  The place is known as a revolving door for a reason, the people they hire are very capable and motivated, the organization itself may not be best suited for that expertise and vision.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-6136114156852575360?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/r0IXqvmnSqkjsDASjv8lloLN4cU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/r0IXqvmnSqkjsDASjv8lloLN4cU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/r0IXqvmnSqkjsDASjv8lloLN4cU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/r0IXqvmnSqkjsDASjv8lloLN4cU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=ShQqDUxv-1M:VE5l7OPhaK4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=ShQqDUxv-1M:VE5l7OPhaK4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=ShQqDUxv-1M:VE5l7OPhaK4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=ShQqDUxv-1M:VE5l7OPhaK4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=ShQqDUxv-1M:VE5l7OPhaK4:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=ShQqDUxv-1M:VE5l7OPhaK4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=ShQqDUxv-1M:VE5l7OPhaK4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/ShQqDUxv-1M" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/6136114156852575360/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=6136114156852575360&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/6136114156852575360?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/6136114156852575360?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/ShQqDUxv-1M/nsa-uscert-einstein-tic-telecom.html" title="NSA, USCERT, EINSTEIN, TIC, Telecom Providers and the Future of Government Information Security" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/07/nsa-uscert-einstein-tic-telecom.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEYHRH04cSp7ImA9WxBRGEQ.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-1163492512910651077</id><published>2009-06-07T13:21:00.000-05:00</published><updated>2010-01-07T13:22:15.339-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-07T13:22:15.339-06:00</app:edited><title>Incident Response: A walk in the park</title><content type="html">So if you follow me on Facebook or &lt;a href="http://www.twitter.com/rockyd" title="Twitter"&gt;Twitter&lt;/a&gt; you may have heard our family had a bit of excitement over the weekend.  My wife and two youngest children (2 and 7)  got stuck at the top of a ride at Busch Gardens due to a "technical malfunction".  I know that mechanical and/or technical failures happen all the time at theme parks, but when it's your family up there and you're on the ground, it sucks.&lt;br /&gt;&lt;br /&gt;Busch Gardens did everything right, they quickly informed everyone on the ride of the malfunction, asked them to stay calm and at the same time sent emergency responders up to the top of the ride to help get everyone off safely.  No running around crazy, no unnecessary escalations, no waiting on approvals, no idle hands... Everyone played their role.   It got me thinking about the obvious parallels in incident response (well parts of it at least)&lt;br /&gt;&lt;br /&gt;The ride was designed with safety mechanisms including emergency exit and communication mechanisms.   The "owners" had procedures that were extremely well tested, communicated and executed by the "administrators".  Everyone had their role, understood it and was authorized to just "do it" and it worked out.  Once completed, they accomplished the repair, tested the ride, re-tested it from another perspective and then once approved by management they put the ride back into production for the park visitors ("users").  Sure the visitors had to wait a few minutes, but everyone was understanding once they had the right information made available to them.  Certainly, I'd prefer this sort of thing to never happen, but that's unrealistic given all variables in place at a Theme park in Florida with millions of visitors.  I'm just happy everyone was safe and we were able to enjoy the rest of the day.       and then just when you think it's over...&lt;br /&gt;&lt;br /&gt;Not more than 20 minutes later we saw another ride fail.  The sky-ride (gondola) got stuck mid-ride for over 10 Minutes.  Luckily, we were not on that ride.  I'd have gotten a bit suspicious at that point :).  &lt;br /&gt;&lt;br /&gt;Actually, at that time we were on a train ride enjoying a peaceful ride through the park, pointing out animals to my two year old, when a grumpy Rhino tried to prove to the train that he was in control and decided to give it a little shove to encourage the train to keep moving along.  I'm not sure if it was a full moon, an everyday occurrence for the park or Murphy's Law that caused all the excitement. &lt;br /&gt;&lt;br /&gt;It just goes to show you that you can't predict what's going to go wrong, just that something will go wrong - it always does.  We must prepare for as many types of Incidents as we can and enable our teams to react effectively, and expect that they will.  Obviously, a lot of pre-planning, risk assessment, exercise activities, documentation and training goes into the equation.  Everyone has to become involved, if a barely over minimum wage them park worker can be trained to play a role during an emergency, certainly we can figure out how to more effectively involve our "owners", "administrators", and management in our incident response activities. &lt;br /&gt;&lt;br /&gt;Ok, enough excitement for one evening I'm off to bed,   I can't wait for next week's cruise and the lessons that will bring..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-1163492512910651077?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/uz9akP3jg5rL1dONAt9y-eJwwEg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uz9akP3jg5rL1dONAt9y-eJwwEg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/uz9akP3jg5rL1dONAt9y-eJwwEg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uz9akP3jg5rL1dONAt9y-eJwwEg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=fL2hPHJzTKA:vDsfD38sqMc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=fL2hPHJzTKA:vDsfD38sqMc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=fL2hPHJzTKA:vDsfD38sqMc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=fL2hPHJzTKA:vDsfD38sqMc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=fL2hPHJzTKA:vDsfD38sqMc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=fL2hPHJzTKA:vDsfD38sqMc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=fL2hPHJzTKA:vDsfD38sqMc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/fL2hPHJzTKA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/1163492512910651077/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=1163492512910651077&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/1163492512910651077?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/1163492512910651077?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/fL2hPHJzTKA/incident-response-walk-in-park.html" title="Incident Response: A walk in the park" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/06/incident-response-walk-in-park.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEcGSXw-fSp7ImA9WxBRGEQ.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-1009813647128641800</id><published>2009-05-13T13:19:00.000-05:00</published><updated>2010-01-07T13:20:28.255-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-07T13:20:28.255-06:00</app:edited><title /><content type="html">Sara Peters at Information Week recently posted an article titled “&lt;a href="http://www.informationweek.com/blog/main/archives/2009/05/siem_case_study.html" title="SIEM Case Study: Israeli e-government ISP"&gt;SIEM Case Study: Israeli e-government ISP&lt;/a&gt;” In this article, Assaf Keren, information security manager at the Israeli e-government ISP Project (called “Tehila”) calls our attention to some very important details to consider when Implementing a SIEM.  Keren’s advice is that a successful SIEM implementation requires:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;1.    Detailed planning,&lt;br /&gt;2.    Fastidious attention to detail,&lt;br /&gt;3.    Superb communication between concerned parties&lt;br /&gt;4.    Attentive oversight of vendor activity.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Another Key Point from Mr. Keren - don’t outsource this “theory phase.”&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Note:  I agree with Mr. Keren that the SIEM requirements have to be driven from within your organization.  However, I believe that expert external entities can and should help drive discussions and help extract and refine requirements from your team. Obviously, the expert external entity MUST NOT be from a Vendor or reseller of any SIEM Products.&lt;br /&gt;&lt;br /&gt;Looking back over hundreds of SIEM deployments and seeing so many consistent decisions (or indecisions) that adversely affected the success of the SIEM I felt compelled to add a bit more context to augment the lessons Mr. Keren shared.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Overview:&lt;/b&gt;&lt;br /&gt;1. It takes a village, building planners, city inspectors, etc:  Probably, the most important takeaway from this post is that you should take the necessary time to fully comprehend and vet your requirements, as well as decide on your service delivery model, gain consensus on that approach and have realistic expectations along the way.  SIEM failures are more often the fault of poor planning, moving tactically while ignoring the strategic nature of the project, or simply misaligned expectations rather than a pure technology failure.&lt;br /&gt;&lt;br /&gt;2. Know what you are going to do with the Output before you make it Input:  It is tough to make sense (and therefore derive any value) out of billons of events by adding even more events to be evaluated into the mix.   Intelligent Collection, Analysis, Escalation and Remediation and workflow efforts defined before you start (and refined along the way) means that you’ll have a better idea what to do with the information your presented and a much higher chance for success in both end-user usage of the system and aligning that usage of the SIEM with the needs of your organization’s security or compliance program.&lt;br /&gt;&lt;br /&gt;3. Purchase the “right” technology, but do it incrementally:  Quite candidly some SIEM products should be avoided at all costs, however it should be noted that most of them can at least be used to help you meet some very basic requirements.   Consider your business and technical requirements over a 24-month period, but only purchase what is necessary to deliver based on the next 6 months of work you expect to get accomplished.  The system needs to be flexible to support all of those upcoming needs, but there is no need to spend money today to support tasks you won’t even consider touching for over 12 months.&lt;br /&gt;&lt;br /&gt;A successful SIEM tool supporting your organization’s Security and/or Compliance needs really boils down to some very simple concepts:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Define Success&lt;/b&gt;&lt;br /&gt;Have a strategic vision about how you want your Security Operation and/or Compliance Program to run and use that to help define requirements for how the SIEM (and Log Management) tools will provide input or drive workflow related to that Program.  Involve all the stakeholders early and keep them engaged along the way!&lt;br /&gt;&lt;br /&gt;•    If your rationale for buying a SIEM is PCI Compliance, STOP.&lt;br /&gt;&lt;br /&gt;•    If your rationale for investing in SIEM is to provide “x”,”y” and “z” data sets to business unit “a” and “b” and initiating workflow for your SOC; and you understand the event sources necessary/business logic to compile the data sets for each customer; and you fully understand how they intend to use that information the you are much closer to being ready to work with a SIEM.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related Resources: &lt;/b&gt;&lt;br /&gt;•    &lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_bp_basic_implementation_success_criteria/" title="SIEM: Basic Implementation Success Criteria"&gt;SIEM: Basic Implementation Success Criteria&lt;/a&gt;&lt;br /&gt;•    &lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_bp_before_you_buy/" title="SIEM: Before you Buy"&gt;SIEM: Before you Buy&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Plan Accordingly&lt;/b&gt;&lt;br /&gt;SIEM is not an overnight project, and yes even an Appliance-based SIEM’s require significant attention to work to their maximum potential for your organization.&lt;br /&gt;&lt;br /&gt;•    Gather requirements from all “stakeholders” Compliance, Legal, IT, Business Units, Security, Executive, everyone that will help you get information into the SIEM or receive information from the SIEM (or your service offering that leverages SIEM).&lt;br /&gt;&lt;br /&gt;•    Define Event Sources based on end-user needs:  Security, IT Operations and Compliance teams all have distinct needs and therefore may require different event source information.  At a minimum they may require different “views” of similar information set available in the SIEM or Log Management Tool.   Ensure you have the proper information sets, logging at the right levels and the information is available in a logical and meaningful manner.&lt;br /&gt;&lt;br /&gt;•    End-User Requirements are the most valuable.  The more your team understands how your “customers” value the data and service offering the more you can benefit from the functionality of the SIEM.&lt;br /&gt;&lt;br /&gt;•    Analytical and Workflow Requirements.  Security Analysts need to be able to quickly identify, analyze, prioritize and escalate the data with context in order for the SIEM to meet its most basic functions.  This functionality is not as common as you would think across different SIEM’s.    Be sure that the SIEM integrates with your workflow systems in an acceptable fashion.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related Resources:&lt;/b&gt;&lt;br /&gt;•    &lt;a href="http://blog.decurity.com/index.php/dec_template/more/best_practices_in_security_operations_collection/" title="SIEM: Best Practices in Collection "&gt;SIEM: Best Practices in Collection &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Vendor Selection&lt;/b&gt;&lt;br /&gt;Now that you have your requirements documented and prioritized compare them against &lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_best_practices_evaluation_criteria/" title="SIEM: Evaluation Criteria"&gt;SIEM: Evaluation Criteria&lt;/a&gt; and refine them even further…&lt;br /&gt;&lt;br /&gt;•    Either partner with an expert that can tell you exactly why certain Vendors can not meet your needs (today/tomorrow) and compare those answers a n honest discussion with the vendor or invest in a Pilot in an effort to prove out ALL of your requirements (not just the top three.)&lt;br /&gt;&lt;br /&gt;•    Make sure you have data either directly from production event sources or a reasonably similar source.  If you use &lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_best_practices_combined_log_management_and_siem_architecture_benefits/" title="combined Log Management and SIEM architecture"&gt;combined Log Management and SIEM architecture&lt;/a&gt;, make sure you can configure outbound events in a format the SIEM can comprehend for more than just Syslog events.  If the SIEM can natively handle ODBC but your architecture requires Log Management to be the Collection Tier and forward events to the SIEM – How does the LM reformat those events and how does the SIEM handle that data?&lt;br /&gt;&lt;br /&gt;•    Customer Referrals are nice, but be careful.  I’ve seen this scenario too many times.  Victim asks a SIEM Reference Client about a key area of concern, say scalability and the reference client dutifully answers the questions with a resounding “Yes, the $VENDOR scales to meet my global organization’s amazing needs” in all the excitement it was overlooked that it takes 100+ systems to get there and oh yeah, by the way none of these SIEM systems can cross correlate information.  As your requirements are defined, build out testing plans if the requirement is that critical and test it prior to purchasing.&lt;br /&gt;&lt;br /&gt;•    Maximize your dollar.  Ensure the vendor is prepared to partner with you for the long haul, you both have a vested interest in the success of the program – make sure they are going to be there for you&lt;br /&gt;•     Find out the vendor’s fiscal period and plan your purchase accordingly.  Fiscal Quarter end and Fiscal Year end are great times to make deals (especially enterprise deals) with vendors.&lt;br /&gt;•    Purchase what you need not what you want.   If you don’t have a documented requirement that you can reasonably achieve in the next 6 months don’t buy it yet.   Conversely, don’t skimp on things you absolutely do need.  If you have a requirement to store 8 Billon events a day over a 10-year period and you expect to do that with local storage or even DAS, NAS.  Stop and rethink things a bit.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Focused Effort: &lt;/b&gt;&lt;br /&gt;Ensure that you have dedicated enough time and energy to the success of your SIEM Effort.  If you are a large enterprise this is at least 2 FTE’s or an &lt;a href="http://www.decurity.com/Decurity_D3_Overview.html%20" title="Expert Partner "&gt;Expert Partner &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Seriously, Requirements Gathering, Vendor Selection, Pilot, Implementation, Initial Operating Capability, Operational Refinements, Final Operating Capability (Formal Service Delivery), On-going Enhancements, Patches, Upgrades, Lab Testing, Additional Content Tuning, Expansion and the related Coordination, Planning, Execution, Oversight and Measurements is enough to keep an entire team busy.  Doing all of that within the framework of your overall Strategic Security Program and not just tactically solving issues as the “pop-up” on a daily basis is the key to success with SIEM and ultimately your entire security and/or compliance program.&lt;br /&gt;&lt;br /&gt;Having the wrong team or not listening to the right team is about the same as not having resources at all.  Spend the time to ensure your SIEM team is baked into your Security/Compliance Program(s) so they can help you plan for today and tomorrow and save a lot of headaches in new hardware, storage or even total SIEM replacement.  If your not ready to dedicate the right Resources/Partner’s then you may be better off waiting and then introducing SIEM into your organization when the requirements, proposed solution and funding are more in line.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Lifecycle Planning&lt;/b&gt;&lt;br /&gt;This goes way beyond simple O&amp;amp;M tasks.  SIEM is part of your overall Security Program and as such need to stay in step with that Program.  Your SIEM Team (Partner) needs to be involved along the way to help ensure compatibility and/or flexibility as you evolve.  Service Delivery, Technology, Business and Compliance requirement changes and/or reprioritizations can all have a significant impact on the success or failure of the overall program.  The tighter the team is with the thought process around those upcoming changes the more likely your SIEM Program will meet your needs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-1009813647128641800?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/eUadeNkJd1-XGwuAFljD9SX_I-c/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/eUadeNkJd1-XGwuAFljD9SX_I-c/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/eUadeNkJd1-XGwuAFljD9SX_I-c/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/eUadeNkJd1-XGwuAFljD9SX_I-c/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Ozm99xf0Ff4:1L2UZv-cuAE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Ozm99xf0Ff4:1L2UZv-cuAE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=Ozm99xf0Ff4:1L2UZv-cuAE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Ozm99xf0Ff4:1L2UZv-cuAE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Ozm99xf0Ff4:1L2UZv-cuAE:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Ozm99xf0Ff4:1L2UZv-cuAE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=Ozm99xf0Ff4:1L2UZv-cuAE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/Ozm99xf0Ff4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/1009813647128641800/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=1009813647128641800&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/1009813647128641800?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/1009813647128641800?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/Ozm99xf0Ff4/sara-peters-at-information-week.html" title="" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2010/01/sara-peters-at-information-week.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkMEQXgyfSp7ImA9WxVaGEQ.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-858059695771717372</id><published>2009-04-16T10:04:00.001-05:00</published><updated>2009-04-16T10:06:40.695-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-04-16T10:06:40.695-05:00</app:edited><title>Latest Verizon Business Data Breach Report</title><content type="html">I just wanted to let everyone know that Verizon Business has published the 2009 Data Breach Report.  The breadth and depth of these reports are invaluable.  Since there are very few solid sources of this type of information the release of this report dominates the availability of the few brain cells I have remaining.&lt;br /&gt;&lt;br /&gt;Press Release Here: &lt;a href="http://www.verizonbusiness.com/products/security/risk/databreach/"&gt;http://www.verizonbusiness.com/products/security/risk/databreach/&lt;/a&gt;&lt;br /&gt;Actual Report Here: &lt;a href="http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf"&gt;http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf&lt;/a&gt;&lt;br /&gt;Look for updates/comments from the authors/team at &lt;a href="http://securityblog.verizonbusiness.com"&gt;http://securityblog.verizonbusiness.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From my first 5 minute glance at the report here are some of my favorite things:&lt;br /&gt;&lt;br /&gt;Figure 31. Time Span of breach event by percent of breaches. This may be the best metric we as security professionals can look to improve.  Seeking to reduce the time to Incident Identification and Mitigation&lt;br /&gt;&lt;br /&gt;Figure 32. Breach Discovery methods by percent of breaches.  Interesting observations about how things are detected, nearly 70% by third parties, only 7% by “active” internal teams.&lt;br /&gt;&lt;br /&gt;Figure 34. Detective Controls by percent of breach victims.  System and Application Logs are KEY (don’t just rely on security devices).&lt;br /&gt;&lt;br /&gt;Many of the recommendations seem brain dead simple so I won’t cover them here, nor will I go into the pseudo risk calculations or PCI “Compliance” at this time.  All in all a ton of food for thought in this report.  I’m going to wait to post more comprehensive notes on this report to allow it all to sink in a bit more.  Verizon obviously puts a lot of thought and effort into this report and I find myself spending hours dissecting it every time.  To my friends over at Verizon Business - Thanks again for the information!  Everyone else - I encourage you to take the time to review it thoroughly. &lt;br /&gt;&lt;br /&gt;Originally published on blog.decurity.com on 14 April 2009.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-858059695771717372?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/rcqUPXo9HKv7-cmj0_ZuMT6PbxE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rcqUPXo9HKv7-cmj0_ZuMT6PbxE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/rcqUPXo9HKv7-cmj0_ZuMT6PbxE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rcqUPXo9HKv7-cmj0_ZuMT6PbxE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=_MzbFprbbLA:btkoQfvDQtA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=_MzbFprbbLA:btkoQfvDQtA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=_MzbFprbbLA:btkoQfvDQtA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=_MzbFprbbLA:btkoQfvDQtA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=_MzbFprbbLA:btkoQfvDQtA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=_MzbFprbbLA:btkoQfvDQtA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=_MzbFprbbLA:btkoQfvDQtA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/_MzbFprbbLA" height="1" width="1"/&gt;</content><link rel="related" href="http://blog.decurity.com/index.php/dec_template/more/latest_verizon_business_data_breach_report/" title="Latest Verizon Business Data Breach Report" /><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/858059695771717372/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=858059695771717372&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/858059695771717372?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/858059695771717372?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/_MzbFprbbLA/latest-verizon-business-data-breach.html" title="Latest Verizon Business Data Breach Report" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/04/latest-verizon-business-data-breach.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUCRXgzeyp7ImA9WxVaGEQ.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-5452387266859700079</id><published>2009-04-16T10:01:00.001-05:00</published><updated>2009-04-16T10:04:24.683-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-04-16T10:04:24.683-05:00</app:edited><title>Hackers for Charity</title><content type="html">&lt;a href="http://ihackcharities.org"&gt;Hackers for Charity&lt;/a&gt; is Johnny Long’s new website and mission in life.  Saying that I applaud him on this effort is the biggest understatement I can make.  On a personal level I am very moved by his passion and commitment to server others, here and everywhere.  Johnny has taken his talents and applied them in ways that help so many people across the world.  Just thinking about what he is accomplishing motivates me to seek better out of myself.  Please do pop over to his site and find a way to help Johnny and his family on their upcoming year-long efforts in Uganda.  Equipment, Advise, Money - anything you can provide will help Johnny, his family and so many others in Uganda and across the world!&lt;br /&gt;&lt;br /&gt;Rocky&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-5452387266859700079?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/-w3A82jM675Hf5hrqjAGxftXr48/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-w3A82jM675Hf5hrqjAGxftXr48/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/-w3A82jM675Hf5hrqjAGxftXr48/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-w3A82jM675Hf5hrqjAGxftXr48/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=ZwJQLDa2KLI:kT53h3mP2-I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=ZwJQLDa2KLI:kT53h3mP2-I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=ZwJQLDa2KLI:kT53h3mP2-I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=ZwJQLDa2KLI:kT53h3mP2-I:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=ZwJQLDa2KLI:kT53h3mP2-I:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=ZwJQLDa2KLI:kT53h3mP2-I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=ZwJQLDa2KLI:kT53h3mP2-I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/ZwJQLDa2KLI" height="1" width="1"/&gt;</content><link rel="related" href="http://blog.decurity.com/index.php/dec_template/more/hackers_for_charity/" title="Hackers for Charity" /><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/5452387266859700079/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=5452387266859700079&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/5452387266859700079?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/5452387266859700079?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/ZwJQLDa2KLI/hackers-for-charity.html" title="Hackers for Charity" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/04/hackers-for-charity.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkAFSXs9eCp7ImA9WxVUFUk.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-746769143401347160</id><published>2009-03-20T04:10:00.002-05:00</published><updated>2009-03-20T04:18:38.560-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-03-20T04:18:38.560-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SIEM Best Practices" /><category scheme="http://www.blogger.com/atom/ns#" term="SIEM" /><category scheme="http://www.blogger.com/atom/ns#" term="Rocky" /><category scheme="http://www.blogger.com/atom/ns#" term="Log Logic" /><category scheme="http://www.blogger.com/atom/ns#" term="Decurity" /><category scheme="http://www.blogger.com/atom/ns#" term="ArcSight" /><title>More SIEM Vendor Leap Frog</title><content type="html">&lt;a href="http://www.networkworld.com/news/tech/2009/031909-tech-update.html?page=1" title="Network World's recent article"&gt;Network World's recent article&lt;/a&gt; provides additional evidence that Log Management and SIEM Vendors are still trying to evolve.&lt;br /&gt;&lt;br /&gt;Dominique Levin (EVP of Strategy/Marketing at &lt;a href="http://www.loglogic.com" title="Log Logic"&gt;Log Logic&lt;/a&gt; writes in this &lt;a href="http://www.networkworld.com/news/tech/2009/031909-tech-update.html?page=1" title="Network World article"&gt;Network World  article&lt;/a&gt; posted last night (03/19/2009) about the development and convergence of SIEM and Log Management.  I'm glad that Log Logic finally understands the model and is trying to address a broader market opportunity by incorporating SIEM into their offering.  If you didn't already know, last month Log Logic partnered with ExaProtect to be able to provide a more native (to Log Logic) SIEM solution.  As a side note, it has been my experience that you can make other SIEM's work in conjunction with Log Logic (at least in an unidirectional manner) by forwarding events to a SIEM from the Log Management platform.  I hope that Log Logic (and other vendors) continue to read my &lt;a href="http://blog.decurity.com/index.php/dec_template/more/recent_siem_announcements" title="SIEM Vendor Leap Frog"&gt;SIEM Vendor Leap Frog&lt;/a&gt; post and take some of the challenges in current technologies to heart.  Bi-directional search between Log Management and SIEM, shared user authorization and authentication techniques, more robust shared management options - all of which really need to evolve from these types of offerings.  I hope they and the other vendors look at this as an opportunity to truly merge the products into a solution versus the current "bolt-on" approach some in the market have taken.  It is not enough to just have the technology available, the vendors must understand how the customers will use this in the field and make it more simple to deploy, manage and ultimately actually use these products.  &lt;a href="http://www.arcsight.com" title="ArcSight"&gt;ArcSight&lt;/a&gt;, &lt;a href="http://www.rsa.com/node.aspx?id=3170" title="RSA"&gt;RSA&lt;/a&gt; and other key players are working on this very diligently and have made great strides to making this vision a reality.  It's still nowhere near perfect but I think it will get much more emphasis over the next 12-18 months or so as more people demand better integrated solutions during their acquisition or renewal cycles.  &lt;br /&gt;&lt;br /&gt;Another side note:  At the recent &lt;a href="http://blog.decurity.com/index.php/dec_template/comments/2009_ians_mid-atlantic_forum_summary/" title="IANS DC forum"&gt;IANS DC forum&lt;/a&gt; and again at &lt;a href="http://blog.decurity.com/index.php/dec_template/more/review_sourceboston_2009/" title="SOURCE Boston"&gt;SOURCE Boston&lt;/a&gt; Peter Kuper noted that security vendors are going to have to make more of an effort to partner with their customers to really thrive in this market.  Peter also made the point that customers have to demand more value from their vendors in order to show value to their own management.  I think everyone should take that message to heart!&lt;br /&gt;&lt;br /&gt;The information presented in the Network World article further validates some of the positions I presented in my &lt;a href="http://blog.decurity.com/index.php/dec_template/more/recent_siem_announcements/" title="SIEM Vendor Leap Frog"&gt;SIEM Vendor Leap Frog&lt;/a&gt; post earlier this week.  For that matter so does a &lt;a href="http://twitter.com/nitrosecurity/status/1356503553" title="recent &amp;quot;tweet&amp;quot;"&gt;recent "tweet"&lt;/a&gt; from &lt;a href="http://www.nitrosecurity.com" title="NitroSecurity"&gt;NitroSecurity&lt;/a&gt; (Twitter: &lt;a href="http://www.twitter.com/nitrosecurity" title="@nitrosecurity"&gt;@nitrosecurity&lt;/a&gt;) as well as, a &lt;a href="http://twitter.com/tknsecurityguy/status/1349443074" title="&amp;quot;tweet&amp;quot;"&gt;"tweet"&lt;/a&gt; from RSA's SIEM Solutions Evangelist Paul Stamp (Twitter: &lt;a href="http://www.twitter.com/tknsecurityguy" title="@tknsecurityguy"&gt;@tknsecurityguy&lt;/a&gt;) &lt;a href="http://tokensecurityguy.typepad.com/token_security_guy/2009/03/spot-on-analysis-of-siem-market.html" title="and a recent post from RSA's SIEM Solutions Evangelist Paul Stamp in his personal blog"&gt;and a recent post Paul Stamp in his personal blog&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;The idea of combining Log Management and SIEM isn't novel (in fact it is several years old) but only recently has it become the "standard" for gaining "&lt;a href="http://blog.decurity.com/index.php/dec_template/more/best_practices_in_security_operations_collection/" title="Enterprise Visibility"&gt;Enterprise Visibility&lt;/a&gt;" and then moving towards making security operations work more fluidly through the use of a SIEM.  &lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_best_practices_combined_log_management_and_siem_architecture_benefits/" title="The combining of Log Management and SIEM is not trivial to accomplish but can be done quite well if architected correctly"&gt;The combining of Log Management and SIEM is not trivial to accomplish but can be done quite well and adds huge value, if architected correctly&lt;/a&gt;.   &lt;br /&gt;&lt;br /&gt;The article explains the evolution of SIEM through the years, beginning with Perimeter Security "Use-Cases", moving through certain "Internal Monitoring" Use-cases and then describes how SIEM gained critical mass through "Compliance" Use-Cases.  I will not debate the relevance of SIEM in each of these situations other than to say - Both the Log Management and SIEM's product sets are nothing more than tools. They can be a powerful resource in the right hands and have a great many potential applications, but the team wielding that power has to know how to apply it and when (and when not to).  While it is true that some SIEM platforms are flexible enough to move beyond simple network security based use-cases, the complexity involved in making those transitions requires expert touch. Let's get these systems working correctly in security first then we can think about expansion into other areas (business intelligence, etc).  There is no magic fairy dust here.  It is hard work at each and every step, but there is a payoff.  You can automate many labor intensive tasks including identification and escalation of alerts, which should free up some analytical cycles to find new and more complex activities that they can turn into "events of interest" for future correlation.  BTW I didn't mean to dismiss the value of Log Management and SIEM outside the context of Security - it is possible (it requires great flexibility in the vendor solution but I know many organizations that have made interesting solutions work in very unique ways) I'm simply saying there is a lot more work we can do to get the actual security focused portion of these solutions to work better before we try and show value (and over exert our reach/resources) in other areas.  &lt;br /&gt;&lt;br /&gt;Let's keep working together to encourage the right partnership and evolution from our vendors!  They are doing the best they can, but it is up to the community at large to focus them in the right direction.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-746769143401347160?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/V2UYCjpThjUhx0RjZm0KDT1I2iM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/V2UYCjpThjUhx0RjZm0KDT1I2iM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/V2UYCjpThjUhx0RjZm0KDT1I2iM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/V2UYCjpThjUhx0RjZm0KDT1I2iM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=GAdYhfalNto:WSVBtB_SnPw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=GAdYhfalNto:WSVBtB_SnPw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=GAdYhfalNto:WSVBtB_SnPw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=GAdYhfalNto:WSVBtB_SnPw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=GAdYhfalNto:WSVBtB_SnPw:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=GAdYhfalNto:WSVBtB_SnPw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=GAdYhfalNto:WSVBtB_SnPw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/GAdYhfalNto" height="1" width="1"/&gt;</content><link rel="related" href="http://blog.decurity.com/index.php/dec_template/more/more_siem_vendor_leapfrog" title="More SIEM Vendor Leap Frog" /><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/746769143401347160/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=746769143401347160&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/746769143401347160?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/746769143401347160?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/GAdYhfalNto/more-siem-vendor-leap-frog.html" title="More SIEM Vendor Leap Frog" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/03/more-siem-vendor-leap-frog.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0MFSXk-fip7ImA9WxVUE0Q.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-4627774025622863250</id><published>2009-03-18T11:51:00.002-05:00</published><updated>2009-03-18T11:56:58.756-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-03-18T11:56:58.756-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Splunk" /><category scheme="http://www.blogger.com/atom/ns#" term="SIEM" /><category scheme="http://www.blogger.com/atom/ns#" term="Rocky" /><category scheme="http://www.blogger.com/atom/ns#" term="ArcSight" /><category scheme="http://www.blogger.com/atom/ns#" term="NetWitness" /><category scheme="http://www.blogger.com/atom/ns#" term="Log Management" /><title>SIEM Vendor Leapfrog</title><content type="html">Recently, Log Management and SIEM vendors have spent a lot of time updating/fixing their products.  Over the past few months some vendors have quietly passed over other solutions in terms of market relevance and certainly the door has been opened to a whole bunch of upstarts trying to make a name for themselves.  While the majority of Log Management and SIEM business (and therefore product direction) is driven by compliance activities, I appreciate the forward movement towards enterprise security that many in the field are trying to make.  The initial execution on that product vision I'm seeing from many of the vendors this year is very welcome.  IMHO the entire space had gotten very stale with the big guys mainly focusing on compliance appliances or playing feature catch-up with one another.  Here's my summary of what's going on in SIEM and Log Management so far in 2009.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;My observations about recent SIEM and Log Management Vendor announcements and my thoughts about what is still needed to make it more effective for most customers.&lt;br /&gt;&lt;br /&gt;1. Log Management appliance based solutions continue to rule the land.  See &lt;a href="http://yahoo.brand.edgar-online.com/DisplayFiling.aspx?dcn=0000950134-09-005194" title="ArcSight's last quarterly results announcement"&gt;&lt;/a&gt; &lt;a href="http://www.arcsight.com/" title="ArcSight's"&gt;ArcSight's&lt;/a&gt; last quarterly results announcement and extract from that the fact that something like 46% of product revenue was based on their appliances or talk with &lt;a href="http://www.intellitactics.com/" title="Intellitactics"&gt;Intellitactics&lt;/a&gt; about their recent growth in &lt;a href="http://intellitactics.com/int/products/safe.asp" title="SAFE Logging Appliance"&gt;SAFE Logging Appliance&lt;/a&gt; sales if you don't believe me.  &lt;a href="http://www.splunk.com/" title="Splunk "&gt;Splunk &lt;/a&gt;may be exception to that appliance rule as they continue to gain ground on everyone but the fact remains if you don't have a solid Log Management offering you're toast in 2009.  Conversely, pure Log Management solutions have seen the importance of having a SIEM offering available to be able to effectively compete on larger accounts (see the link below about Log Logic partnership with ExaProtect as one example).&lt;br /&gt;&lt;br /&gt;2. Some vendors are still playing feature catch-up adding things like Trouble Ticket Integration of Vulnerability Assessment Tool Integration.  It is amazing to me that these are "new feature sets" in several products, but progress is progress and I'll take it.  I'm still not thrilled with most vendors idea of integration being unidirectional SMTP based updates but it's a start.  The idea of Vulnerability Management and then furthering that by full CMDB integration is awesome in theory but in many cases it is very hard to scale.  This has made significant stride forward but in my mind much more is left to be accomplished.&lt;br /&gt;&lt;br /&gt;3. Database Activity Monitoring seems to be catching on.  Interesting given how difficult this really is to accomplish in an enterprise - Admin level monitoring is easy enough but field level and/or transaction level auditing like Oracle FGA is a non-trivial task to accomplish.  Most vendors have approached this solution set through 3rd party product support (Imperva, Guardium, etc) but at least a couple have tackled this directly through development or acquisition.&lt;br /&gt;&lt;br /&gt;4. Enterprise Visibility is a growing trend.    I've previously stated my appreciation for having proper visibility across the enterprise.  When &lt;a href="http://www.netwitness.com/" title="NetWitness"&gt;NetWitness&lt;/a&gt; announced their free version of Investigator I &lt;a href="http://blog.decurity.com/index.php/dec_template/more/netwitness_investigator_summary_1/" title="posted my comments and review of the technology."&gt;posted my comments and review of the technology.&lt;/a&gt;  Last year in my "&lt;a href="http://blog.decurity.com/index.php/dec_template/more/best_practices_in_security_operations_collection/" title="Best Practices in Security Operations: Collection"&gt;Best Practices in Security Operations: Collection&lt;/a&gt;" post I expressed my thoughts on what it takes to really do Enterprise Security Operations correctly and that the foundation of the entire process is Collection.  Part of that collection is filling in the gaps missed by other products and Full Packet Capture is an awfully powerful tool to have in your arsenal.  Several vendors have announces partnerships with 3rd party providers and/or announced network capture/replay as an internal capability through development or acquisition (see NitroSecurity).&lt;br /&gt;&lt;br /&gt;5. Hard stuff is still hard - Windows Event Logs, Custom Applications, CMDB Integration, Database Monitoring are all hard problems to tackle.  No vendor has this perfect (how could we expect them to) but several have started to think about ways to make this easier, rather than just saying "start with critical systems" they are developing more reliable/scalable/flexible solutions.  I'm interested to see how far the vendors get with the more complex logs and more meaningful IT operations integrations in 2009.&lt;br /&gt;&lt;br /&gt;6. Relevant content is king.  The default content (Correlation, Reports, etc) from most of the vendors is not going to work in your enterprise.  Sure some of it works at least some of the time but seriously on average how could 1500+ reports ever apply to your environment.  Content Tuning is the #1 area vendors can make these solutions more relevant and easier for customers.  I believe this so much that Decurity has re-focused much of its energy to &lt;a href="http://decurity.com/SIEM_SUBSCRIPTION_OVERVIEW.html" title="address this issue head on"&gt;address this issue head on&lt;/a&gt; hey, it's my blog and I'll pimp if I want to.&lt;br /&gt;&lt;br /&gt;7. Consolidation/Contraction.  I do expect to see more industry consolidation.  High Tower won't be the last failure and some of the big boys need to revamp their overall integrated solutions.  The Log Management side may be commodity ready but SIEM is not (yet).  I expect at least 2 more acquisitions/failures to occur in the space in the coming months and not necessarily because of bad technology.  A great technology in the wrong hands or begin put against the wrong goals is no better than a crappy technology. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Additional Thoughts:&lt;/b&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;SIEM: &lt;/b&gt;&lt;/u&gt;  &lt;i&gt;The Fortune 100 &lt;/i&gt; seems to be saturated with products/solutions (a lot have failed and some are actually working) and they have plenty of war stories that hey are more than willing to share.  The overall take-away is simple - you need to be ready to invest in success if you jump into SIEM, product flexibility, product expertise, documented internal &lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_best_practices_evaluation_criteria/" title="requirements"&gt;requirements&lt;/a&gt; and perhaps most importantly internal processes/procedures for making it work.&lt;br /&gt;&lt;i&gt;Fortune 200-2000:&lt;/i&gt; I'm happy to see that many organizations are now starting to push-back on vendors (and their own management) after learning from the mistakes of others.  I think they will take a more reasonable approach of making Log Management work first before moving to SIEM and when they get to SIEM I'm encouraged by the increasing trend of documenting actual use-cases and requirements.&lt;br /&gt;&lt;i&gt;Channel:&lt;/i&gt;  Nearly all the of vendors are trying enabling better global channel programs and at least in Log Management these are very successful programs helping them gain foreign market share and SMB market in the US.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;SIEM: Some idea's for improvement:&lt;/b&gt;&lt;br /&gt;1. Most of the SIEM products require significant expertise to deploy, manage and maintain effectively.  There is a good business there for the right partnerships and companies should leverage that expertise.  Today the number of VAR's and Consulting organizations that really can be considered "expert" in this area can be counted on one hand.  I still think the vendors are going to have to do better to make their SIEM products more user-friendly and that will require a true partnership with their customers. &lt;br /&gt;2. If your SIEM can't correlate events (Raw or Meta events) between engines you should be pushing your Vendor towards making that work in 2009.  Linear scalability is irrelevant you are going to need flexibility in the future.  Even if your organization is not mature enough to use that functionality today, you will eventually get there, make sure your vendors are partnered with you to help you achieve your long-term goals.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;LOG MANAGEMENT:  &lt;/b&gt;&lt;/u&gt; Log Management will continue to grow across all market segments, no question.  The overall channel effectiveness seems to be growing as the acceptance of appliance based solutions grows.  Compliance is an easy driver for sales in Log MGMT but at some point the big customers will have to step up and require better and more scalable solutions from the vendors. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Log Management: Some idea's for improvement: &lt;/b&gt;  &lt;br /&gt;1.) Log Management solutions that attach to an in-house SAN is a great idea - but only if the SAN carve out is unlimited or at least sufficient enough that they aren't required to purchase additional appliances to scale to the enterprise. &lt;br /&gt;2.) Better bi-directional support between Log Management and SIEM solutions is absolutely required.  You have to be able to search one/both from a single location for these to gain better traction as &lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_best_practices_combined_log_management_and_siem_architecture_benefits/" title="combined offerings"&gt;combined offerings&lt;/a&gt;.&lt;br /&gt;3.) Flexibility is going to be key moving forward.  Splunk is gaining ground for a reason (and it is more than marketing).  Integration of new event sources will continue to be a key issue.&lt;br /&gt;4.) Content is also an issue on the Log Management end.  Some vendors do a fantastic job and others need better partnerships or a renewed internal focus on relevant security content.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;Recent Log Management and SIEM Product Update News and Links:&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;u&gt;March 2009&lt;/u&gt;&lt;br /&gt;&lt;a href="http://www.nitrosecurity.com/information/news/pr/2009/20090318.psp" title="Nitro Security"&gt;Nitro Security&lt;/a&gt; Acquires Chronicle Solutions .&lt;br /&gt;&lt;a href="http://www.rsa.com/node.aspx?id=3170" title="EMC RSA"&gt;EMC RSA&lt;/a&gt; &lt;a href="http://www.rsa.com/go/press/RSATheSecurityDivisionofEMCNewsRelease_online3.9.09.html" title="RSA releases enVision v4.0"&gt;RSA releases enVision v4.0&lt;/a&gt;  And now &lt;a href="http://www.rsa.com/blog/blog.aspx?author=stamp" title="Paul Stamp"&gt;Paul Stamp&lt;/a&gt; is over there helping them move the product further along!&lt;br /&gt;&lt;a href="http://netforensics.com/" title="NetForensics"&gt;NetForensics&lt;/a&gt; &lt;a href="http://netforensics.com/contentdisplay.asp?id=300" title="NetForensics releases NFX v4.1"&gt;NetForensics releases NFX v4.1&lt;/a&gt; .&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Feb 2009&lt;/u&gt;&lt;br /&gt;&lt;a href="http://www.tenablesecurity.com/news/" title="Tenable" releases="" database="" auditing="" capability=""&gt;Tenable&lt;/a&gt;Tenable releases Database Auditing Capability&lt;br /&gt;&lt;a href="http://www.q1labs.com/" title="Q1Labs"&gt;Q1Labs&lt;/a&gt; QRadar 6.2 was released.  .&lt;br /&gt;&lt;a href="http://www.loglogic.com/" title="LogLogic"&gt;LogLogic&lt;/a&gt; &lt;a href="http://loglogic.com/news/news-releases/2009/exaprotect-announce-release/%20" title="partners with"&gt;partners with&lt;/a&gt; &lt;a href="http://exaprotect.com/" title="exaprotect"&gt;exaprotect&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.scmagazineus.com/NetForensics-buys-High-Tower/article/127423" title="NetForensics buys High Tower"&gt;NetForensics&lt;/a&gt;  HighTower was gobbled up by NetForensics.  I'm reserving judgment for now. &lt;br /&gt;&lt;br /&gt;&lt;u&gt;Jan 2009&lt;/u&gt;&lt;br /&gt;&lt;a href="http://nitrosecurity.com/" title="Nitro Security"&gt;Nitro Security&lt;/a&gt; integrates Database Activity Monitoring (DAM) into SIEM.&lt;br /&gt;&lt;a href="http://eiqnetworks.com/" title="eIQnetworks"&gt;eIQnetworks&lt;/a&gt; announces a new round of funding and management additions A lot of "buzz" around eIQ right now but I have yet to have the opportunity to see them in action in a global enterprise.  I hear good things about their approach, but I'm always cautious. &lt;br /&gt;&lt;br /&gt;&lt;u&gt;Late 2008 News:&lt;/u&gt;&lt;br /&gt;&lt;a href="http://www.symantec.com/business/products/newfeatures.jsp?pcid=pcat_security&amp;amp;pvid=929_1" title="Symantec"&gt;Symantec SIM v4.6 released" &lt;/a&gt;.&lt;br /&gt;&lt;a href="http://www.trigeo.com/" title="Trigeo"&gt;Trigeo seeks HighTower's customers&lt;/a&gt; Trigeo offered a competitive upgrade to former HighTower customers.&lt;br /&gt;&lt;a href="http://logrhythm.com/" title="LogRhythm"&gt;LogRhythm Version 4.1 Released &lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.sensage.com/" title="Sensage"&gt;Sensage version 4.0 Released&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.splunk.com/" title="Splunk"&gt;Splunk v3.4.6 released &lt;/a&gt;  I hear rumors of Splunk 4.0 coming this summer!&lt;br /&gt;&lt;a href="http://www.arcsight.com/" title="ArcSight "&gt;ArcSight Announces ESM 4.0 SP2 and ArcSight Logger 3.0 &lt;/a&gt;  ArcSight Logger 3.0 was a VAST improvement over previous versions in terms of speed and capability.&lt;br /&gt;&lt;a href="http://www.q1labs.com/pr.php?id=469" title="Q1 Labs"&gt;Q1 Labs&lt;/a&gt; QRadar product was OEM'ed into Juniper STRM Products.  An interesting play, very similar to what Protego did a few years ago (now Cisco MARS).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-4627774025622863250?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/hGfLs7tktDQklAqE5EIAQFkSHEE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/hGfLs7tktDQklAqE5EIAQFkSHEE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/hGfLs7tktDQklAqE5EIAQFkSHEE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/hGfLs7tktDQklAqE5EIAQFkSHEE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=G4SyIniQm8A:gR5mAqyw8nc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=G4SyIniQm8A:gR5mAqyw8nc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=G4SyIniQm8A:gR5mAqyw8nc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=G4SyIniQm8A:gR5mAqyw8nc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=G4SyIniQm8A:gR5mAqyw8nc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=G4SyIniQm8A:gR5mAqyw8nc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=G4SyIniQm8A:gR5mAqyw8nc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/G4SyIniQm8A" height="1" width="1"/&gt;</content><link rel="related" href="http://blog.decurity.com/index.php/dec_template/more/recent_siem_announcements" title="SIEM Vendor Leapfrog" /><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/4627774025622863250/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=4627774025622863250&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/4627774025622863250?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/4627774025622863250?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/G4SyIniQm8A/siem-vendor-leapfrog.html" title="SIEM Vendor Leapfrog" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/03/siem-vendor-leapfrog.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkMHSHs9cCp7ImA9WxVUEEU.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-1517227171230316862</id><published>2009-03-07T22:30:00.000-06:00</published><updated>2009-03-14T22:40:39.568-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-03-14T22:40:39.568-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SIEM Best Practices" /><category scheme="http://www.blogger.com/atom/ns#" term="SIEM" /><category scheme="http://www.blogger.com/atom/ns#" term="Rocky" /><category scheme="http://www.blogger.com/atom/ns#" term="Decurity" /><category scheme="http://www.blogger.com/atom/ns#" term="ArcSight" /><category scheme="http://www.blogger.com/atom/ns#" term="Log Management" /><title>Combined Log Management and SIEM Architecture Benefits</title><content type="html">The following notional diagram provides some basic recommendations to consider when deploying and managing Log Management and SIEM systems together.  &lt;br /&gt;&lt;br /&gt;A well-maintained Log Management and SIEM deployment can significantly reduce the time to Incident Identification and really enhance your overall information security capability.  The diagram attempts to illustrate that all information from the Event Sources are processed through the appropriate Log Collection Mechanism and then forwarded to the Log Management System. &lt;br /&gt;&lt;br /&gt;The Log Management system eats, stores and can regurgitate everything put into it.  The Log Management Solution also can further refine the data set and forward only applicable events for analysis to the correlation engine (SIEM) through the use of intelligent “tagging” of events.  &lt;br /&gt;&lt;br /&gt;Overall data reduction is only part of the end goal, more importantly we want to ensure the right data is forwarded and evaluated so that we can gain from the overall efficiencies offered by the SIEM.  In short we’re ensuring the system has the correct information available to it so that it can respond to the questions you want to ask of it and reduce the garbage as much as possible.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_7cKexWoDNAg/Sbx2vO1fvgI/AAAAAAAAAE4/f46HdTjaip4/s1600-h/Decurity_LOGMGT_SIEM_COMBINED.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 300px;" src="http://2.bp.blogspot.com/_7cKexWoDNAg/Sbx2vO1fvgI/AAAAAAAAAE4/f46HdTjaip4/s400/Decurity_LOGMGT_SIEM_COMBINED.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5313252214198746626" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This post is a mirror of my post at http://blog.decurity.com  &lt;br /&gt;&lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_best_practices_combined_log_management_and_siem_architecture_benefits/"&gt;SIEM Best Practices:  Combined Log Management and SIEM Architecture Benefits&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-1517227171230316862?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/hi3FINE521xrB2-LILlVyj-Edr0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/hi3FINE521xrB2-LILlVyj-Edr0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/hi3FINE521xrB2-LILlVyj-Edr0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/hi3FINE521xrB2-LILlVyj-Edr0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=YOOC4Z0I1oc:AkNqfS8JQlg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=YOOC4Z0I1oc:AkNqfS8JQlg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=YOOC4Z0I1oc:AkNqfS8JQlg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=YOOC4Z0I1oc:AkNqfS8JQlg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=YOOC4Z0I1oc:AkNqfS8JQlg:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=YOOC4Z0I1oc:AkNqfS8JQlg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=YOOC4Z0I1oc:AkNqfS8JQlg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/YOOC4Z0I1oc" height="1" width="1"/&gt;</content><link rel="related" href="http://blog.decurity.com/index.php/dec_template/more/siem_best_practices_combined_log_management_and_siem_architecture_benefits/" title="Combined Log Management and SIEM Architecture Benefits" /><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/1517227171230316862/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=1517227171230316862&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/1517227171230316862?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/1517227171230316862?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/YOOC4Z0I1oc/combined-log-management-and-siem.html" title="Combined Log Management and SIEM Architecture Benefits" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_7cKexWoDNAg/Sbx2vO1fvgI/AAAAAAAAAE4/f46HdTjaip4/s72-c/Decurity_LOGMGT_SIEM_COMBINED.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/03/combined-log-management-and-siem.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkMHSHs9cSp7ImA9WxVUEEU.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-6624134848598626510</id><published>2009-02-24T22:35:00.003-06:00</published><updated>2009-03-14T22:40:39.569-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-03-14T22:40:39.569-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SIEM Best Practices" /><category scheme="http://www.blogger.com/atom/ns#" term="SIEM" /><category scheme="http://www.blogger.com/atom/ns#" term="Rocky" /><category scheme="http://www.blogger.com/atom/ns#" term="Decurity" /><category scheme="http://www.blogger.com/atom/ns#" term="ArcSight" /><category scheme="http://www.blogger.com/atom/ns#" term="Log Management" /><title>SIEM Best Practices:  Evaluation Criteria</title><content type="html">SIEM Best Practices:  Evaluation Criteria&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Decurity often has the opportunity to our customers find the right Log Management and/or SIEM solution.  We are honored that our customers trust us with that very important question so we wanted to take a moment and explain our requirements gathering/documentation process for vendor selection and hope that our explanation helps a few of more folks out there!  We also get asked by Vendors on how they can improve their products, but that’s a entirely different blog post.&lt;br /&gt;&lt;br /&gt;In March of 2008 I authored a couple of posts related to SIEM pre-requisites: &lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_bp_basic_implementation_success_criteria/"&gt;SIEM Best Practices: Very Basic SIEM Implementation Success Criteria&lt;/a&gt; and &lt;br /&gt;&lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_bp_before_you_buy/"&gt;SIEM Best Practices: Before you buy&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;In those posts I tried to create a baseline of information customers looking to purchase and implement a SIEM solution should have before engaging the vendors. The point of those posts really boiled down to this idea: You must have a strong set requirements defined up front for the vendors to indicate how they meet that requirement. Allowing the vendors to "work their magic" and define your problems is roughly equivalent to handing them a blank check. Along those lines I wanted to highlight a strategy we employ when helping company’s to define their SIEM requirements by presenting a sample of the categories of questions we ask of the customer and the vendors during evaluation process.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A couple of quick notes before we begin with the listings:&lt;br /&gt;1.) All of this assumes you’ve answered the initial “Key Problems we are trying to solve” question and the answer is something more tangible than to meet PCI,SOX, Audit requirements.&lt;br /&gt;1a.) If events per second (EPS) is your key measurement you are looking at the wrong product set - seek out Log Management Tools first.&lt;br /&gt;2.) It is also important to note that when we perform the evaluation each of these stated technical requirement categories breaks down into a dozen or more actual testing criteria that is prioritized according to your requirements The "Sample Questions" presented are only a very quick overview of the types of questions that fall into that category.&lt;br /&gt;3.) This post is simply highlighting the fact that significant thought should be given to this decision. Don’t worry if you need help – we’re here.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Sample Categories of Requirements to consider:&lt;/span&gt;&lt;br /&gt;Common Requirement Categories&lt;br /&gt;Category (Sample Questions)&lt;br /&gt;Access Control (Application, User, flexibility, inherited controls, etc)&lt;br /&gt;Authentication (LDAP, SSO, AD, Internal, other)&lt;br /&gt;Architecture (Reliable and Scalable)&lt;br /&gt;Event Sources (Supported Technologies and versions, Connection Methods for each, Data Parsing Errors, Normalization Data Loss, Categorization Correctness, Structured/Unstructured Data Handling)&lt;br /&gt;Log Management (Is the Integration Bi-Directional, easy to implement, etc)&lt;br /&gt;Event Forwarding (Security, Methods, Low-Bandwidth options, etc)&lt;br /&gt;Overall Security (System and the data)&lt;br /&gt;External Integrations: (Tool Integration, Ticketing System Integrations, etc)&lt;br /&gt;Storage Requirements (Compression, Costs, Management)&lt;br /&gt;Storage Flexibility (NAS, SAN, Internal, Offline/Online, Tiered Storage)&lt;br /&gt;Data Processing (Internally how does the system handle new event sources with uncommon field requirements "unstructured data")&lt;br /&gt;Installation (Does the solution match our standards?)&lt;br /&gt;Patching and Upgrade (Level of effort required for Minor and Major Versions)&lt;br /&gt;Overall User Experience (Can I see what is important quickly and easily? Can I drill down quickly and intuitively?)&lt;br /&gt;Standard Reporting (Easy, Flexible, Exportable)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Advanced Usage Requirement Categories&lt;/span&gt;&lt;br /&gt;Category (Sample Questions)&lt;br /&gt;Basic Alerting Criteria (Pattern Matching or Aggregation/Counting)&lt;br /&gt;Basic Correlation (IF ,THEN, ELSE, AND, NOT, OR type Statements)&lt;br /&gt;Advanced Correlation (Meta Analysis of enriched and/or raw data across technologies, time and result sets in real time.)&lt;br /&gt;Statistical Analysis (Flexible event statistics that can be used in alerting or to enrich data sets for correlation)&lt;br /&gt;Custom Reporting (Can I create my favorite report or extend it)&lt;br /&gt;Data Mining (Can I easily look for patterns across the entire DB?)&lt;br /&gt;Data Visualization (Can data viz be integrated and does it matter for me?)&lt;br /&gt;Vulnerability Integration (Is the correlation useful for our environment and is the reporting useful?)&lt;br /&gt;Network Modeling (How hard is to model our environment and what value is lost/gained?)&lt;br /&gt;Asset Modeling (Can I easily assign systems to relevant categories and assign priorities, can I update them easily, etc)&lt;br /&gt;User/Activity Modeling (Can we realistically “profile” users or activities and alert on deviations?)&lt;br /&gt;External Threat Feeds (Does the vendor or a partner provide daily updates for Hotlists?)&lt;br /&gt;Built in Mgmt Tools (Does the vendor provide a way of measuring the health of the system?)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Other Important Criterion&lt;/span&gt;&lt;br /&gt;Category (Sample Questions)&lt;br /&gt;Company Performance (This is becoming more and more a key decision factor.)&lt;br /&gt;Support (What can I escalate, response times, expertise, RMA)&lt;br /&gt;Thought Leadership (What is the vision for the technology?)&lt;br /&gt;Training (Do I need 4 weeks of training to use the product? If so how many types of training opportunities are available?)&lt;br /&gt;Services Support (Do I need 12 weeks of Services? How can I guarantee I don’t get the new guy? Is the team compensated on billability or Customer Success?)&lt;br /&gt;Content Updates (How often can I receive content updates? Do I need constant "workshops" to move forward, Are there external providers that can help?)&lt;br /&gt;Licensing Model (Price can be greatly affected by various pricing models, make sure you understand the total cost of all phases of your deployment before you begin).&lt;br /&gt;&lt;br /&gt;This post is a mirror of my personal post on http://blog.decurity.com&lt;br /&gt;&lt;a href="http://blog.decurity.com/index.php/dec_template/more/siem_best_practices_evaluation_criteria/"&gt;http://blog.decurity.com/index.php/dec_template/more/siem_best_practices_evaluation_criteria/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-6624134848598626510?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/jxpYYAZiktgBAuG0oLWAzdoWZhk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jxpYYAZiktgBAuG0oLWAzdoWZhk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/jxpYYAZiktgBAuG0oLWAzdoWZhk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jxpYYAZiktgBAuG0oLWAzdoWZhk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=w-knfiK54fs:HS-ivbHtTyY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=w-knfiK54fs:HS-ivbHtTyY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=w-knfiK54fs:HS-ivbHtTyY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=w-knfiK54fs:HS-ivbHtTyY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=w-knfiK54fs:HS-ivbHtTyY:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=w-knfiK54fs:HS-ivbHtTyY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=w-knfiK54fs:HS-ivbHtTyY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/w-knfiK54fs" height="1" width="1"/&gt;</content><link rel="related" href="http://blog.decurity.com/index.php/dec_template/more/siem_best_practices_evaluation_criteria/" title="SIEM Best Practices:  Evaluation Criteria" /><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/6624134848598626510/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=6624134848598626510&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/6624134848598626510?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/6624134848598626510?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/w-knfiK54fs/siem-best-practices-evaluation-criteria_24.html" title="SIEM Best Practices:  Evaluation Criteria" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/02/siem-best-practices-evaluation-criteria_24.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0YMRH05eCp7ImA9WxVWFE8.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-286631671817026165</id><published>2009-02-20T06:37:00.005-06:00</published><updated>2009-02-23T15:39:45.320-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-02-23T15:39:45.320-06:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SIEM" /><category scheme="http://www.blogger.com/atom/ns#" term="SOC" /><category scheme="http://www.blogger.com/atom/ns#" term="Decurity" /><category scheme="http://www.blogger.com/atom/ns#" term="ArcSight" /><category scheme="http://www.blogger.com/atom/ns#" term="Log Management" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Operations" /><title>Preview of Decurity’s New Enterprise SIEM Subscription Service</title><content type="html">The Decurity team has been incredibly busy over the last few months cooking up new and more cost effective ways to support our mantra of “keeping security simple”.  We’re getting ready to introduce a “game changer” for our Log Management and SIEM customers.  Our newest offering will be fully described in the coming days but here is a preview of the new subscription services Decurity is offering to our clients.   &lt;p&gt;&lt;b&gt;Simplistic overview of the O&amp;amp;M Problems most SIEM customers face:  &lt;/b&gt;&lt;br /&gt;1. Today, many SIEM customers have 2 or more Full Time Engineers (FTE’s) supporting, managing or otherwise dedicated to their SIEM and still find themselves using only a small percentage of the SIEM’s real potential.&lt;br /&gt;2. Many customers know that there is more they can “do” with the SIEM but simply can’t get there from where they currently stand.  Frustration continually builds up.&lt;br /&gt;3. Most customers simply don’t know where to go next after the initial implementation or consulting engagement.&lt;br /&gt;4. Hiring the best SIEM Experts is really, really expensive especially when you factor in all of the downtime caused by change-control or other mission critical tasks that pop-up and waste valuable time. &lt;/p&gt;  &lt;p&gt;&lt;b&gt;Simplified solution overview:  &lt;/b&gt;&lt;br /&gt;1. Decurity will help ensure you purchase the right tool for your needs and ensure the tools are configured optimally for the long-haul. &lt;br /&gt;2. Decurity will provide pre-packaged and custom-built content delivered to you on a recurring basis to help expand your usage of the SIEM and extract the most possible value from the tool.&lt;br /&gt;3. Decurity is there for the long-term, working to understand your changing needs and using our expertise to help guide your efforts accordingly.&lt;br /&gt;4. Decurity leverages the most experienced SIEM team in the industry to deliver these services in a very cost-effective manner.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;A little more detail about what is including in our Enterprise SIEM Subscription Service:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;i&gt;Installation/Expansion:&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;Decurity can help during all phases of your SIEM deployment.  Decurity will work with you to help you define the requirements, guide you through vendor selection, architect the solution, implement or expand on your existing infrastructure.  We partner with you to ensure you receive the best possible advice through the lifecycle of your SIEM deployment.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;i&gt;Quarterly SIEM Healthchecks:&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;As part of this service offering on a quarterly basis Decurity will work with your team to ensure your SIEM is performing at it’s most optimal capacity.  Typically, much of this work can be accomplished remotely further reducing your team’s time and cost commitments.  We’ll quickly identify any issues, offer remediation plans and help you implement any necessary changes. &lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;i&gt;SIEM Content Updates:&lt;/i&gt; &lt;/b&gt;&lt;br /&gt;Our experts will develop SIEM Content to help your analysts more accurately focus on the “Events of Interest” for your organization.  Our solutions are categorized by Event Source and/or by Problem-Set to help you better understand which content will add value to your environment.  Solutions will be updated on a recurring basis (daily, weekly, etc) as new Event Sources, Problem-Sets and Solutions are identified and/or refined.&lt;/p&gt;  &lt;p&gt;&lt;i&gt;Here are some examples of SIEM Content we’ll update/refine for you:&lt;/i&gt;&lt;br /&gt;•  Active Lists:  For Example:  Hot IP’s, Domains - We maintain a list of Hot IP’s and Domains that is updated Daily (as necessary).&lt;br /&gt;•    Active Channels:  Events of Interest, Interesting Analytical Views&lt;br /&gt;•    Data Monitors / Dashboards:  Statistical Analysis, Performance Measurements, Security Status Dashboards&lt;br /&gt;•    Filters: (reusable queries)&lt;br /&gt;•    Reports/Query/Trends:  Reports that focus on measuring success or providing “Actionable Intelligence”&lt;br /&gt;•  Correlaton Rules:  Basic and Advanced Correlation relevant to the Problem-set and customizable to meet your specific organizations needs.&lt;br /&gt;•    Workflow and Notifications&lt;br /&gt;•    Tools:  Integration of tools/macros/scripts&lt;br /&gt;•  Pattern Discovery (Profiles):  (ArcSight Only) By providing new and updated profiles based on Event Sources or problem sets we’ll help you gain the most from this powerful tool!&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;i&gt;Added Value:&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;As part of this offering customers also have the opportunity to submit new problem-sets for us to solve - simply work with us through our support system to understand the problems you are trying to solve and we’ll help you develop customized solutions.  Instead of investing in costly consulting engagements you can leverage this service to create solutions.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;i&gt;Log Management and SIEM integration Support&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;We’ll help you most effectively use your Log Management and SIEM tools to complement and enhance the overall value of both solutions!&lt;br /&gt;We’ll ensure from the the data is intelligently processed providing you with the information you need but not killing your SIEM and overwhelming your team.  From the Event Source through the “collector” into your Log Management Solution and finally as it reached your SIEM we’ll work with you to ensure the right information is collected, stored, forwarded and analyzed to maximize functionality and overall value by reducing storage/processing costs.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;i&gt;Summary:&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;No matter where you stand with your SIEM deployment Decurity’s Subscription service will benefit you greatly.  If you’re just getting started we’ll save you the 2 years of frustration your peers enjoyed.  If you’re more mature in your SIEM efforts we can help ensure you’re really getting all the value you possibly can from your system.  Our goal is to make this as simple as possible so that you can work on the output of the SIEM and take action to protect your enterprise.  We’ll make the SIEM work FOR you!  &lt;/p&gt;  &lt;p&gt;&lt;i&gt;Sales Information:&lt;/i&gt;  We want to work with you to understand your needs and will be more than happy to schedule some time to talk more about how Decurity can help you with your SIEM and Log Management needs.  Please send us an email at sales at decurity dot com with any questions you might have and we’ll get back to you (usually the same day).  &lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;i&gt;About Decurity:&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;Decurity supports the Fortune 500 Globally and many US Government customers on a true enterprise scale.  We are focused solely on Security Operation including the usage SIEM and Log Management Solutions to enhance the Incident Response Process.  Our experts have been responsible for hundreds of Log Management and SIEM implementations across the world.  We will do what it takes to make you successful! &lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The preceding has been a repost of my blog entry at:  http://blog.decurity.com/index.php/dec_template/more/preview_of_decuritys_new_subscription_service/&lt;br /&gt;&lt;br /&gt;Update 1 (23 Feb 2009) :  Updated http://www.decurity.com reference link:  &lt;a href="http://www.decurity.com/SIEM_SUBSCRIPTION_OVERVIEW.html"&gt;http://www.decurity.com/SIEM_SUBSCRIPTION_OVERVIEW.html&lt;/a&gt; &lt;br /&gt;The webpage offers additional explanation about the initial rollout of this service offering which is centered on the Arcsight ESM and ArcSight Logger products.  Future releases will offer support for products such as Splunk, Symantec SIM, RSA Envision, etc.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-286631671817026165?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/BHFmqDIHPLSg_drRwm2z3thFS8M/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/BHFmqDIHPLSg_drRwm2z3thFS8M/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/BHFmqDIHPLSg_drRwm2z3thFS8M/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/BHFmqDIHPLSg_drRwm2z3thFS8M/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Y8Kd2NPf2vc:0BpgrqKwx2k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Y8Kd2NPf2vc:0BpgrqKwx2k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=Y8Kd2NPf2vc:0BpgrqKwx2k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Y8Kd2NPf2vc:0BpgrqKwx2k:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Y8Kd2NPf2vc:0BpgrqKwx2k:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=Y8Kd2NPf2vc:0BpgrqKwx2k:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=Y8Kd2NPf2vc:0BpgrqKwx2k:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/Y8Kd2NPf2vc" height="1" width="1"/&gt;</content><link rel="related" href="http://blog.decurity.com/index.php/dec_template/more/preview_of_decuritys_new_subscription_service" title="Preview of Decurity’s New Enterprise SIEM Subscription Service" /><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/286631671817026165/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=286631671817026165&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/286631671817026165?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/286631671817026165?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/Y8Kd2NPf2vc/preview-of-decuritys-new-enterprise.html" title="Preview of Decurity’s New Enterprise SIEM Subscription Service" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2009/02/preview-of-decuritys-new-enterprise.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkMHSHs8eCp7ImA9WxVUEEU.&quot;"><id>tag:blogger.com,1999:blog-3454348359976120052.post-2186950801521206161</id><published>2008-11-26T00:35:00.001-06:00</published><updated>2009-03-14T22:40:39.570-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-03-14T22:40:39.570-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Decurity" /><title>SIEM:  The Quickening Begins</title><content type="html">&lt;p&gt;Though unlike Highlander, I hope that in the end there can be more than one.  SIEM is NOT dead, but if High-Tower’s recent announcement is any indication it certainly will become a thinner herd in the very near future.  &lt;/p&gt; &lt;p&gt;How many vendors have both viable solutions and can realistically survive in SIEM and/or Log Management for the long-term?  ArcSight, RSA EnVision, NetForensics, Q1 Labs, CA, NetIQ, Symantec, eIQNetworks, Splunk, Cisco, IBM, Nitro Security, TriGeo, Tenable, Log Logic, LogRhythm, Intellitactics, Sensage, Exaprotect, Alertlogic, Checkpoint, Novell and IBM.  Not to mention MSSP specific solutions or vendors I may have missed. &lt;/p&gt;&lt;p&gt;A few years ago there was a period of acquisitions / consolidation (Cyber Wolf, E-Security, Micromuse/GuardedNet) but &lt;a href="http://www.socaltech.com/high_tower_software_shuts_down/s-0018681.html" title="if this article from socaltech.com is correct"&gt;if this article from socaltech.com is correct&lt;/a&gt; than this is the first outright collapse from a SIEM product company that I can think of off the top of my head.  High Tower had reinvented itself over the past 18 months from the ground up.  They had some very dedicated and talented folks on staff.  When they rebuilt CINXI they had a simple but relatively effective tool for the SMB marketplace.  Most importantly to me they always seemed passionate about making life better for their customers.  That moves me to another train of thought....  &lt;/p&gt;&lt;p&gt;  &lt;/p&gt;&lt;p&gt;&lt;b&gt;SIEM: Time to re-focus?&lt;/b&gt;&lt;br /&gt;In my mind that “passion” for customer success is what the SIEM market sorely needs again. The main focus of many vendors has turned to targeting smaller companies and/or providing specifically branded solutions striving to solve all the world’s problems related to PCI, etc. &lt;/p&gt;&lt;p&gt;  &lt;/p&gt;&lt;p&gt;It seems to me that the magic SIEM once had, has been lost.  The “magic” was the partnership that existed between the vendor and the customer where the entire vendor organization pushed relentlessly for customer success!  The vendor would sit with the customer and pull use-cases (teeth) from the customer.  Then together they would develop customized solutions to those defined problemsets.  The initial process might take weeks or even months to accomplish because it is a learning effort for the customer but the level of trust, understanding, collaboration and overall value to the entire security team is tangible.  Thinking through how to define the necessary data elements, ensure time sync is in place, obtain and centralize the data, refine analysis processes, enact acl’s, create reports and facilitate actions is a difficult but crucial element to ensuring your can effectively monitor and identify incidents on your network.  &lt;/p&gt;&lt;p&gt;  &lt;/p&gt;&lt;p&gt;&lt;b&gt;What needs to happen?&lt;/b&gt;&lt;br /&gt;The vendors need to make the products easier right from the start and work constantly to add value to the overall solution.  We need to help the customer understand the value of the event sources they have in place today and which event sources add value in conjunction with current/planned event sources.  What information can remain in the log management solution and what is best feed to the SIEM? What are common problemsets/solutions and how can they be enhanced/updated more frequently?  We need to collaborate better and level the playing field for the “good guys” for a change. &lt;/p&gt;&lt;p&gt;&lt;b&gt;SIEM has significant value:  &lt;/b&gt;&lt;br /&gt;Implementing a SIEM correctly forces you to look at and specifically address all of these issues mentioned earlier.  SIEM also provides benefits including enterprise-wide changes in enterprise visibility, log standards, time sync, IT and business unit collaboration, reporting and overall security posture.  It certainly doesn’t hurt that the efficiency and overall effectiveness of your security team greatly enhanced by having a good process, comprehensive enterprise visibility, the right tools and trained professionals!  &lt;/p&gt;&lt;p&gt;&lt;b&gt;Summary:&lt;/b&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt; There are a ton of Log Management and SIEM vendors and the smaller ones will continue to be bought or fail through the next 12-18 months.  &lt;/li&gt;&lt;li&gt; The Log Management and/or SIEM solutions you put in place need to be driven by real world and well defined problem-sets and you do need to worry about long term viability of the company, many won’t exist this time next year. &lt;br /&gt;&lt;/li&gt;&lt;li&gt;Both Log Management and SIEM are tools that fit into an overall process within your organization and the entire process needs love to be successful! &lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3454348359976120052-2186950801521206161?l=securityoperations.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Oc0F2eBTJkGOrsuRpD0c6z0tIxY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Oc0F2eBTJkGOrsuRpD0c6z0tIxY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Oc0F2eBTJkGOrsuRpD0c6z0tIxY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Oc0F2eBTJkGOrsuRpD0c6z0tIxY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=epyCJnunnkI:jjQ9WR3p85g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=epyCJnunnkI:jjQ9WR3p85g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=epyCJnunnkI:jjQ9WR3p85g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=epyCJnunnkI:jjQ9WR3p85g:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=epyCJnunnkI:jjQ9WR3p85g:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/blogspot/OGTr?a=epyCJnunnkI:jjQ9WR3p85g:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/blogspot/OGTr?i=epyCJnunnkI:jjQ9WR3p85g:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/OGTr/~4/epyCJnunnkI" height="1" width="1"/&gt;</content><link rel="related" href="http://blog.decurity.com/index.php/dec_template/more/siem_the_quickening_begins/" title="SIEM:  The Quickening Begins" /><link rel="replies" type="application/atom+xml" href="http://securityoperations.blogspot.com/feeds/2186950801521206161/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3454348359976120052&amp;postID=2186950801521206161&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/2186950801521206161?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3454348359976120052/posts/default/2186950801521206161?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/OGTr/~3/epyCJnunnkI/siem-quickening-begins.html" title="SIEM:  The Quickening Begins" /><author><name>Visible Risk</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityoperations.blogspot.com/2008/11/siem-quickening-begins.html</feedburner:origLink></entry></feed>

