<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: atlanta]]></title>
    <link>http://securityratty.com/tag/atlanta</link>
    <description></description>
    <pubDate>Mon, 19 May 2008 07:25:54 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[AT&T Extends Free Wi-Fi to Cheapest DSL Plans]]></title>
      <link>http://securityratty.com/article/856e4c3817e07dfbb28fe42f32fd57e9</link>
      <guid>http://securityratty.com/article/856e4c3817e07dfbb28fe42f32fd57e9</guid>
      <description><![CDATA[AT&amp;T seems to have added free Wi-Fi for its lowest-priced DSL customers: The Atlanta Journal-Constitution is the only one with this story, and they've garbled a few of the details, but checking AT&amp;T's...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.ajc.com/business/content/business/stories/2008/09/16/att_internet_service.html"><strong>AT&T seems to have added free Wi-Fi for its lowest-priced DSL customers:</strong></a> The Atlanta Journal-Constitution is the only one with this story, and they've garbled a few of the details, but checking AT&T's public sites seems to confirm it. Previously, AT&T customers had to either have a fiber-optic U-Verse subscription, or a DSL line running at 1.5 Mbps downstream or faster to get free Wi-Fi Basic. The Basic pool covers most of the 17,000 U.S. hotspots, excluding some hotels and premium locations.</p>

<p>AT&T <a href="http://www.att.com/gen/general?pid=5949"><strong>now says</strong></a> that any "FastConnect" subscription, even its DSL Lite offering of 768 Kbps down/128 Kbps up, qualifies for Wi-Fi Basic. The new statement reads: "AT&T Wi-Fi Basic service is FREE and already included if you subscribe to AT&T High Speed Internet, AT&T U-verseSM High Speed Internet, or AT&T FastAccess&reg; DSL&mdash;all speed plans included.</p>

<p>There's still a $10 per month fee to upgrade to Wi-Fi Premier, which includes over 70,000 locations worldwide, along with the missing U.S. hotspots, but their Web site says that you have to have a 1.5 Mbps or faster connection to get the $10 per month upgrade. That may be out of date. That ordering page also says you need 1.5 Mbps or faster for free Wi-Fi, so that tends to confirm it hasn't been fixed. (It's even hosted at sbc.com, so perhaps that's part of the vestige of an older system, harder to update.)</p>

<p>Please note that iPhone subscribers still don't get free Wi-Fi on AT&T's Basic network.</p>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 09:30:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/free wi-fi basic">free wi-fi basic</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <category domain="http://securityratty.com/tag/att customers">att customers</category>
      <category domain="http://securityratty.com/tag/att u-versesm">att u-versesm</category>
      <category domain="http://securityratty.com/tag/wi-fi basic">wi-fi basic</category>
      <category domain="http://securityratty.com/tag/speed internet">speed internet</category>
      <category domain="http://securityratty.com/tag/faster">faster</category>
      <source url="http://wifinetnews.com/archives/008445.html">AT&amp;T Extends Free Wi-Fi to Cheapest DSL Plans</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Routing Out an Address; Badger-Fi]]></title>
      <link>http://securityratty.com/article/47e82ddcf180a1e8e117a5087166b7f3</link>
      <guid>http://securityratty.com/article/47e82ddcf180a1e8e117a5087166b7f3</guid>
      <description><![CDATA[Slashdot breathlessly posts an item by coderrr that Skyhook Wireless is exposing people's addresses: Yeah, whatever. Skyhook has accidentally offered an API that lets you query their Wi-Fi positioning...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://hardware.slashdot.org/article.pl?sid=08/09/12/1255218"><strong>Slashdot breathlessly posts an item by coderrr that Skyhook Wireless is exposing people's addresses:</strong></a> Yeah, whatever. Skyhook has accidentally offered an API that lets you query their Wi-Fi positioning system for latitude and longitude using a MAC address. Skyhook constantly drives major cities around the world and integrates scans created by users of their systems as well. The poster defines a non-existent problem: first, a scammer needs to get someone's MAC address; then you need to pair a rough lat/long with their street address; then, coderrr says, you'd get a phishing email with your home address. Whatever. If my machine is compromised enough that you can obtain my MAC address and then launch a phishing attack, I have worse problems already than my street address being in the email--which is unlikely given that most Wi-Fi scans will be in urban areas. It's likely Skyhook will modify their systems to prevent submission of such queries, or perhaps open their API further.</p>

<p><a href="http://badgerherald.com/news/2008/09/12/atlanta_firm_buys_ci.php"><strong>Madison Wi-Fi network sold to Atlanta firm:</strong></a> Xiocom purchases Mad City Broadband, a firm that has suffered significant criticism over the performance of its Wi-Fi network in Madison, Wisc. The press release from Xiocom (some quoted in the Badger Herald article) are a bit over the top about a network that reportedly has few users, inconsistent performance, and covers only a fraction of the city.</p>]]></content:encoded>
      <pubDate>Fri, 12 Sep 2008 07:34:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi network">wi-fi network</category>
      <category domain="http://securityratty.com/tag/madison wi-fi network">madison wi-fi network</category>
      <category domain="http://securityratty.com/tag/madison">madison</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/mac address">mac address</category>
      <category domain="http://securityratty.com/tag/skyhook">skyhook</category>
      <category domain="http://securityratty.com/tag/skyhook wireless">skyhook wireless</category>
      <category domain="http://securityratty.com/tag/skyhook constantly">skyhook constantly</category>
      <source url="http://wifinetnews.com/archives/008437.html">Wee-Fi: Routing Out an Address; Badger-Fi</source>
    </item>
    <item>
      <title><![CDATA[Start-up Purewire offers managed security service for Web users]]></title>
      <link>http://securityratty.com/article/68d6c5898332b44c492f232d5da22d2a</link>
      <guid>http://securityratty.com/article/68d6c5898332b44c492f232d5da22d2a</guid>
      <description><![CDATA[Atlanta-based start-up Purewire marks its debut today with a managed security service aimed at protecting enterprise Internet users from being victimized by Web-based attacks...]]></description>
      <content:encoded><![CDATA[Atlanta-based start-up Purewire marks its debut today with a managed security service aimed at protecting enterprise Internet users from being victimized by Web-based attacks online.]]></content:encoded>
      <pubDate>Sun, 03 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security service aimed">security service aimed</category>
      <category domain="http://securityratty.com/tag/enterprise internet users">enterprise internet users</category>
      <category domain="http://securityratty.com/tag/start-up purewire marks">start-up purewire marks</category>
      <category domain="http://securityratty.com/tag/attacks online">attacks online</category>
      <category domain="http://securityratty.com/tag/debut">debut</category>
      <source url="http://www.networkworld.com/news/2008/080408-purewire-managed-security-service.html?fsrc=rss-security">Start-up Purewire offers managed security service for Web users</source>
    </item>
    <item>
      <title><![CDATA[Security Through Visibility - Montego, Lancope and NetFlow]]></title>
      <link>http://securityratty.com/article/03c1f11d6787944e11b9ab1baec0352e</link>
      <guid>http://securityratty.com/article/03c1f11d6787944e11b9ab1baec0352e</guid>
      <description><![CDATA[We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments. This is because it is extremely challenging to see...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments.&nbsp; This is because it is extremely challenging to see what is going on at a micro vs. macro level within a virtual environments network.&nbsp; The virtualization vendors such as VMWare and Citrix have provided embedded tools into their management consoles that show a macro level of visibility but its not enough to identify security events in the environment.&nbsp; Take a look at the attached picture.&nbsp; It simply shows VMWare's ability to monitor virtual network performance statistics from a bits per second perspective.</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/performancescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Performancescreen" title="Performancescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/performancescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
<br />&lt;-Click To Enlarge</p>

<p>With only this level of detail how can one determine which network applications are causing spikes.&nbsp; Is it FTP traffic that is occuring at a high volume at an unuseal time of day?&nbsp; If that were occuring, could that be indicative of either a breach or some sort of problem? What if FTP isn't even an authorized service in the virtual environment but there is a high volume of it?&nbsp; Did someone install a rouge FTP service so they could steal information from the server at will? </p>

<p>These types of questions can't really be answered without a micro level of detail into the packets flowing in, out and within the virtual environment.&nbsp; Now, what I am highlighting is not security in the traditional sense of prevention but using visibility as a means to first identify, then pin point the source of an issue so that it can properly be mitigated.&nbsp; Having constant visibility can also ensure that other security products in the environment are performing as expected.&nbsp; What if a Montego HyperSwitch with firewalling enabled is configured with many policies but someone forgot to create an FTP block policy.&nbsp; One could think they are protected from rouge FTP services transmiting data out of the network, but without constant visibility monitoring, can you be certain?</p>

<p>Some vendors, namely Reflex Security will get you to believe that their IPS / IDS solution that is inline and running in the virtual environment is the right and only approach.&nbsp; Or they will tell you to hang a virtual IDS off a span port in the virtual environment and you will at least have visibility into the attacks that are taking place.&nbsp; Well, sure... You now have attack visibility but at the performance cost of your virtual environment.&nbsp; Signature matching technologies are great, I'm a huge believer; however they don't scale very well in shared computing environments such as virtual ones.&nbsp; IDS systems also don't typically track protocol and network service (FTP, HTTP, etc.) utilizations; which is another important part of visibility.</p>

<p>So, what do we do to gain visibility without the performance headache?&nbsp; Well, for starters its probably best to put your IDS/IPS solutions in the physical environment where performance will be less of a concern.&nbsp; In fact, you can span a virtual switch's traffic out to a physical NIC as easy as you can to a virtual one.&nbsp; So why do it virtual and have to pay a 60% CPU utilization tax?&nbsp; Another solution is to IDS inspect only the things you care about.&nbsp; Why IDS inspect SSL traffic if you know your solution can't unencrypt SSL.&nbsp; Its just a waste of compute cycles isnt it?&nbsp; Policy based switching helps you with directing only the things you care about to an IDS (attack visualization product).&nbsp; Montego's HyperSwitch also can help you with the traffic redirection of only the things you care about. </p>

<p>Another method of visibility which I tend to be a fan of is one of packet analysis (aka NetFlow).&nbsp; NetFlow was invented by Cisco some time ago and has gained popularity in the physical world and definately has a use in the virtual world.&nbsp; NetFlow is lightweight.&nbsp; Let me say that again, its light weight!&nbsp; It only sends a summation of packet detail to an analytical engine which can do some number crunching, packet comparison, etc. etc. to make some sense out of whats going on.&nbsp; <a href="http://www.lancope.com">Lancope</a>, an Atlanta based visibility company that provides Network Visibility, Security Visibility and User Visibility has this tool on their website that is a Netflow Bandwidth calculator.&nbsp; You'll see from playing with this ( <a href="http://www.lancope.com/netflowcalculator.aspx">http://www.lancope.com/netflowcalculator.aspx</a> ) calculator that it doesn't consume a lot of network bandwidth to transmit these network accounting records.&nbsp; It also doesn't cause a lot of CPU overhead to send these records to an analytical engine sitting somewhere in the network.</p>

<p>Lancope's analytical engines have the ability to do the following for you within your virtual environment:</p><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta name="ProgId" content="PowerPoint.Slide" /><meta name="Generator" content="Microsoft PowerPoint 11" /><title><p>&lt;p&gt;Slide 3&lt;/p&gt;</p></title><meta name="Description" content="7/30/2008" /><style>
.O
	{color:black;
	font-size:149%;}
a:link
	{color:#CC9900 !important;}
a:active
	{color:#9B2D1F !important;}
a:visited
	{color:#96A9A9 !important;}
</style><style media="print">
&amp;lt;!--.sld
	{left:0px !important;
	width:6.0in !important;
	height:4.5in !important;
	font-size:103% !important;}
--&amp;gt;
</style><o:shapelayout v:ext="edit"></o:shapelayout><o:idmap v:ext="edit" data="1"></o:idmap><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9">&nbsp;</p:colorscheme><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9"><div v:shape="_x0000_s1026" class="O">

<ol><li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert network behavior of VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Track Vmotion movement of VMs accross physical servers</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert on communication between VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify users accessing VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify unauthorized or rouge VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert when VM’s go online or offline
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify network services running on VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor Network / Application performance of VMs<br />Display active hosts accessing VMs</span></li></ol>















<div></div>

</div>

</p:colorscheme><p>...and probably a slew of other things I'm not aware of.&nbsp; A screen shot of their product is bellow:</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/lancopescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Lancopescreen" title="Lancopescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/lancopescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a> &lt;- Click to enlarge</p>

<p>You'll notice from the screenshot that you are able to visualize who is talking to who, how much traffic they have sent and received and something called a concern index (not seen on this screenshot).</p>

<p>Now, a concern index is a number that increases as Lancopes analytical engines monitor suspicious activity on a session.&nbsp; A high counter can be indicative of a security problem.&nbsp; Its another way of identifying (visualizing) compromised hosts (virtual machines) without having to do signature matching like a heavy weight IPS engine.&nbsp; Example:&nbsp; Lets say you have a VM that has a BOT on it and is &quot;owned&quot;.&nbsp; The Lancope product is monitoring this long life session.&nbsp; Let's say that session is established for several hours or maybe even days or months.&nbsp; Lets also say that the conversation appears to be mostly unidirectional from a public ip address not belonging to your enterprise.&nbsp; Lancope would increase a the concern index on this since this server hasn't typically had this type of behavior.&nbsp; Once the concern index reached a certain level it could then fire off an email, send you a text message or something saying:&nbsp; <strong>Warning, Warning, Danger, Danger Will Robinson!!! You're virtual server may be infected with a BOT, please investigate immediately!!!</strong></p>

<p>This example is VISIBILITY which helps you with SECURITY.&nbsp; There are a number of other things you can do with NetFlow and Lancope products that have less to do with security and more to do with operational efficiencies.&nbsp; Things like, helping you answer questions of:&nbsp; How do I know what network applications are taking up the most bandwidth?&nbsp; When should I move those applications over to a server with more horsepower?&nbsp; When did these VM's vmotion over here and was there a traffic condition / CPU condition that caused that to occur?&nbsp; I could go on and on but thats a topic for another blog entry.</p>

<p>So, my suggestion is to take a look at what NetFlow has to offer.&nbsp; Montego Networks supports NetFlow transmission and Lancope supports NetFlow analytics and with both you can regain what was lost visibility.</p>

<p>I hope this was helpful to you all!</p>

<p>-John Peterson</p></div>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 17:57:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network visibility">network visibility</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/environments">environments</category>
      <category domain="http://securityratty.com/tag/virtual environments network">virtual environments network</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/network bandwidth">network bandwidth</category>
      <category domain="http://securityratty.com/tag/bandwidth">bandwidth</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/350982407/security-throug.html">Security Through Visibility - Montego, Lancope and NetFlow</source>
    </item>
    <item>
      <title><![CDATA[Security Through Visibility - Montego, Lancope and NetFlow]]></title>
      <link>http://securityratty.com/article/5b6ed1101dc183f8ebcfa1e481566982</link>
      <guid>http://securityratty.com/article/5b6ed1101dc183f8ebcfa1e481566982</guid>
      <description><![CDATA[We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments. This is because it is extremely challenging to see...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments.&nbsp; This is because it is extremely challenging to see what is going on at a micro vs. macro level within a virtual environments network.&nbsp; The virtualization vendors such as VMWare and Citrix have provided embedded tools into their management consoles that show a macro level of visibility but its not enough to identify security events in the environment.&nbsp; Take a look at the attached picture.&nbsp; It simply shows VMWare's ability to monitor virtual network performance statistics from a bits per second perspective.</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/performancescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Performancescreen" title="Performancescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/performancescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
<br />&lt;-Click To Enlarge</p>

<p>With only this level of detail how can one determine which network applications are causing spikes.&nbsp; Is it FTP traffic that is occuring at a high volume at an unuseal time of day?&nbsp; If that were occuring, could that be indicative of either a breach or some sort of problem? What if FTP isn't even an authorized service in the virtual environment but there is a high volume of it?&nbsp; Did someone install a rouge FTP service so they could steal information from the server at will? </p>

<p>These types of questions can't really be answered without a micro level of detail into the packets flowing in, out and within the virtual environment.&nbsp; Now, what I am highlighting is not security in the traditional sense of prevention but using visibility as a means to first identify, then pin point the source of an issue so that it can properly be mitigated.&nbsp; Having constant visibility can also ensure that other security products in the environment are performing as expected.&nbsp; What if a Montego HyperSwitch with firewalling enabled is configured with many policies but someone forgot to create an FTP block policy.&nbsp; One could think they are protected from rouge FTP services transmiting data out of the network, but without constant visibility monitoring, can you be certain?</p>

<p>Some vendors, namely Reflex Security will get you to believe that their IPS / IDS solution that is inline and running in the virtual environment is the right and only approach.&nbsp; Or they will tell you to hang a virtual IDS off a span port in the virtual environment and you will at least have visibility into the attacks that are taking place.&nbsp; Well, sure... You now have attack visibility but at the performance cost of your virtual environment.&nbsp; Signature matching technologies are great, I'm a huge believer; however they don't scale very well in shared computing environments such as virtual ones.&nbsp; IDS systems also don't typically track protocol and network service (FTP, HTTP, etc.) utilizations; which is another important part of visibility.</p>

<p>So, what do we do to gain visibility without the performance headache?&nbsp; Well, for starters its probably best to put your IDS/IPS solutions in the physical environment where performance will be less of a concern.&nbsp; In fact, you can span a virtual switch's traffic out to a physical NIC as easy as you can to a virtual one.&nbsp; So why do it virtual and have to pay a 60% CPU utilization tax?&nbsp; Another solution is to IDS inspect only the things you care about.&nbsp; Why IDS inspect SSL traffic if you know your solution can't unencrypt SSL.&nbsp; Its just a waste of compute cycles isnt it?&nbsp; Policy based switching helps you with directing only the things you care about to an IDS (attack visualization product).&nbsp; Montego's HyperSwitch also can help you with the traffic redirection of only the things you care about. </p>

<p>Another method of visibility which I tend to be a fan of is one of packet analysis (aka NetFlow).&nbsp; NetFlow was invented by Cisco some time ago and has gained popularity in the physical world and definately has a use in the virtual world.&nbsp; NetFlow is lightweight.&nbsp; Let me say that again, its light weight!&nbsp; It only sends a summation of packet detail to an analytical engine which can do some number crunching, packet comparison, etc. etc. to make some sense out of whats going on.&nbsp; <a href="http://www.lancope.com">Lancope</a>, an Atlanta based visibility company that provides Network Visibility, Security Visibility and User Visibility has this tool on their website that is a Netflow Bandwidth calculator.&nbsp; You'll see from playing with this ( <a href="http://www.lancope.com/netflowcalculator.aspx">http://www.lancope.com/netflowcalculator.aspx</a> ) calculator that it doesn't consume a lot of network bandwidth to transmit these network accounting records.&nbsp; It also doesn't cause a lot of CPU overhead to send these records to an analytical engine sitting somewhere in the network.</p>

<p>Lancope's analytical engines have the ability to do the following for you within your virtual environment:</p><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta name="ProgId" content="PowerPoint.Slide" /><meta name="Generator" content="Microsoft PowerPoint 11" /><title><p>&lt;p&gt;Slide 3&lt;/p&gt;</p></title><meta name="Description" content="7/30/2008" /><style>
.O
	{color:black;
	font-size:149%;}
a:link
	{color:#CC9900 !important;}
a:active
	{color:#9B2D1F !important;}
a:visited
	{color:#96A9A9 !important;}
</style><style media="print">
&amp;lt;!--.sld
	{left:0px !important;
	width:6.0in !important;
	height:4.5in !important;
	font-size:103% !important;}
--&amp;gt;
</style><o:shapelayout v:ext="edit"></o:shapelayout><o:idmap v:ext="edit" data="1"></o:idmap><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9">&nbsp;</p:colorscheme><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9"><div v:shape="_x0000_s1026" class="O">

<ol><li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert network behavior of VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Track Vmotion movement of VMs accross physical servers</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert on communication between VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify users accessing VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify unauthorized or rouge VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert when VM???s go online or offline
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify network services running on VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor Network / Application performance of VMs<br />Display active hosts accessing VMs</span></li></ol>















<div></div>

</div>

</p:colorscheme><p>...and probably a slew of other things I'm not aware of.&nbsp; A screen shot of their product is bellow:</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/lancopescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Lancopescreen" title="Lancopescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/lancopescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a> &lt;- Click to enlarge</p>

<p>You'll notice from the screenshot that you are able to visualize who is talking to who, how much traffic they have sent and received and something called a concern index (not seen on this screenshot).</p>

<p>Now, a concern index is a number that increases as Lancopes analytical engines monitor suspicious activity on a session.&nbsp; A high counter can be indicative of a security problem.&nbsp; Its another way of identifying (visualizing) compromised hosts (virtual machines) without having to do signature matching like a heavy weight IPS engine.&nbsp; Example:&nbsp; Lets say you have a VM that has a BOT on it and is &quot;owned&quot;.&nbsp; The Lancope product is monitoring this long life session.&nbsp; Let's say that session is established for several hours or maybe even days or months.&nbsp; Lets also say that the conversation appears to be mostly unidirectional from a public ip address not belonging to your enterprise.&nbsp; Lancope would increase a the concern index on this since this server hasn't typically had this type of behavior.&nbsp; Once the concern index reached a certain level it could then fire off an email, send you a text message or something saying:&nbsp; <strong>Warning, Warning, Danger, Danger Will Robinson!!! You're virtual server may be infected with a BOT, please investigate immediately!!!</strong></p>

<p>This example is VISIBILITY which helps you with SECURITY.&nbsp; There are a number of other things you can do with NetFlow and Lancope products that have less to do with security and more to do with operational efficiencies.&nbsp; Things like, helping you answer questions of:&nbsp; How do I know what network applications are taking up the most bandwidth?&nbsp; When should I move those applications over to a server with more horsepower?&nbsp; When did these VM's vmotion over here and was there a traffic condition / CPU condition that caused that to occur?&nbsp; I could go on and on but thats a topic for another blog entry.</p>

<p>So, my suggestion is to take a look at what NetFlow has to offer.&nbsp; Montego Networks supports NetFlow transmission and Lancope supports NetFlow analytics and with both you can regain what was lost visibility.</p>

<p>I hope this was helpful to you all!</p>

<p>-John Peterson</p></div>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 17:57:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network visibility">network visibility</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/environments">environments</category>
      <category domain="http://securityratty.com/tag/virtual environments network">virtual environments network</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/network bandwidth">network bandwidth</category>
      <category domain="http://securityratty.com/tag/bandwidth">bandwidth</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <source url="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/07/security-throug.html">Security Through Visibility - Montego, Lancope and NetFlow</source>
    </item>
    <item>
      <title><![CDATA[Your 419 Mail Roundup]]></title>
      <link>http://securityratty.com/article/cac739eb23af3ee3d5ecd500b5815c6f</link>
      <guid>http://securityratty.com/article/cac739eb23af3ee3d5ecd500b5815c6f</guid>
      <description><![CDATA[A handful of scam mails currently in circulation, including one mention of &quot;groundnut oil&quot; that seems so bizarre I had to highlight it in bold text. All this and more, after the jump
Subject
FROM THE...]]></description>
      <content:encoded><![CDATA[
        A handful of scam mails currently in circulation, including one mention of "groundnut oil" that seems so bizarre I had to highlight it in bold text. All this and more, after the jump...<br />  
        Subject:<br />FROM THE DESK OF MR. STEVEN JAMES<br />From:<br />"Steven James"&lt;steven@fristbnkngplc.net&gt;<br />Date:<br />Mon, 30 Jun 2008 19:17:03 +0100<br />BCC:<br /><br />FROM THE DESK OF MR. STEVEN JAMES<br />CHAIRMAN INTERNATIONAL RELATION<br />FIRST BANK OF NIGERIA PLC<br /># 1 BANK ROAD WUSE FCT <br />ABUJA-NIGERIA.<br />PHONE: +234-80-66520277<br />Email: stevenjames809@live.co.uk&nbsp; <br /><br /><br />Very Urgent Attention,<br /><br />Please permit me to introduce my humble self to you, my name is Mr. Steven James, I am the Manager of International Relation with First Bank of Nigeria Plc, I 'm 38yrs old, and I got your email address from a friend of mine, and my confidence reposed on you. I hope you read this message carefully and reply me immediately. Although we have not met before, but I suggest that this transaction will bring us together.<br /><br />My dear, we had a customer, a foreigner but base here in Nigeria, his Name was Mr. Hamilton Creek. He is from Atlanta Georgia United State of America, but based here with his wife and his two children, Mr. Hamilton has being banking with us for the past 4yrs and some time in August 2002, Mr. Hamilton was on his way to his house, and <b>unfortunately ran into a Trailer load of Groundnut Oil, and died&nbsp;&nbsp; immediately, Their car got burnt, no single soul was saved, Mr. Hamilton Creek and His entire family was confirmed dead.</b><br /><br />My Board of Directors and the Management of First Bank has mandated and instructed me to look for Mr. Hamilton Creek? Relation(s) and his Next of&nbsp; Kin to come and claim his fund, Since August 2003 till date, I have been looking for his relation's or his next of Kin to come and claim his fund which he Deposited with our bank, I have contacted his Embassy and after 3days, his Ambassador told me that Mr. Hamilton Creek has no relation and no next of Kin, their Ambassador told me that he used his first son as His next of kin, but it is quite unfortunate that Mr. Hamilton Creek Died with all his family members.<br /><br />The reason why I contacted you is thus, Mr. Hamilton is dead, and his only son who supposed to inherit his properties and money also died with him. As at this moment, nobody or person[s] is coming to&nbsp;&nbsp; claim this Money from our bank. The Board of Directors and management of our bank told me that if nobody or person[s] apply for the claim of Mr. Hamilton Fund, the bank will return the entire Fund into our Federal reserve. In the Light of the above, I want you to stand as the next of kin to Late Mr. Hamilton Creek; it might interest you to know that he had a Domiciliary Bank Account with our Bank and he has a total sum of US$9.2M Nine Million Two Hundred thousand Dollars, this is the exact amount which he had in his domiciliary account before the ugly incident occurred, and this money is still in his account as unclaimed money.<br /><br />This transaction is very easy and simple, and it is 100% risk free, I'm the Manager for International Relations with First Bank of Nigeria Plc, and the Management and Board of Directors of the Bank are waiting for me to provide to them the Relation or next of Kin to late Mr. Hamilton Creek, of which I told them that I am still searching the next of kin to the deceased. Finally, if you are interested with this transaction, I will front you to the bank as the only next of kin to late Mr. Hamilton Creek, and I will let the bank know that you are the only right person to inherit Late Mr. Hamilton Funds and properties. If you are interested, just email me or call me on my&nbsp;&nbsp; direct and private line#: +234-80-27536038 and late Mr. Hamilton's Funds will be credited into your account and all his Properties will be released to you either through Courier Services or the Bank will Cargo all his properties to you in any were you want it.<br /><br />So reply me immediately and feel free to ask any question with regards to this transaction. You will take 50% of the US$9.2M. Which is? US$4.600, 000.00 Four Million Six Hundred Thousand Dollars, while the Balance of the same amount will be mine.<br /><br />Your swift response will be highly appreciated.<br /><br />Thanks and have a nice day.<br /><br />Friendly Regards<br /><br />Mr. Steven James<br /><br />*******************************************************************************************<br /><br />Subject:<br />REPRESENTATIVE NEEDED<br />From:<br />DFS SALES LTD UK &lt;info@dfs.net&gt;<br />Date:<br />Tue, 01 Jul 2008 23:00:55 +0800<br />To:<br />undisclosed-recipients: ;<br /><br /><br />COMPLIMENT OF THE DAY TO YOU.<br /><br />I am PETER WOODS from DFS SALES LTD UK.(<br />Website: www.dfs-online.co.uk ) Visit our site<br /><br />We are into&nbsp; furnitures and we sell shares to people in<br />Canada,America, Australia and Europe.<br /><br />We are in need of a book keeper. someone who can represent our company<br />in his/her country.<br /><br />Our client in your location will contact you and make the company<br />payment to you.<br /><br />You will be entitle to 11% of every payment been made out to you.<br /><br />This is because most of our officer are from china and they do not<br /><br />understand english very well.its hard for them to contact our<br />customers.<br /><br />Our head office is located in CHINA. But we have a sub-office in the<br />uk.<br /><br />If you are interested, Kindly send the entries for more understanding.<br /><br />NAME IN FULL :.........<br />COMPANY NAME: .....<br />POSITION:......<br />FULL ADDRESS: .......<br />CITY/TOWN:........<br />STATE:............<br />ZIP CODE:........<br />COUNTRY:.......<br />MOBILE:.......<br />HOME TEL: .....<br />EMAIL ADDRESS: ........<br />OCCUPATION: ...........<br />BANK NAME :.......<br />AGE:............<br /><br />You are to send the above details to<br /><br />NAME : PETER WOODS.<br />EMAIL : dfs_woods@yahoo.co.uk<br />PHONE NUMBER : +44-704-575-0212<br /><br />HOPE TO HEAR FROM YOU<br /><br /><br />*****************************************************************************************<br /><br />To:<br />undisclosed-recipients:;<br /><br />Good day!!!<br /><br />&nbsp;We have been waiting for you since to contact me for your Confirmable Bank Draft of ?18 Million (Eighteen Million Pounds sterling) but we did not hear from you since for a couple of weeks now. Then we went to the bank to confirm if the draft that expired or getting near to expire and Metropolitan Police Uk told us that before the funds will get to your hand that it will expire.So I told him to cash the ?18 Million (Eighteen Million Pounds sterling) to cash payment to avoid losing this fund under expiration as I will be out of the country for a 6 Months Course.<br /><br />&nbsp;What you have to do now is to contact FED EX COURIER SERVICES as soon as possible to know when they will deliver of your funds to you because of the expiring date. For your information we have paid for the delivering Charge Insurance premium. The only money you will send to the FED EX COURIER SERVICES to deliver your cheque direct to your postal Address in your country is ?250.00 being Security Keeping Fee of the Courier Company so far. Again don't be deceived by anybody to pay any other money except ?250.00 for the Security Keeping Fee.We would have paid that but they said no because they don't know when you will contact them and in case of demurrage. You have to contact FED EX COURIER SERVICES now for the delivery of your Draft with this<br />information below:<br /><br />&nbsp;CONTROLLER: Mrs.Helen Williams<br />&nbsp;NAME: FED EX COURIER SERVICES<br />&nbsp;ADDRESS: fedexofficeuk@gmail.com<br />&nbsp;PHONE NUMBER: +447024080684<br /><br />&nbsp;IF YOU ARE THE OWENER OF THE FUNDS AND YOU WILL SEND YOUR INFORMATION TO US SO THAT WE CAN DELIVERY YOUR FUNDS TO YOU WITHIN THE NEXT 84HRS TIME.IF YOU DO NOT RECEIVED YOUR FUNDS WITHIN THE NEXT 72HRS TIME AND YOU REPORT US THE UK FBI AND THE METROPOLITAN POLICE (SCOTLAND YARD) or YOU CONTACT YOUR LAWYER TO TAKE UP PROCEDURES AGAINST US.<br /><br />&nbsp;Let me repeat again try to contact them as soon as you receive this mail to avoid any further delay and remember to pay them their Security keeping fee of ?250.00 for their immediate action. The FED EX COURIER SERVICES don't know the contents of the funds. This is to avoid them delaying with the funds.<br /><br />&nbsp;Thanks as you contact them today.<br /><br />&nbsp;Yours Faithfully<br /><br />&nbsp;Mrs Helen Williams.<br /><br /><b>(The above actually comes with a nifty graphic that they've thrown in, thinking it makes it all look more legitimate. It doesn't, but here it is anyway):</b><br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fedx1.jpg" src="http://blog.spywareguide.com/images/fedx1.jpg" class="mt-image-none" style="" height="64" width="472" /></span>
<br /><br />....altogether now: oooooh. A slightly shorter 419 roundup than usual, but I'm sure I'll have piles of the things next week.<br /><br /><br /><div class="moz-text-plain" wrap="true" graphical-quote="true" style="font-family: -moz-fixed; font-size: 13px;" lang="x-cyrillic"><pre wrap=""><br /><br /><br /><br /><br /></pre></div><div><br /></div>
    ]]></content:encoded>
      <pubDate>Wed, 02 Jul 2008 13:11:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hamilton fund">hamilton fund</category>
      <category domain="http://securityratty.com/tag/hamilton">hamilton</category>
      <category domain="http://securityratty.com/tag/hamilton creek">hamilton creek</category>
      <category domain="http://securityratty.com/tag/draft">draft</category>
      <category domain="http://securityratty.com/tag/confirmable bank draft">confirmable bank draft</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/domiciliary bank account">domiciliary bank account</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/hamilton funds">hamilton funds</category>
      <source url="http://blog.spywareguide.com/2008/07/your-419-mail-roundup-1.html">Your 419 Mail Roundup</source>
    </item>
    <item>
      <title><![CDATA[The Wee Bonny Has a Blog]]></title>
      <link>http://securityratty.com/article/500926383ebd85e56063452a0944d8f3</link>
      <guid>http://securityratty.com/article/500926383ebd85e56063452a0944d8f3</guid>
      <description><![CDATA[My friend, the Wee Bonny Graydon McKee, has his own company and a new blog. Graydon is from Atlanta, helps us teach with the Potomac Forum, and just finished his Masters in Information Assurance....]]></description>
      <content:encoded><![CDATA[<p>My friend, the Wee Bonny Graydon McKee, has his own company and a new blog.  Graydon is from Atlanta, helps us teach with the Potomac Forum, and just finished his Masters in Information Assurance.  Pretty good guy all around.  Check him out at <a href="http://www.ascensionriskmanagement.com/BlogOne/" target="_blank">Ascension Risk Management</a> and fire up your RSS reader.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/425&amp;title=The+Wee+Bonny+Has+a+Blog" title="Add 'The Wee Bonny Has a Blog' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'The Wee Bonny Has a Blog' to Del.icio.us" alt="Add 'The Wee Bonny Has a Blog' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/425&amp;title=The+Wee+Bonny+Has+a+Blog" title="Add 'The Wee Bonny Has a Blog' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'The Wee Bonny Has a Blog' to digg" alt="Add 'The Wee Bonny Has a Blog' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/425&amp;title=The+Wee+Bonny+Has+a+Blog" title="Add 'The Wee Bonny Has a Blog' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'The Wee Bonny Has a Blog' to reddit" alt="Add 'The Wee Bonny Has a Blog' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=The+Wee+Bonny+Has+a+Blog&amp;url=http://www.guerilla-ciso.com/archives/425&amp;version=0.7" title="Add 'The Wee Bonny Has a Blog' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'The Wee Bonny Has a Blog' to Feed Me Links" alt="Add 'The Wee Bonny Has a Blog' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/425" title="Add 'The Wee Bonny Has a Blog' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'The Wee Bonny Has a Blog' to Technorati" alt="Add 'The Wee Bonny Has a Blog' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/425&amp;t=The+Wee+Bonny+Has+a+Blog" title="Add 'The Wee Bonny Has a Blog' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'The Wee Bonny Has a Blog' to Yahoo My Web" alt="Add 'The Wee Bonny Has a Blog' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/425&amp;title=The+Wee+Bonny+Has+a+Blog" title="Add 'The Wee Bonny Has a Blog' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'The Wee Bonny Has a Blog' to Stumble Upon" alt="Add 'The Wee Bonny Has a Blog' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/425&amp;title=The+Wee+Bonny+Has+a+Blog" title="Add 'The Wee Bonny Has a Blog' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'The Wee Bonny Has a Blog' to Google Bookmarks" alt="Add 'The Wee Bonny Has a Blog' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/425" title="Add 'The Wee Bonny Has a Blog' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'The Wee Bonny Has a Blog' to Squidoo" alt="Add 'The Wee Bonny Has a Blog' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/425" title="Add 'The Wee Bonny Has a Blog' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'The Wee Bonny Has a Blog' to Bloglines" alt="Add 'The Wee Bonny Has a Blog' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=ZElmCI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=ZElmCI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=HOTnwi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=HOTnwi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/321367798" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 10:40:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ascension risk management">ascension risk management</category>
      <category domain="http://securityratty.com/tag/information assurance">information assurance</category>
      <category domain="http://securityratty.com/tag/rss reader">rss reader</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/potomac forum">potomac forum</category>
      <category domain="http://securityratty.com/tag/friend">friend</category>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <category domain="http://securityratty.com/tag/atlanta">atlanta</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/321367798/425">The Wee Bonny Has a Blog</source>
    </item>
    <item>
      <title><![CDATA[Laptop stolen from the home of a BearingPoint employee]]></title>
      <link>http://securityratty.com/article/cdacc39a32caa98a264d6e52be4b661f</link>
      <guid>http://securityratty.com/article/cdacc39a32caa98a264d6e52be4b661f</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/5/08

Organization
BearingPoint, Inc

Contractor/Consultant/Branch
None

Victims
Independent BearingPoint contractors

Number Affected
Unknown

Types...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/bearingpoint.jpg" width="166" align="right" height="81"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/5/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.bearingpoint.com/portal/site/bearingpoint">BearingPoint, Inc.</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Independent BearingPoint contractors<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"first and last name and Social Security Number"<br><br><span style="font-weight: bold;">Breach Description:</span><br>On May 14, 2008 a BearingPoint company-issued laptop was stolen from the residence of an employee.&nbsp; The laptop contained sensitive personal information belonging to a number of BearingPoint independent contractors.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.oag.state.md.us/idtheft/Breach%20Notices/ITU-153117.pdf">The Maryland State Attorney General breach notification</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The Maryland State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>BearingPoint recognizes the importance of safeguarding the personal information it handles in the course of conducting business.<br><span style="font-style: italic;">[Evan] As demonstrated on their web site.&nbsp; The number "8" followed by "The number of years in a row that identity theft has been the #1 internet crime"</span><br><br><img src="http://images.quickblogcast.com/95781-88451/8.jpg" width="576" border="0"><br><br><br><img src="http://images.quickblogcast.com/95781-88451/8y.jpg" width="576" border="0"><br><br>To that end, we have implemented safeguards for the information.<br><span style="font-style: italic;">[Evan] OK, I am following so far.</span><br><br>Even the most rigorous safeguards, however, can not guarantee protection against criminal conduct.<br><span style="font-style: italic;">[Evan] Well, I think "rigorous safeguards" needs to be quantified somewhat.&nbsp; What are "rigorous safeguards" and how do they apply to this breach?</span><br><br>The Company was recently victimized by such conduct and we are writing to inform you that this criminal conduct might have a direct impact on you.<br><span style="font-style: italic;">[Evan] Uh oh, here it comes.&nbsp; Not only was "The Company" recently victimized, but just as importantly, the owners of the personal information were victimized as well.</span><br><br>On May 14, 2008, the residence of one of our employees was burglarized and the company-issued laptop computer was taken amongst other personal property.<br><br>The employee promptly reported the theft to the Atlanta Police Department, which is investigating the break in.<br><br>The investigation into the burglary is on-going and BearingPoint is cooperating fully.<br><br>BearingPoint worked diligently to reconstruct the information stored on the stolen laptop.<br><br>BearingPoint has been able to determine that the computer contains the name and social security number of independent contractors.<br><span style="font-style: italic;">[Evan] Recognizing the importance of safeguarding personal information, is storing personal information on a laptop (presumably without encryption due to the fact that there is no mention of it) a prudent practice?</span><br><br>The stolen laptop did not contain credit or debit card numbers, or financial account numbers.<br><span style="font-style: italic;">[Evan] So a criminal would have to open his/her own accounts using the other information that WAS on the laptop.</span><br><br>We have no reason to believe that the information stored on the stolen laptop was the target of the burglary or that the information has been misused.<br><br>The personal information on the laptop can be accessed only with two passwords and two forms of authentication.<br><span style="font-style: italic;">[Evan] The "passwords" are the authentication.&nbsp; I am guessing that BearingPoint meant two forms of identification (probably usernames).&nbsp; Again, I am guessing that one of the username/passwords is for the operating system itself which takes less than 10 minutes to bypass in most instances and I am guessing that the other username/password combination is file access for which there are known workarounds in many common applications (Word, Excel, PowerPoint, etc.).&nbsp; Either way, I think that this excerpt is meant to minimize the situation with a strong bias towards saving face.</span><br><br>In addition, the personal information was not stored in a single file or spreadsheet but dispersed among numerous files.<br><span style="font-style: italic;">[Evan] Information security personnel know better than to argue the security through obscurity defense.</span><br><br>To date, we have received no report indicating that the information stored on the laptops has been accessed or misused.<br><span style="font-style: italic;">[Evan] I think "laptops" in the breach notification is a typo</span><br><br>BearingPoint recognizes this development, and any related inconvenience, might be upsetting.<br><br>We regret this incident has occurred and we apologize for any inconvenience it may cause you.<br><br>As a result of this incident, we have taken immediate steps to review our current policies and procedures to further enhance security for personal data we handle and to reduce the risk of recurrence.<br><span style="font-style: italic;">[Evan] Restrict ability to store confidential information on mobile devices?&nbsp; Encryption?&nbsp; Two-factor authentication?</span><br><br>To lessen the potential inconvenience to you and reduce the risk that you might be subjected to attempts to steal your identity, we have engaged ConsumerInfo.com Inc., and Experian company, to provide you with one year of credit monitoring, at no cost to you.<br><br>Please contact BPt-FMGOICPrivacy@bearingpoint.com should you have additional questions regarding the cirumstance of the incident.<br><br>BearingPoint currently anticipates notifying affected individuals on or before June 6, 2008, of this incident.<br><br><span style="font-weight: bold;">Commentary:</span><br>Marketing on the BearingPoint web site boasts "BearingPoint has demonstrated some of the biggest advancements in risk consulting services among the large number of providers in this market" - Forrester Wave: Risk Consulting Services, Q2, June 2007 Report.&nbsp; <br><br>It is disappointing to read about a well-respected company losing control of confidential information, but what makes this worse is the fact that it happened through the actions of a leading information security and risk consulting company.&nbsp; It is important to point out that one incident <span style="font-weight: bold;">DOES NOT</span> define a company. <br><br>No encryption or mention of it as a matter of policy, and the attempts to minimize the possible impact by mentioning ineffective controls (passwords and obscurity) is troubling. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/19/bearingpoint.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 19 Jun 2008 11:38:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/bearingpoint">bearingpoint</category>
      <category domain="http://securityratty.com/tag/store confidential information">store confidential information</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/independent contractors">independent contractors</category>
      <source url="http://breachblog.com/2008/06/19/bearingpoint.aspx">Laptop stolen from the home of a BearingPoint employee</source>
    </item>
    <item>
      <title><![CDATA[Heading to a Long Weekend of Dance]]></title>
      <link>http://securityratty.com/article/3fb6bcbba89c218f247e8edf40e95a76</link>
      <guid>http://securityratty.com/article/3fb6bcbba89c218f247e8edf40e95a76</guid>
      <description><![CDATA[After many days, weeks and months of working on various customer and company projects, Im taking the weekend off ! (Yes, I usually work weekends and use the time to read, review and catch up
Most of...]]></description>
      <content:encoded><![CDATA[<p>After many days, weeks and months of working on various customer and company projects, <strong>I&#8217;m taking the weekend off</strong>! (Yes, I usually work weekends and use the time to read, review and catch up.)</p><p>Most of my dance peeps have already trekked down to Atlanta for the 2008 <a class="offsite-link-inline" href="http://www.usagrandnationals.com/" target="_blank">USA Grand Nationals </a>&nbsp;Dance Comp- a professional show of <strong>Shag</strong> and <strong>West Coast Swing</strong> dancers from across the country. I&#8217;ll be heading out in just a few hours with one of my friends to join the flock.</p><p>In case you haven&#8217;t kept up with previous posts, I used to compete in Shag (looong ago), then American Ballroom and, most recently, West Coast Swing. This event is the perfect spot to see fellow friends and dancers from today and yesteryear.</p><p>Because of my work schedule, I&#8217;ve taken a bit of a hiatus for the past couple of years. I won&#8217;t be competing here, but it&#8217;s a great competition to watch and the best group of people around!</p><p>I&#8217;m excited and I hope to get back on the photo-taking bus and have lots of fun and goofy shots to share next week.</p><p># # #</p><p>&nbsp;</p>
]]></content:encoded>
      <pubDate>Fri, 23 May 2008 10:37:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/west coast">west coast</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <category domain="http://securityratty.com/tag/fellow friends">fellow friends</category>
      <category domain="http://securityratty.com/tag/looong ago">looong ago</category>
      <category domain="http://securityratty.com/tag/perfect spot">perfect spot</category>
      <category domain="http://securityratty.com/tag/previous posts">previous posts</category>
      <category domain="http://securityratty.com/tag/american ballroom">american ballroom</category>
      <category domain="http://securityratty.com/tag/weekend">weekend</category>
      <category domain="http://securityratty.com/tag/company projects">company projects</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/5/23/heading-to-a-long-weekend-of-dance.html">Heading to a Long Weekend of Dance</source>
    </item>
    <item>
      <title><![CDATA[Welcome to Microsoft Carric Dooley]]></title>
      <link>http://securityratty.com/article/bedf0fb71fcae03b2062233e123bc10c</link>
      <guid>http://securityratty.com/article/bedf0fb71fcae03b2062233e123bc10c</guid>
      <description><![CDATA[If you are a Lost fan, people keep appearing on the Island. Whats really happening?) Carric and I have worked together for the last 8 years. I first saw customers reverence for him when I moved to...]]></description>
      <content:encoded><![CDATA[(If you are a Lost fan, people keep appearing on the Island. What&#8217;s really happening?)
Carric and I have worked together for the last 8 years. I first saw customers reverence for him when I moved to Atlanta while working for ISS in 2000. Carric was a contractor at Coke and I was explicitly told by [...]]]></content:encoded>
      <pubDate>Mon, 19 May 2008 07:25:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/carric">carric</category>
      <category domain="http://securityratty.com/tag/lost fan">lost fan</category>
      <category domain="http://securityratty.com/tag/customers reverence">customers reverence</category>
      <category domain="http://securityratty.com/tag/explicitly">explicitly</category>
      <category domain="http://securityratty.com/tag/island">island</category>
      <category domain="http://securityratty.com/tag/moved">moved</category>
      <category domain="http://securityratty.com/tag/iss">iss</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/atlanta">atlanta</category>
      <source url="http://securitybuddha.com/2008/05/19/welcome-to-microsoft-carric-dooley/">Welcome to Microsoft Carric Dooley</source>
    </item>
  </channel>
</rss>
