<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: colleague]]></title>
    <link>http://securityratty.com/tag/colleague</link>
    <description></description>
    <pubDate>Sat, 26 Jul 2008 03:01:30 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[You may not even know it, but a Bodyguard may be protecting your colleague as you work.]]></title>
      <link>http://securityratty.com/article/b854f696580e858bbb700b07fed3a181</link>
      <guid>http://securityratty.com/article/b854f696580e858bbb700b07fed3a181</guid>
      <description><![CDATA[I just came across an excellent workplace violence article written by Seattlepi.com reporter, Andrea James

The article raises many points that I am sure many of us have or would overlook if it was...]]></description>
      <content:encoded><![CDATA[I just came across an excellent workplace violence article written by <a href="http://seattlepi.nwsource.com/business/384364_domesticviolence22.html">Seattlepi.com reporter, Andrea James.</a><br /><span id="fullpost"><br />The article raises many points that I am sure many of us have or would overlook if it was not brought to our attention.  The director of New Beginnings, a Seattle based non-profit that provides advocacy and shelter for victims made the point that while going home after a hard day's work is something that many employees look forward to, for victims of domestic abuse, work is the only place that provides them safety and a sanctuary from a tortured home life.<br /><br /></span><br />Our company is frequently requested by employers to provide covert bodyguards for employees with domestic problems at home.  The reason for this is due to the fact that physical violence at home, quite often spills into the workplace by the abuser and when that happens, the liklihood of the domestic partner and other co-workers getting hurt or even killed is very real.<br /><br />Employers know that they have a responsibility to keep the workplace safe so they hire companies like ours to have trained personal protection specialists blend in at the place of empoyment and watch out for the identified threat.  Just about 100% of the time the victim of the abuse is a female employee but this article and the comments that follow show that males also suffer from domestic violence.  <br /><br />It is the opinion of our company that we will see even more workplace violence, domestic and otherwise, as companies continue to practice cost cutting tactics like downsizing and layoffs due to the worsening economy.  Other related predictions would be thefts from the workplace, increase in fraud and embezzlement, an increase in Resume/CV fabrications as more and more people compete for fewer jobs.<br /><br />This all goes to show that employers have to be more astute and procative in making sound hiring decisions, being alert for internal theft and abuse and being proactive when it comes to workplace violence.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 26 Oct 2008 09:33:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/workplace safe">workplace safe</category>
      <category domain="http://securityratty.com/tag/workplace">workplace</category>
      <category domain="http://securityratty.com/tag/domestic">domestic</category>
      <category domain="http://securityratty.com/tag/domestic violence">domestic violence</category>
      <category domain="http://securityratty.com/tag/workplace violence">workplace violence</category>
      <category domain="http://securityratty.com/tag/domestic partner">domestic partner</category>
      <category domain="http://securityratty.com/tag/home life">home life</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/provide covert bodyguards">provide covert bodyguards</category>
      <source url="http://www.thebulletproofblog.com/2008/10/you-may-not-even-know-it-but-bodyguard.html">You may not even know it, but a Bodyguard may be protecting your colleague as you work.</source>
    </item>
    <item>
      <title><![CDATA[Fraud Detection in Financial Services Reloaded]]></title>
      <link>http://securityratty.com/article/ded3c6e73beb9af7e3aaa5abae657b06</link>
      <guid>http://securityratty.com/article/ded3c6e73beb9af7e3aaa5abae657b06</guid>
      <description><![CDATA[I read an interesting post bythe former CTO of out-of-business Kaskad Technology , where event processing colleague Colin Clark respectfully disagrees with my assesement of the (lack of) capabilitesin...]]></description>
      <content:encoded><![CDATA[<p>I read an <a href="http://colinclarkeventprocessing.com/?p=154" target="_blank">interesting post</a> by the former CTO of <a href="http://rulecore.com/CEPblog/?p=279" target="_blank">out-of-business Kaskad Technology</a>, where event processing colleague Colin Clark respectfully disagrees with my assesement of the (lack of) capabilites in current-generation &#8220;CEP engines&#8221; for detecting complex fraud in financial services.  I&#8217;ll respond with a quote from my September 2007 post,  <a title="End Users Should Define the CEP Market." rel="bookmark" href="http://www.thecepblog.com/2007/12/17/end-users-should-define-the-cep-market/"><span style="color: #105cb6;">End Users Should Define the CEP Market.</span></a></p>
<blockquote><p><em>&#8220;Experienced end users are very intelligent. </em></p>
<p><em>These end users know the complex event processing problems they need to solve; and they know the limitations of the current COTS approaches marketed by the CEP community.  Even in Thailand, a country many of you might mistakenly think is not very advanced technologically, there are experts in telecommunications (who run large networks) who are working on very difficult fraud detection applications, and they use neural networks and say the results are very good.   However, there is not one CEP vendor, that I know of, who offers true CEP capability in the form of neural nets. </em></p>
<p><em>Almost every major bank, telco, etc. has the same opinion, and the same problem. They need much more capability than streaming joins, selects and rules to solve their complex event processing problems that Dr. Luckham outlined in his book.   The software vendors are attempting to define the CEP market to match their capability; unfortunately, their capabilities do not meet the requirements of the vast majority of end users who have CEP problems to solve.</em></p>
<p><em>If the current CEP platforms were truely solving complex event processing problems, annual sales would be orders of magnitudes higher.  Hence, the users have already voted.   The problem is that the CEP community is not listening.&#8221;</em></p></blockquote>
<p>Not to be overly repetitive,  but the last part of this quote from a year ago is worth highlighting:</p>
<blockquote><p><em>&#8220;If the current CEP platforms were truely solving complex event processing problems, annual sales would be orders of magnitudes higher.  Hence, the users have already voted.   The problem is that the CEP community is not listening.&#8221;</em></p></blockquote>
<p>Frankly speaking, nothing in the &#8220;CEP world&#8221; has changed, technologically speaking, since this September 2007 post was written.  From a sales perspective, we have seen less CEP-related sales in 2008 than in prior years.   If these so called CEP products were actually capability of detecting &#8220;real&#8221; complex network-centric situations (threats) in real-time, they would be selling faster than a cup of ice water in the blazing hot Sahara desert.</p>
<p>Don&#8217;t shoot the messenger.  Build better detection engines!</p>
<p>On the other hand, maybe complex detection is too hard for most of these companies and that is why they focus on routing, mediation and relatively simple rule-based scenarios, versus complex event processing?</p>
]]></content:encoded>
      <pubDate>Sat, 20 Sep 2008 18:36:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/versus complex event">versus complex event</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/cep products">cep products</category>
      <category domain="http://securityratty.com/tag/cep community">cep community</category>
      <category domain="http://securityratty.com/tag/cep vendor">cep vendor</category>
      <category domain="http://securityratty.com/tag/current cep platforms">current cep platforms</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/sales">sales</category>
      <source url="http://www.thecepblog.com/2008/09/20/fraud-detection-in-financial-services-reloaded/">Fraud Detection in Financial Services Reloaded</source>
    </item>
    <item>
      <title><![CDATA[Sorry, Qantas, No Unfettered Broadband]]></title>
      <link>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</link>
      <guid>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</guid>
      <description><![CDATA[Qantas backs off from earlier plans, changes provider for in-flight broadband: The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://www.smh.com.au/news/travel/qantas-limits-access-to-web/2008/09/17/1221330929870.html"><strong>Qantas backs off from earlier plans, changes provider for in-flight broadband:</strong></a> The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its in-flight broadband plans. Aeromobile was the provider when the service <a href="http://www.breakingtravelnews.com/article.php?story=2007081609481129&query=qantas"><strong>was tested in second quarter 2007</strong></a>, but OnAir is now described as the airline's partner. This was noted by colleague Fabio Zambelli, who emailed me the news, and <a href="http://www.setteb.it/content/view/4742"><strong>has his own account</strong></a> at 7BIT (in Italian).</p>

<p><a href="http://www.onair.aero/index.php?pid=123"><strong>OnAir</strong></a> has so far tested their calling/texting-only service on two aircraft--one operated by Air France, one by TAP Portugal--even though RyanAir announced plans that its planes would started being unwired with the service by late 2007. Still no word on that fleet progress.</p>

<p>Qantas will apparently launch cached Web browsing and limited Web email (probably through a proxy) along with instant messaging, with full Internet service coming "later in 2009." This is clearly due to a lack of satellite coverage that was just remediated a few weeks ago (see below). The first plane with limited service, a new A380, should be in flight 20-October-2008.</p>

<div style="float:right; margin:0px; padding-left: 10px; padding-bottom: 0px;"><p><img src="http://wifinetnews.com//images/2008/SorryQantas.jpg" alt="SorryQantas.jpg" border="0" width="100" height="152"></p><p style="font-size: 10px">I hate in-flight<br/>broadband</p></div>To Qantas' credit, note that each seat on the plane will have a laptop opower socket, a USB port, and a multimedia system that can show 100 movies and 500 TV show episodes, play the contents of 1,000 CDs and 20 radio stations, and offer 80 games. 

<p>The Morning Herald seems to overstate the importance and scope of a complaint filed by the union representing American Airlines' flight attendants. The detailed coverage in the U.S. had more to do with the potential for issues, and likely attendants lack of interest in policing yet another media on the plane. Filtering doesn't work, the attendants probably already know, and this may just be a negotiating point with the airline.</p>

<p>On why Qantas is waiting until late 2009? This requires unwinding how OnAir gets its signal.</p>

<p>Aeromobile and OnAir both rely on Inmarsat satellites for their service. Both companies had several years ago staked their futures on the fourth-generation network Inmarsat was to inaugurate with three satellites that would use beamforming to allow precise delivery of nearly 500 Kbps per receiver, with hundreds or thousands of regions being able to be targeted from a single satellite. Inmarsat's third-gen network--don't confuse this with 3G cellular ground-based networks--can deliver about 64 Kbps per channel.</p>

<p>Now, unfortunately, Inmarsat was three years late on launching its trans-Pacific bird. While the company <a href="http://www.inmarsat.com/About/Newsroom/Press/00021465.aspx?language=EN&textonly=False"><strong>claims 85 percent coverage of the earth</strong></a> and 98 percent coverage of population, there's a big gap over the Pacific that also prevents them from having good overlap between the U.S. and Japan/China/Korea, as well as the southern Pacific, covering Australia. Since the biggest market for long-haul flights would likely be Australia, Japan, and China, traveling trans-Pacific or trans-hemispheric routes, that gap is rather large.</p>

<p>Aeromobile opted to build out a service, deployed only by Emirates airline as far as I can tell, that uses the 3G service since it was available, and most necessary equipment is already installed on most over-water planes. OnAir was waiting for 4G, which has necessitated a long wait, but allowed them to launch in Europe with a seemingly next-generation service. Given that OnAir is controlled by an airline-owned integration firm, SITA, and by Airbus, they're not going anywhere.</p>

<p>Inmarsat finally <a href="http://spaceflightnow.com/proton/i4f3/"><strong>lofted its third satellite on Baikonur Cosmodrome in Kazakhstan</strong></a> on 19-August-2008, and the launch and separation was reported as successful. Previously, the company has needed up to a year to verify and deploy its 4G satellites. (You can <a href="http://forum.nasaspaceflight.com/index.php?topic=12380.105"><strong>read extremely close coverage of the launch</strong></a> at a Web site devoted to space enthusiasm.)</p>

<p>However, the dirty little secret about Inmarsat's BGAN is that it costs a fortune to heft bandwidth across it. Thus, in-flight broadband over BGAN, if it's ever available, is going to be changed on an extremely high per-MB rate. None of the providers want to say this. This is in contrast to Row 44 (and, once, Connexion by Boeing), which relies on leased Ku-band transponders where they can fix costs and they require high volumes to keep per-bit costs efffectively low.</p>

<p>OnAir's launch of calling on Air France's service involves paying a few euros per minute for calls, which might help you understand what data costs could ultimately run.</p>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 06:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/satellite coverage">satellite coverage</category>
      <category domain="http://securityratty.com/tag/coverage">coverage</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service involves">service involves</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/in-flight broadband plans">in-flight broadband plans</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/inmarsat satellites">inmarsat satellites</category>
      <category domain="http://securityratty.com/tag/inmarsat">inmarsat</category>
      <source url="http://wifinetnews.com/archives/008448.html">Sorry, Qantas, No Unfettered Broadband</source>
    </item>
    <item>
      <title><![CDATA[On The History of Event Processing: Global Network Monitoring]]></title>
      <link>http://securityratty.com/article/0a39883e48015e3b5b486ebc5391de1e</link>
      <guid>http://securityratty.com/article/0a39883e48015e3b5b486ebc5391de1e</guid>
      <description><![CDATA[In A Short History of Complex Event Processing. Part 1: Beginnings , David Luckham opens his history discussion by saying
Event processing has been going on for more than fifty years
However, in On...]]></description>
      <content:encoded><![CDATA[<p>In <a title="A Short History of Complex Event Processing.  Part 1: Beginnings" rel="bookmark" href="http://complexevents.com/?p=321">A Short History of Complex Event Processing. Part 1: Beginnings</a>, David Luckham opens his history discussion by saying;</p>
<blockquote><p>&#8220;Event processing has been going on for more than fifty years.&#8221;</p></blockquote>
<p>However, in <a href="http://epthinking.blogspot.com/2008/08/on-event-processing-as-discipline-and.html" target="_blank">On Event Processing as a Discipline and Some Subsets</a> another colleague mistakenly blogs,</p>
<blockquote><p><em>&#8220;&#8230; <span>people who dealt in this area [network management and event correlation] have never investigated event processing in the larger sense (e.g. looking at additional patterns), and this area has also not spawned the event processing discipline.&#8221;</span></em></p></blockquote>
<p>If you examine just one page from the <a href="http://pavg.stanford.edu/cep/" target="_blank">CEP history at Stanford</a>, researchers there outlined their view of the future applications for CEP, as follows:</p>
<ul>
<li>Instant Insight  - hierarchical event viewing applied to the Enterprise IT layer.
<ul>
<li><a href="http://pavg.stanford.edu/cep/instantinsightpaper.pdf">Analysing business processes</a></li>
</ul>
</li>
<li><a href="http://pavg.stanford.edu/cep/netviewer-presentation.ppt" target="_blank">Network Level Monitoring and Management</a></li>
<li><a href="http://pavg.stanford.edu/ID/">Cyber Security: Network Intrusion Detection</a></li>
<li>Enterprise Monitoring and Management</li>
<li><a href="http://pavg.stanford.edu/cep/final-version-131102.pdf">Modeling and Simulation of Collaborative Business Processes </a></li>
<li>Business Policy Monitoring</li>
<li>Analysis and Debugging of Distributed Systems</li>
</ul>
<p>These applications areas mentioned by Stanford researchers, including Professor Luckham, support and validate our recent discussion <a title="Magic Quadrant for IT Event Correlation and Analysis, 2007" rel="bookmark" href="http://www.thecepblog.com/2008/08/26/magic-quadrant-for-it-event-correlation-and-analysis-2007/"><span style="color: #105cb6;">Magic Quadrant for IT Event Correlation and Analysis, 2007</span></a> where we concluded that <em>&#8220;event correlation and event analysis is Gartner’s closest magic quadrant (MQ)  [...] relates directly to complex event processing (and event processing in general).&#8221;  </em></p>
<p>If you take a detailed look at the 1999 CEP presentation, <a href="http://pavg.stanford.edu/cep/netviewer-presentation.ppt" target="_blank">Defeating Large Scale Attacks: Technology and Strategies for Global Network Monitoring</a> you will readily see that our colleagues are incorrect when they says that event correlational and network management folks have never investigated event processing in the &#8220;larger sense&#8221;.  For example, the 1999 slides above, Stanford, slide 6, is titled &#8220;Complex Event Processing,&#8221; defining CEP from the application perspective of event correlation;</p>
<p><em>Complex Event Processing</em></p>
<ul>
<li>Accept network ‘events’ from any source
<ul>
<li>CISCO NetFlow FlowCollector, tcpdump</li>
</ul>
</li>
<li>Correlates events based on content and temporal relationship between events</li>
<li>Event Processing Agents (EPAs) connected in an Event Processing Network (EPNs)</li>
<li>Both post-mortem and real-time processing</li>
</ul>
<p>This single event correlational project example from David&#8217;s team at Stanford examined the challenging event correlation problems in the context of hierarchical events, maps, patterns, visualization tools, event processing models, patterns languages, network management abstraction layers, and more.  Those core event processing problems from this 1999 example, very large and complex then, still exist today and are much more large and complex - precisely why it is called &#8220;complex event processing.&#8221;</p>
<p>It is quite obvious, in just this one example, that many folks have been looking at event correlation as a motivating application for event processing, in a larger context, for a long time, contrary to what our colleagues write in their &#8220;history of event processing&#8221; posts.  </p>
<p>In a future post I will completely debuke these event processing &#8220;history revisionists.&#8221;   I will illustrate very clearly how the history of event processing goes back at least a decade, and perhaps two (twenty years) before the history outlined in posts like <a href="http://epthinking.blogspot.com/2008/08/on-research-and-practice-in-event.html" target="_blank">On Research and Practice in Event Processing</a> and <a href="http://www.eventstreamprocessing.com/cep-history.htm" target="_blank">The History of Complex Event Processing</a>. </p>
<p>David Luckam stated that the art-and-science of event processing goes back around 50 years. </p>
<p>I am not sure I will go all the way back to 1960 in my next post on the history of event processing.  However,  I will go back at least to the early days of Internet Protocol (IP) networking and illustrate why distributed IP networking, network management and network security, is one of the key  motivating factors for what we now call &#8220;event processing&#8221; and &#8220;complex event processing.&#8221;</p>
]]></content:encoded>
      <pubDate>Sat, 30 Aug 2008 06:17:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/event correlational">event correlational</category>
      <category domain="http://securityratty.com/tag/event correlation problemsin">event correlation problemsin</category>
      <category domain="http://securityratty.com/tag/core event">core event</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/event correlation">event correlation</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/hierarchical event">hierarchical event</category>
      <source url="http://www.thecepblog.com/2008/08/30/on-the-history-of-event-processing-global-network-monitoring/">On The History of Event Processing: Global Network Monitoring</source>
    </item>
    <item>
      <title><![CDATA[This week in history - volcanos, hurricanes, and the risk of Black Swans]]></title>
      <link>http://securityratty.com/article/1c99044530f3bdcc78ac07456ab99c44</link>
      <guid>http://securityratty.com/article/1c99044530f3bdcc78ac07456ab99c44</guid>
      <description><![CDATA[Pouring over endless details of risks, regulations, taxonomies, and technologies can sometimes give us a narrow view of the world, so it seems worthwhile to take a minute to mark the 125th anniversary...]]></description>
      <content:encoded><![CDATA[<p><img title="Chris McClean" alt="Chris McClean" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Chris-McClean.gif" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /></p>

<p>Pouring over endless details of risks, regulations, taxonomies, and technologies can sometimes give us a narrow view of the world, so it seems worthwhile to take a minute to mark the 125th anniversary of the <a href="http://www.wired.com/science/discoveries/news/2008/08/dayintech_0826">cataclysmic eruption of Krakatoa</a> this week. For those of us that want to think big but can’t remember that far back, this week is also the 3rd anniversary of <a href="http://www.hhs.gov/disasters/emergency/naturaldisasters/hurricanes/katrina/index.html">Hurricane Katrina’s devastating sweep</a> across a wide stretch of the US Gulf Coast. </p>

<p>By now, I expect that most of you have read or are familiar with the 2007 book, The Black Swan, by <a href="http://www.fooledbyrandomness.com/">Nassim Nicholas Taleb</a>, which argues that these kinds of unpredictable, outlying occurrences are the ones that really shape businesses, countries, economies, and people. Taleb argues that although these “Black Swan” events are almost completely unforeseeable, we mistakenly try to explain the circumstances at the time and make predictions about similar events in the future. </p>

<p>In my ERM work with clients, and especially in the context of research I’ve been doing with my colleague <a href="http://www.forrester.com/rb/analyst/stephanie_balaouras?internal=1">Stephanie Balaouras</a> on business continuity and resiliency, questions come up about how to plan for catastrophes... and they’re good questions. Were the CardSystems or TJX data breaches foreseeable? What about the Societe General debacle or the 2004 Indian Ocean tsunami? What’s next? Should these types of events be included in our risk assessments? </p>

<p>We’d like to get your opinion on these and other risks that may be on the very edge of the statistical tail. At what point do they belong in your risk register? </p>

<p>Of course, it’s possible to define mitigating controls for crises, disasters, or incidents without knowing for sure what they’re going to look like. That’s one of the hallmarks of a good crisis management plan. And that’s an important point, because trying to predict the next unforeseeable event can be a real challenge sometimes. </p>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 07:07:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/similar events">similar events</category>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/black swan events">black swan events</category>
      <category domain="http://securityratty.com/tag/black swan">black swan</category>
      <category domain="http://securityratty.com/tag/plan">plan</category>
      <category domain="http://securityratty.com/tag/crisis management plan">crisis management plan</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/colleague stephanie balaouras">colleague stephanie balaouras</category>
      <category domain="http://securityratty.com/tag/argues">argues</category>
      <source url="http://blogs.forrester.com/srm/2008/08/this-date-in-hi.html">This week in history - volcanos, hurricanes, and the risk of Black Swans</source>
    </item>
    <item>
      <title><![CDATA[Facebook Worm Still Going Strong]]></title>
      <link>http://securityratty.com/article/3d63cb5f4654a97b393266f752d1c56a</link>
      <guid>http://securityratty.com/article/3d63cb5f4654a97b393266f752d1c56a</guid>
      <description><![CDATA[A colleague of mine had a private message sent to them on Facebook yesterday from the account of a friend. The message is related (of course) to the recent Facebook worm





Click the link, and...]]></description>
      <content:encoded><![CDATA[
        A colleague of mine had a private message sent to them on Facebook yesterday from the account of a friend. The message is related (of course) to the recent <a href="http://blogs.pcmag.com/securitywatch/2008/08/facebook_worm_spreads_rapidly.php">Facebook worm</a>:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fbspam1.jpg" src="http://blog.spywareguide.com/images/fbspam1.jpg" class="mt-image-none" style="" height="304" width="413" /></span></div><br /> <div><br />Click the link, and you'll see something like this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fbspam2.html" onclick="window.open('http://blog.spywareguide.com/images/fbspam2.html','popup','width=700,height=510,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fbspam2-thumb-300x218.jpg" alt="fbspam2.jpg" class="mt-image-none" style="" height="218" width="300" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />Yes, it's Ye Olde Fake Codec installer, hosted on what appears to be a hacked website. As always, pay close attention to what you're being sent from your friends. If it doesn't <i>seem</i> like something they'd send you, that's probably because they didn't...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 05:57:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/recent facebook worm">recent facebook worm</category>
      <category domain="http://securityratty.com/tag/close attention">close attention</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/facebook yesterday">facebook yesterday</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/friend">friend</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <source url="http://blog.spywareguide.com/2008/08/facebook-worm-still-going-stro.html">Facebook Worm Still Going Strong</source>
    </item>
    <item>
      <title><![CDATA[TV news anchor admits to hacking, leaking colleague's e-mail]]></title>
      <link>http://securityratty.com/article/0dda0266143e66edbb1bc5748d1720b5</link>
      <guid>http://securityratty.com/article/0dda0266143e66edbb1bc5748d1720b5</guid>
      <description><![CDATA[Philadelphia TV news anchor Lawrence Mendte pleaded guilty to to one count of accessing a protected computer that involved breaking into his co-anchor's e-mail accounts more than 500...]]></description>
      <content:encoded><![CDATA[Philadelphia TV news anchor Lawrence Mendte pleaded guilty to to one count of accessing a protected computer that involved breaking into his co-anchor's e-mail accounts more than 500 times.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=K8Cke3"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=K8Cke3" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/372144461" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/e-mail accounts">e-mail accounts</category>
      <category domain="http://securityratty.com/tag/count">count</category>
      <category domain="http://securityratty.com/tag/co-anchor">co-anchor</category>
      <category domain="http://securityratty.com/tag/guilty">guilty</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/times">times</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/372144461/article.do">TV news anchor admits to hacking, leaking colleague's e-mail</source>
    </item>
    <item>
      <title><![CDATA[Upping The IPS Ante]]></title>
      <link>http://securityratty.com/article/81aa745b480141b489146432f5c59ee0</link>
      <guid>http://securityratty.com/article/81aa745b480141b489146432f5c59ee0</guid>
      <description><![CDATA[My colleague at Forrester, Chris Silva, recently commented upon the recent Air Defense acquisition by Motorola. Looking at the deal through the security lens, I completely agree with Chris that this...]]></description>
      <content:encoded><![CDATA[<p>My colleague at Forrester, Chris Silva, recently commented upon the recent Air Defense acquisition by Motorola.&nbsp; Looking at the deal through the security lens, I completely agree with Chris that this will help ease integration of wireless security into wireless infrastructure.&nbsp; It's good to see one of the major wireless brands step up and take wireless security seriously.&nbsp; Perhaps that other major wireless vendor will get the hint...</p>

<blockquote><p><span style="color: #636363;"><a href="http://blogs.forrester.com/it_infrastructure/2008/07/upping-the-ips.html">Upping The IPS Ante</a></span></p></blockquote>

<blockquote><p><span style="color: #8a8a8a;">	
Motorola <a href="http://www.airdefense.net/newsandpress/07_28_08.php">announced</a> this week its intentions to acquires Wireless IDS/IPS vendor <a href="http://www.airdefense.net/">AirDefense</a>.
The acquisition may provide a bit of deja vu to readers who recall the
acquisition of Network Chemistry's wireless IDS/IPS assets by Aruba
Networks <a href="http://www.arubanetworks.com/company/news/release.php?id=25">in 2007</a>. 

</span></p>

<p><span style="color: #8a8a8a;">Meru Networks, eschewing acquisition for product introduction made <a href="http://www.merunetworks.com/news/press_releases/index.php?articleID=072808">its own announcement</a>
on Monday, announcing the company's RF Barrier, an active RF management
solution that aims to solve the problem of what the vendor is calling
&quot;leaky RF.&quot; The Meru solution actively blocks 802.11 RF from escaping
the physical confines of a WLAN deployment to thwart external &quot;parking
lot&quot; attacks by closing Wi-Fi based attack avenues. </span></p>

<p><span style="color: #8a8a8a;">In fact, 2007 - 2008 has been a time focused on shoring up the security
of the WLAN as the networks become more critical to <a href="http://www.forrester.com/Research/Document/0,7211,42451,00.html">over 50%</a>
of
enterprises Forrester sees investing in the networks today. As the
networks are more pervasive, moving toward covering the entire physical
environment, and more employees are relying on Wi-Fi to access
corporate data and applications, it's high-time to secure the WLAN.</span></p>

<p><span style="color: #8a8a8a;">In the case of Motorola, the Wi-Fi network is especially critical. As the vendor embarks on selling its message of the <a href="http://www.informationweek.com/news/mobility/converence/showArticle.jhtml?articleID=206904190">all-wireless enterprise</a>,
where WLANs will interconnect not only users to the network, but
networke edge devices -- such as WLAN access points -- to the network
along with storage, printers and other peripheral devices, the WLAN is
citical and, therefore, a major focus for security. </span></p>

<p><span style="color: #8a8a8a;">In markets such as retail, standards like the Payment Card
Industry's Data Security Standard dictate wireless security, but
compliance and regulation aside, it is becoming easier to secure the
WLAN, regardless of the industry you are in. Vendors are rapily working
to close security gaps with product enhancements and new product
introductions. Look for a broader suite of solutions to address
security coming from your primary network vendor; while this won't
negate the need to&nbsp; integrate these add-on network elements, the single
source should ease integration to some degree. </span></p>

<p><span style="color: #8a8a8a;">How secure do you feel your organization's WLAN is today? What are
your concerns either about securing the network or its current lack of
security?</span></p></blockquote>]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 11:14:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/address security">address security</category>
      <category domain="http://securityratty.com/tag/security lens">security lens</category>
      <category domain="http://securityratty.com/tag/data security standard">data security standard</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi network">wi-fi network</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/wireless security">wireless security</category>
      <source url="http://blogs.forrester.com/srm/2008/07/upping-the-ips.html">Upping The IPS Ante</source>
    </item>
    <item>
      <title><![CDATA[World War II Deception Story]]></title>
      <link>http://securityratty.com/article/ffeef2b2ecdc9709d491f4a4c3ecd7f5</link>
      <guid>http://securityratty.com/article/ffeef2b2ecdc9709d491f4a4c3ecd7f5</guid>
      <description><![CDATA[Great security story from an obituary of former OSS agent Roger Hall: One of his favorite OSS stories involved a colleague sent to occupied France to destroy a seemingly impenetrable German tank at a...]]></description>
      <content:encoded><![CDATA[<p>Great <a href="http://www.philly.com/inquirer/obituaries/20080723_Roger_Hall___Poked_fun_at_spies__89.html">security story</a> from an obituary of former OSS agent Roger Hall:</p>

<blockquote>One of his favorite OSS stories involved a colleague sent to occupied France to destroy a seemingly impenetrable German tank at a key crossroads. The French resistance found that grenades were no use. 

<p>The OSS man, fluent in German and dressed like a French peasant, walked up to the tank and yelled, "Mail!" </p>

<p>The lid opened, and in went two grenades.</blockquote></p>

<p>Hall's book about his OSS days, <a href="http://www.amazon.com/Youre-Stepping-Cloak-Dagger-Bluejacket/dp/1591143535/ref=pd_bbs_sr_1"><i>You're Stepping on My Cloak and Dagger,</i></a> is a must read.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=urokhJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=urokhJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=TBL5AJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=TBL5AJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 09:50:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oss">oss</category>
      <category domain="http://securityratty.com/tag/oss days">oss days</category>
      <category domain="http://securityratty.com/tag/favorite oss stories">favorite oss stories</category>
      <category domain="http://securityratty.com/tag/grenades">grenades</category>
      <category domain="http://securityratty.com/tag/french resistance">french resistance</category>
      <category domain="http://securityratty.com/tag/french peasant">french peasant</category>
      <category domain="http://securityratty.com/tag/key crossroads">key crossroads</category>
      <category domain="http://securityratty.com/tag/security story">security story</category>
      <category domain="http://securityratty.com/tag/dagger">dagger</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/world_war_ii_de.html">World War II Deception Story</source>
    </item>
    <item>
      <title><![CDATA[Distributed Memory in Blackboard Systems]]></title>
      <link>http://securityratty.com/article/c8294d6fcd37560ac3558a8a3914fdaa</link>
      <guid>http://securityratty.com/article/c8294d6fcd37560ac3558a8a3914fdaa</guid>
      <description><![CDATA[Paul Vincent, ex-colleague at TIBCO, kindly responds to A Brief Introduction to Blackboard Architectures with Blackboards for Complex Event Processing . Paul correctly mentions that TIBCOs...]]></description>
      <content:encoded><![CDATA[<p>Paul Vincent, ex-colleague at TIBCO, kindly responds to <a href="http://www.thecepblog.com/2008/07/20/a-brief-introduction-to-blackboard-architectures/" target="_blank">A Brief Introduction to Blackboard Architectures</a> with <a title="Permalink" href="http://tibcoblogs.com/cep/2008/07/25/blackboards-for-complex-event-processing/">Blackboards for Complex Event Processing</a>.   Paul correctly mentions that TIBCO&#8217;s BusinessEvents software is an excellent scheduling component in a blackboard systems architecture.</p>
<p>However, I should briefly clarify Paul&#8217;s note that &#8220;<em>blackboard systems historically used a single memory model (i.e. multiple threads or processes using a single machine’s memory model)</em>&#8220;.</p>
<p>In fact, there were many blackboard systems, some more than a decade old, that used a distributed memory data-model.   What I think Paul meant to say, and my apologies to Paul for being so literal, is that &#8220;<em>blackboard systems <strong>originally </strong>used a single memory model (i.e. multiple threads or processes using a single machine’s memory model)</em>&#8221;</p>
<p>John McManus, <a href="http://www.nasa.gov/offices/ocio/about/j_mcmanus_bio.html" target="_blank">former CTO of NASA</a>, wrote an excellent PhD dissertation in 1992,  <a href="http://www.thecepblog.com/tb/pdf/mcmanus_thesis_blackboard.pdf" target="_blank">Design and Analysis Techniques for Concurrent Blackboard Systems</a>.    John&#8217;s thesis, now more than 16 years old, examined many details of concurrent blackboards where memory is distributed.  For example, refer to<em> Figure 2.3. Distributed Blackboard System with Distributed Blackboard Data Structure, </em> page 36 of John&#8217;s dissertation.</p>
<p>Quoting directly from page 37 of John&#8217;s disseration;</p>
<blockquote><p>Rice, Aiello and Nii [20] present several options for gaining speedups in a distributed blackboard system.</p>
<ul>
<li>1) Eliminate the centralized scheduling mechanism</li>
<li>2) Optimize system design for a distributed memory, message-passing hardware</li>
<li>3) Distribute the data across the blackboard to reduce hotspots</li>
</ul>
</blockquote>
<p>Quoting further from the same page;</p>
<blockquote><p>Poligon [21] is based on a distributed memory hardware model when each processor is viewed as a blackboard node. They define a blackboard node as follows: <em>“a blackboard node is a process on a processor, surrounded by a collection of processors able to service its requests to execute rules.” </em>[22] The implicit assumption in this definition is that all knowledge sources are rule–based systems. This assumption may severely limit the performance of systems implemented using Poligon, and limits the types of problems it is suited to address.</p></blockquote>
<p>In <a title="Permalink" href="http://tibcoblogs.com/cep/2008/07/25/blackboards-for-complex-event-processing/">Blackboards for Complex Event Processing</a>, Paul concludes, <em></em></p>
<blockquote><p><em>&#8220;One suspects the blackboard systems domain and terminology is overdue some updates thanks to developments in the Complex Event Processing space.&#8221;</em></p></blockquote>
<p>If you look at the historical literature, I would say that the following restatement is more accurate:</p>
<blockquote><p><em>&#8220;The CEP domain and terminology is overdue some updates because folks working in CEP did not reference or incorporate the advanced event processing prior art in a number of very important areas, blackboard systems being only one.&#8221;</em></p></blockquote>
<p>On the other hand,  commercial off-the-shelf rule-processing technology such as TIBCO&#8217;s BusinessEvents (BE), advances the ability to economically implement myriad complex problems that blackboard systems are designed to address.</p>
]]></content:encoded>
      <pubDate>Sat, 26 Jul 2008 03:01:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/blackboard systems architecture">blackboard systems architecture</category>
      <category domain="http://securityratty.com/tag/blackboard">blackboard</category>
      <category domain="http://securityratty.com/tag/concurrent blackboard systems">concurrent blackboard systems</category>
      <category domain="http://securityratty.com/tag/blackboard architectures">blackboard architectures</category>
      <category domain="http://securityratty.com/tag/blackboard system">blackboard system</category>
      <category domain="http://securityratty.com/tag/memory">memory</category>
      <category domain="http://securityratty.com/tag/blackboard systems domain">blackboard systems domain</category>
      <category domain="http://securityratty.com/tag/blackboard systems">blackboard systems</category>
      <source url="http://www.thecepblog.com/2008/07/26/distributed-memory-in-blackboard-systems/">Distributed Memory in Blackboard Systems</source>
    </item>
  </channel>
</rss>
