<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: creative]]></title>
    <link>http://securityratty.com/tag/creative</link>
    <description></description>
    <pubDate>Mon, 15 Sep 2008 19:28:38 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[National Security Perspectives A Post-Election Insider View]]></title>
      <link>http://securityratty.com/article/caa8257ee971993e58e1b834379f8c71</link>
      <guid>http://securityratty.com/article/caa8257ee971993e58e1b834379f8c71</guid>
      <description><![CDATA[Recently I participated in an event entitled National Security Perspectives held at the famous Congressional Country Club in Maryland . The featured panelists had impressive credentials from the NSA ,...]]></description>
      <content:encoded><![CDATA[<p>Recently I participated in an event entitled National Security Perspectives held at the famous <a href="http://www.ccclub.org/" target="_blank">Congressional Country Club in Maryland</a>. The featured panelists had impressive credentials from the <a href="http://www.nsa.gov/" target="_blank">NSA</a>, <a href="http://www.dhs.gov/" target="_blank">DHS</a> and the <a href="https://www.cia.gov/" target="_blank">CIA</a>. The topics of discussion ranged from Current Geopolitical Threats and Evolving Technology Demands to predictions about the New Administrations Intelligence, Defense and Homeland Security focus.</p>
<p>The panelists were:<br />
<a href="http://en.wikipedia.org/wiki/National_Security_Agency" target="_blank">William P. Crowell</a> – former Deputy Director of the National Security Agency<br />
<a href="http://www.whitehouse.gov/government/m_jackson-bio.html" target="_blank">Michael P. Jackson</a> – Deputy Secretary, Department of Homeland Security<br />
<a href="http://en.wikipedia.org/wiki/Jose_Rodriguez_(intelligence)" target="_blank">Jose A. Rodriguez, Jr</a>. – former Director CIA, National Clandestine Service &amp; CIA, DCI Counterterrorist Center</p>
<p>Overall, it was a very nicely arranged event on a brisk fall evening with about 100 CXO attendees; mostly large but some small government contractors and a few product companies like ScienceLogic that conduct business with military, intelligence and the public sector.</p>
<p>No surprise, given the financial crisis the economy is suffering from that the panelists said we also have a <a href="http://obsidianwings.blogs.com/obsidian_wings/2008/11/defictits-actua.html" target="_blank">crisis coming on the Federal budget front</a>. This will put enormous pressure on the way Administration thinks, and how and where to spend the $$.</p>
<p>Obama’s tone regarding the issues he will be confronting in the world during the election was encouraging. Make the world more non-partisan and take on the threats that we have in front of us head-on!</p>
<p>The panel was very upfront about current threats. William Crowell said,</p>
<blockquote><p>“It is highly imprudent to believe that there will not be another 9-11. We have to fund and support the work to stop other attacks. We can only mitigate risk but we can’t eliminate risk. We have to try to absorb the sense of urgency and wake up every day looking at the intelligence screens as if 9-11 happened within the last couple of months.”</p></blockquote>
<p>He added,</p>
<blockquote><p>“They (the intelligence community) need the innovation, sense of commitment and urgency that comes from the private sector – a sense of mutual commitment to that mission.”</p></blockquote>
<p>Predicted Priorities for investment for DHS:</p>
<ol>
<li>Cyber attack as the top issue</li>
<li>Nuclear threats including dirty bomb</li>
<li>Chemical and biological attacks</li>
<li>Explosive attacks against critical infrastructure with maximum # of lives and or financial disruption / loss.</li>
<li>Large scale natural disasters – hurricane + earthquakes</li>
<li>Border penetration - identity management and border management issues</li>
</ol>
<p>An <a href="http://www.barackobama.com/index.php" target="_blank">Obama administration</a> will spend dollars around these threat vectors. They will want to spend $$ to help state and local governments. Grants to state and local governments should significantly increase with the Obama administration, so think about how you will increase your focus on the state and local government spending initiatives.</p>
<p><a href="http://lawprofessors.typepad.com/immigration/2008/11/pressure-on-oba.html" target="_blank">Secure border investments</a> – the panelists believe that the new administration will feel compelled to invest here. Michael P. Jackson bluntly said, “You have to make investments in border tools to get meaningful immigration reform.”</p>
<p>Panelists agreed that the 1<sup>st</sup> year will be an intense period of scrutiny about fundamental directions. We can’t afford it all at DHS; it is dramatically under budgeted. At TSA/DOT and then at DHS, we spent about $4 Billion on technology investments since 9-11; those investments are now reaching the end of the original service life.</p>
<p>One gripe from the panel that I found humorous: “We don’t have a group of people who think like entrepreneurs.” It is insane how long things last when you buy things in the government. As an example, we are still replacing vacuum tubes in some of the very old FAA gear… this is well beyond what any reasonable person would think these initial investments should/would last.</p>
<p>Final Thoughts:<br />
I actually think that the Obama Administration will be quite favorable to COTS software products, SaaS offerings, and creative financing initiatives from the private sector. The government just won’t have the capital budget to do everything it wants to accomplish. I would say if you look at how intelligently and aggressively <a href="http://www.concurringopinions.com/archives/2008/11/obama_and_techn.html" target="_blank">Obama used technology</a> to assist his campaign, the odds are good that this new breed of IT talent (which is already really comfortable with SaaS products, blogs, wiki’s, hosted/outsourced Cloud solutions… this team really understands the latest technology trends) will quickly work to bring these new IT paradigms to the Federal marketplace. Clearly the private sector can help the Government achieve more with lower capital budgets – beginning to provide services rather than transaction-based selling. Another clear idea is to think about leasing as a better way to work with the government which going forward will have increased budgets restrictions.</p>
<p>They will likely be in confrontation with members of Congress that won’t change fast enough, however the future of our nation’s ability to fight terror lies in becoming more efficient and effective. It requires the government be flexible enough to figure out what <a href="http://blogs.techrepublic.com.com/hiner/?p=880" target="_blank">jobs and IT functions to outsource</a> in a nimble and smart way. My prediction: this is great news for Service Providers. Overall the next 4 years should be great for our business as well as the Managed Service Provider/SaaS industry!</p>
<p><em><span style="color: #333333;"> </span></em></p>
]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 11:13:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/secure border investments">secure border investments</category>
      <category domain="http://securityratty.com/tag/investments">investments</category>
      <category domain="http://securityratty.com/tag/government contractors">government contractors</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/threats">threats</category>
      <category domain="http://securityratty.com/tag/government achieve">government achieve</category>
      <category domain="http://securityratty.com/tag/initial investments shouldwould">initial investments shouldwould</category>
      <category domain="http://securityratty.com/tag/obama administration">obama administration</category>
      <category domain="http://securityratty.com/tag/current threats">current threats</category>
      <source url="http://blog.sciencelogic.com/national-security-perspectives-a-post-election-insider-view/11/2008">National Security Perspectives A Post-Election Insider View</source>
    </item>
    <item>
      <title><![CDATA[On Security & Risk Management Innovation]]></title>
      <link>http://securityratty.com/article/044cbc91b90e3bcf8694d48ef0276511</link>
      <guid>http://securityratty.com/article/044cbc91b90e3bcf8694d48ef0276511</guid>
      <description><![CDATA[Pre-Script - It should be noted that the outcome of this discussion - in the last paragraph - is one smart way you can approach the We need to reduce your budget discussion (if that discussion hasnt...]]></description>
      <content:encoded><![CDATA[<p><span style="color: #666699;"><em>Pre-Script - It should be noted that the outcome of this discussion - in the last paragraph - is one smart way you can approach the “We need to reduce your budget” discussion (if that discussion hasn’t come already).</em></span></p>
<p>I’ve often read people who say that we (security, risk management) need to “think like the attacker”.  And when you read this sort of article, that usually alludes to trying to anticipate the tactics an attacker might use to mess with your C, I, or A.  Smart stuff, that, and very useful when architecting security solutions.  But as I was training some folks Monday, I was thinking in the back of my head about Threat Capability (TCap) in FAIR.  As you might know, we like to estimate the capability of a threat to apply some level of “force” against our assets.  This ability to apply force is a byproduct of the attacker&#8217;s skills and resources.  And thinking of how an attacker applies skills and resources, I came across another way we might “think” like an attacker.</p>
<p>Traditionally, I’ve thought of “skills” as being a byproduct of the toolset an attacker has.  This mindset probably stems from my time with Penetration Testing teams, where in the process of scoping the  PenTest I would ask our clients to select the level of effort that they wanted us to throw at them.  If a client chose “high” we’d throw every ‘spoit we had at them.  If they chose “low” we’d limit ourselves to a more commonly available toolset.</p>
<p>But while the resources part of TCap is time &amp; materials (money) - the skills are really more than just the toolset.  Skills would include the ability of the attacker to be creative and innovative.    As an example of that innovation from those PenTesting days - when we got a “high” effort request, we would always try to couple that with some “social engineering”-type of attack, or some unique means of delivering an existing exploit.  Our creativity was not necessarily a byproduct of a unique exploit or tool we had, but the process by which we might deliver pre-existing or commonly available exploits.  I remember when we first got ahold of a handful of 32mb thumb drives (hey, 32mb was <em>huge</em> back then) and &#8220;dropped&#8221; a few in the lobby of a client&#8217;s retail space.  The keystroke loggers and phone-home script weren&#8217;t new, but using the thumb drive as delivery vehicle certainly was.</p>
<p>So I’ve started to really think about this concept of innovation, and how if “thinking like an attacker” means to be innovative, we ought to do the same.  I’ve been thinking of two main categories of innovation this morning.</p>
<p><strong>INNOVATION</strong></p>
<p>The first I’ll call <em><strong>Technology Innovation</strong></em>.  And by Technology Innovation, I mean some new, unique, “ahead of the curve” technology that an attacker can use against us.  The obvious example of which is a zero-day.  It’s that “high” tool set our PenTesters would use against the clients.  For security departments, this might be the latest security product designed to enhance our ability to P, D, and/or R.</p>
<p>Alternately, we can be creative in the way we deliver (manage) existing technology.  I think of this as<strong> Process Innovation</strong>.  It’s doing more with what we already have, just like the PenTest team would be creative in the delivery of an existing exploit.</p>
<p>Unfortunately for us - attackers have traditionally had quite a leg up on us in terms of Process Innovation.  It is much easier fro them to be creative, as they are free of political constraints and bureaucracy.  In contrast, when the security industry tries Process Innovation, the results are checklists and “standards”.  It’s committees and consensus.  An extreme example of which might be something like SABSA - a great work if you want to understand some very smart people’s comprehensive understanding of organizational security  - but the “adoption”of which will do very little to help you be innovative in P/D/R.</p>
<p>It’s worth noting that ultimately, this is one reason <strong>I don’t like regulatory compliance efforts</strong> - <strong>they simply serve to prove how mundane your security department is</strong>,  wasting valuable resources that could be spent on creating ways to be more effective.</p>
<p><strong>PROCESS INNOVATION AS A SUBSTITUTE FOR TECHNOLOGY INNOVATION</strong></p>
<p>As we come to the close of 2009, some surveys suggest that security spending isn’t horribly impacted yet by the economy (the latest from E&amp;Y points to only 5% of their respondents getting budget cuts).  But if this is a protracted downturn, and because InfoSec is an operational expense, I would expect cash to become more and more difficult to keep.  And regardless if technology spends do slow, I believe it makes sense to think about Process Innovation because I see Process Innovation as a means to increase effectiveness without significant capital expenditures (effectiveness increases because our ability to manage risk has a direct correlation to the amount of risk we have).</p>
<p>The bad news is, of course, that great innovation is hard.  It is R &amp; D.  Failure is usually a pre-requisite to success.</p>
<p>The good news is, our current state is so bad that many of us don’t need to come up with a whizbang new way of reducing software defects in the SDLC as innovation.  Simply inserting a risk analyst into the PMO’s processes might count as a big enough victory. Be cautioned, though,  that if we’re substituting the risk reductions provided by technology acquisition - Process Innovation might actually be even more &#8220;expensive&#8221; as it requires us to expend political capital.   But there are (forgive the term) innovative ways to spend this political capital.</p>
<p>For example, by taking a second now and figuring out the 3 things that the rest of the organization can do to make your life easier, when that “I need to reduce your budget” talk comes, you can be prepared to negotiate.  Get a political capital &#8220;loan&#8221; or &#8220;investment&#8221; from the C-Suite reducing your budget.  Something to the effect of: “I expected this, and am happy to give up my budget.  But if our tolerance for risk hasn’t changed, what I’d like to do is get you to personally back my office on three projects I’ve identified that can reduce our risk without requiring significant capital expenditure.”</p>
]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 11:23:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/innovation">innovation</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/process innovation">process innovation</category>
      <category domain="http://securityratty.com/tag/call technology innovation">call technology innovation</category>
      <category domain="http://securityratty.com/tag/technology innovation">technology innovation</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/attackers skills">attackers skills</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=516">On Security &amp; Risk Management Innovation</source>
    </item>
    <item>
      <title><![CDATA[Free Atlas of Cyberspace]]></title>
      <link>http://securityratty.com/article/5ede85e6c60a5390082e0e39ce8211c4</link>
      <guid>http://securityratty.com/article/5ede85e6c60a5390082e0e39ce8211c4</guid>
      <description><![CDATA[I used to spend hours playing with Mappa Mundi tool (screen shots in the book) envisaging ways you could map security properties to parts of a web system and infer meaning. This totally free eBook...]]></description>
      <content:encoded><![CDATA[&#160;


&#160;
I used to spend hours playing with Mappa Mundi tool (screen shots in the book) envisaging ways you could map security properties to parts of a web system and infer meaning. This totally free eBook (you can pay for the print version) is brilliant. 
(The full content can be downloaded here, made available on Creative [...]]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 06:49:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mappa mundi tool">mappa mundi tool</category>
      <category domain="http://securityratty.com/tag/map security properties">map security properties</category>
      <category domain="http://securityratty.com/tag/free ebook">free ebook</category>
      <category domain="http://securityratty.com/tag/print version">print version</category>
      <category domain="http://securityratty.com/tag/web system">web system</category>
      <category domain="http://securityratty.com/tag/shots">shots</category>
      <category domain="http://securityratty.com/tag/hours">hours</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/infer">infer</category>
      <source url="http://securitybuddha.com/2008/10/20/free-atlas-of-cyberspace/">Free Atlas of Cyberspace</source>
    </item>
    <item>
      <title><![CDATA[Real-Time OSINT vs Historical OSINT in Russia/Georgia Cyberattacks]]></title>
      <link>http://securityratty.com/article/20a44f5ecd81be809dacc26141c04b6b</link>
      <guid>http://securityratty.com/article/20a44f5ecd81be809dacc26141c04b6b</guid>
      <description><![CDATA[The original real-time OSINT analysis of the Russian cyberattacks against Georgia conducted on the 11th of August, not only closed the Russia vs Georgia cyberwar case for me personally, but also, once...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SPfiGY9ParI/AAAAAAAACT4/qFAdE-rdQZs/s1600-h/georgia_ddos13.JPG.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SPfiGY9ParI/AAAAAAAACT4/9N9uGXoRSB4/s200-R/georgia_ddos13.JPG.png" /></a>The original <a href="http://blogs.zdnet.com/security/?p=1670">real-time OSINT analysis of the Russian cyberattacks against Georgia</a> conducted on the 11th of August, not only closed the Russia vs Georgia cyberwar case for me personally, but also, once again proved that real-time OSINT is invaluable compared to <a href="http://www.scribd.com/doc/6967393/Project-Grey-Goose-Phase-I-Report">historical OSINT using a commercial social network visualization/data mining tool</a> which cannot and will never be able to access the Dark Web, accessible only through real-time <a href="http://ddanchev.blogspot.com/2006/09/cyber-intelligence-cyberint.html">CYBERINT practices</a>.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SPyTGJhYQJI/AAAAAAAACUI/P3h69SzYPm8/s1600-h/georgia_ddos_botnet_cc.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SPyTGJhYQJI/AAAAAAAACUI/LwvYHvdpiFQ/s200-R/georgia_ddos_botnet_cc.png" /></a>The value of real-time OSINT in such <a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">people's information warfare cyberattacks</a> -- with <a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">Chinese hacktivists</a> perfectly aware of the <a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">meaning of the phrase</a> -- relies on the relatively lower operational security (OPSEC) the initiators of a particular campaign apply at the beginning, so that it would scale faster and attract more participants. What the Russian government was doing is fueling the (cyber) fire - literally, since all it takes for a collectivist socienty's cyber militia to organize, is a "call for action" which was taking place at the majority of forums, with the posters of these messages apparently using a spamming application to achieve better efficiency.<br />
<br />
<a href="http://intelfusion.net/wordpress/?p=430">The results</a> from 56 days of <a href="http://intelfusion.net/wordpress/?p=398">Project Grey Goose</a> in action got published last week, a project <a href="http://ddanchev.blogspot.com/2008/09/summarizing-augusts-threatscape.html">I discussed back in August</a>, point out to the bottom of the food chain in the entire campaign - <b>stopgeorgia.ru</b> :<br />
<br />
<a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SPfkXQ-08xI/AAAAAAAACUA/qd9xv7kt2Qw/s1600-h/georgia_ddos8.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SPfkXQ-08xI/AAAAAAAACUA/dnYU_GbeEnw/s200-R/georgia_ddos8.JPG" /></a>"<i>Furthermore, coming up with <a href="http://intelfusion.net/wordpress/?p=398">Social Network analysis of the cyberattacks</a> would produce nothing more but a few fancy graphs of over enthusiastic Russian netizen's distributing the static list of the targets. The real conversations, as always, are <a href="http://blogs.nyu.edu/blogs/agc282/zia/2008/08/intelfusions_sna_of_russian_cy.html">happening in the "Dark Web" limiting the possibilities for open source intelligence</a> using a data mining software. Things changed, OPSEC is slowly emerging as a concept among malicious parties, whenever some of the "calls for action" in the DDoS attacks were posted at mainstream forums, they were immediately removed so that they don't show up in such academic initiatives</i>"<br />
<br />
So what's the bottom line? Nothing that I haven't already pointed out back in August : "<a href="http://voices.washingtonpost.com/securityfix/2008/10/report_russian_hacker_forums_f.html">Report: Russian Hacker Forums Fueled Georgia Cyber Attacks</a>" :<br />
<br />
"<i>But experts say evidence suggests that Russian officials did little to discourage the online assault, which was coordinated through a Russian online forum that appeared to have been prepped with target lists and details about Georgian Web site vulnerabilities well before the two countries engaged in a brief but deadly ground, sea and air war."</i>  <br />
<br />
<a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9117439&amp;source=NLT_PM&amp;nlid=8">Some more comments</a> :<br />
<br />
"<i>Just because there was no smoking gun doesn't mean there's no connection," said Jeff Carr, the principal investigator of Project Grey Goose, a group of around 15 computer security, technology and intelligence experts that investigated the August attacks against Georgia. "I can't imagine that this came together sporadically," he said. "I don't think that a disorganized group can coalesce in 24 hours with its own processes in place. That just doesn't make sense.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SPyW6yXyA5I/AAAAAAAACUQ/roWip-fqbeE/s1600-h/georgia_packet_clearing_house.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SPyW6yXyA5I/AAAAAAAACUQ/7oAwAggiAKE/s200-R/georgia_packet_clearing_house.jpg" /></a>It wouldn't make sense if this was the first time Russian hacktivists are maintaining the same rhythm as real-life events - <a href="http://blogs.zdnet.com/security/?p=1408">which of course isn't</a>.<br />
<br />
Moreover, exactly what would have constituted a "smoking gun" proving that the Russian government was involved in the campaign, remains unknown -- I'm still sticking to my comment regarding <a href="http://georgiaupdate.gov.ge/doc/10006744/CYBERWAR-%20fd_2_new.pdf">the web site defacement creative</a>. If they truly wanted to compromise themselves, they would have cut Georgia off the Internet, at least from the perspective offered by this graph courtesy of the <a href="http://www.pch.net/">Packet Clearing House</a> speaking for their dependability on Russian ISPs. <br />
<br />
As for <a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">the script kiddies</a> at <b>stopgeorgia.ru</b>, <a href="http://74.125.39.104/search?hl=en&amp;q=cache%3Astopgeorgia.ru%2F%3Fpg%3Dser&amp;aq=f&amp;oq=">they were informed enough to feature my research into their "negative public comments section"</a>. To sum up - the "DoS battle stations operational in the name of the "<i><a href="http://www.alexandrasamuel.com/dissertation/pdfs/Samuel-Hacktivism-entire.pdf">Please, input your cause</a></i>" mentality is always going to be there.<b><br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BxRfM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BxRfM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iUQ7M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iUQ7M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9vGjm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9vGjm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=85DIm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=85DIm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mX8FM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mX8FM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XswSM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XswSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wZ9Jm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wZ9Jm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/426491766" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 05:58:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/cyberattacks">cyberattacks</category>
      <category domain="http://securityratty.com/tag/cyber">cyber</category>
      <category domain="http://securityratty.com/tag/georgia cyber attacks">georgia cyber attacks</category>
      <category domain="http://securityratty.com/tag/real-time osint">real-time osint</category>
      <category domain="http://securityratty.com/tag/project">project</category>
      <category domain="http://securityratty.com/tag/project grey goose">project grey goose</category>
      <category domain="http://securityratty.com/tag/forums">forums</category>
      <category domain="http://securityratty.com/tag/cut georgia">cut georgia</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/426491766/real-time-osint-vs-historical-osint-in.html">Real-Time OSINT vs Historical OSINT in Russia/Georgia Cyberattacks</source>
    </item>
    <item>
      <title><![CDATA[DDoS Attack Graphs from Russia vs Georgia's Cyberattacks]]></title>
      <link>http://securityratty.com/article/dc1b9df0e6d3f3f43b5c110a78a3be89</link>
      <guid>http://securityratty.com/article/dc1b9df0e6d3f3f43b5c110a78a3be89</guid>
      <description><![CDATA[Part of Georgia's information warfare campaign aiming to minimize the bandwidth impact on its de-facto media platforms such as the web site of their Ministry of Foreign Affairs, I've just received a...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SPZIdRd6kMI/AAAAAAAACTA/fkKSEaSfIXc/s1600-h/ddos_attack_graph_georgia_russia.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SPZIdRd6kMI/AAAAAAAACTA/KRKwlE_hA04/s200-R/ddos_attack_graph_georgia_russia.JPG" /></a>Part of <a href="http://www.mediachannel.org/wordpress/2008/08/14/the-cnn-effect-georgia-schools-russia-in-information-warfare/">Georgia's information warfare campaign</a> aiming to minimize the bandwidth impact on its de-facto media platforms such as the web site of&nbsp; their Ministry of Foreign Affairs, <a href="http://georgiaupdate.gov.ge/doc/10006744/CYBERWAR-%20fd_2_new.pdf">I've just received a report</a> part of Georgia's "<i>Russian Invasion of Georgia</i>" series entitled "<i>Russian Cyberwar on Georgia</i>", which is quoting me on page 4 in regard to the "too good to be courtesy of <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9112443&amp;taxonomyId=82&amp;intsrc=kc_top">Russia's cyber militia</a>" creative that appeared on the defaced Georgian President's web site. The report also includes DDoS attack graphs and related details worth going through : <br />
<br />
"<i>The last large cyberattack took place on 27 August. After that, there have been no serious attacks on Georgian cyberspace. By that is meant that minor attacks are still continuing but these are indistinguishable from regular traffic and can certainly be attributed to regular civilians. On 27 August, at approximately 16:18 (GMT +3) a DDoS attack against the Georgian websites was launched. The main target was the Georgian Ministry of Foreign Affairs. The attacks peaked at approx 0,5 million network packets per second, and up to 200–250 Mbits per second in bandwidth (see attached graphs). The graphs represent a 5-minute average: actual peaks were higher.</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SPZI1-qp3kI/AAAAAAAACTI/-xuWJWJj9gg/s1600-h/ddos_attack_graph_georgia_russia1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SPZI1-qp3kI/AAAAAAAACTI/Fef2CL-KlH4/s200-R/ddos_attack_graph_georgia_russia1.JPG" /></a><i>The attacks mainly consisted of HTTP queries to the http://mfa.gov.ge website. These were requests for the main page script with randomly generated parameters. These requests were generated to overload the web server in a way where every single request would need significant CPU time. The initial wave of the attack disrupted services for some Georgian websites. The services became slow and unresponsive. This was due to the load on the servers by these requests. As you see from the graphs above the attacks started to wind down after most of the attackers were successfully blocked. The latest attack may have been initiated as a response to the media coverage on the Russian cyber attacks.</i>"<br />
<br />
In case you're interested in more factual evidence about what was happening at the particular moment in time, go through the following assessment - "<a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a>", as well as through the following posts - "<a href="http://ddanchev.blogspot.com/2008/08/russia-vs-georgia-cyber-attack.html">The Russia vs Georgia Cyber Attack</a>"; "<a href="http://ddanchev.blogspot.com/2008/08/whos-behind-georgia-cyber-attacks.html">Who's Behind the Georgia Cyber Attacks?</a>"; "<a href="http://blogs.zdnet.com/security/?p=1533">Georgia President’s web site under DDoS attack from Russian hackers</a>".<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OctdM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OctdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YNEdM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YNEdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i8cZm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i8cZm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Qfnnm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Qfnnm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gCSDM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gCSDM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TEWEM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TEWEM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=SVKNm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=SVKNm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/421908026" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 15 Oct 2008 11:01:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/georgia cyber attacks">georgia cyber attacks</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/georgia cyber attack">georgia cyber attack</category>
      <category domain="http://securityratty.com/tag/ddos attack">ddos attack</category>
      <category domain="http://securityratty.com/tag/russian cyber attacks">russian cyber attacks</category>
      <category domain="http://securityratty.com/tag/graphs">graphs</category>
      <category domain="http://securityratty.com/tag/russia">russia</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/421908026/ddos-attack-graphs-from-russia-vs.html">DDoS Attack Graphs from Russia vs Georgia's Cyberattacks</source>
    </item>
    <item>
      <title><![CDATA[Fake Windows XP Activation Trojan Wants Your CVV2 Code]]></title>
      <link>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</link>
      <guid>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</guid>
      <description><![CDATA[In a self-contradicting social engineering attempt, a malware author is offering to sale a ( updated version of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/YNDy4vo817c/s1600-h/fake_windows_xp_activation1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/BYpcW4rkU0o/s200-R/fake_windows_xp_activation1.png" /></a>In a self-contradicting social engineering attempt, a malware author is offering to sale a (<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-042705-0108-99">updated version</a> of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it claims "<i>We will ask for your billing details, but your credit card will NOT be charged</i>", is requesting and remotely uploading all the credit card details required for a successfully credit card theft.<br />
<br />
Perhaps among the main reasons why such simplistic social engineering attempts never scaled in a "malicious economies of scale" approach, is because sophisticated crimeware kits capable of obtaining the very same data automatically, started leaking for everyone to start taking advantage of - including yesterday's cybercriminals using such DIY fake message builders. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>Moreover, according to <a href="http://news.ncsu.edu/news/2008/09/wmswogalterfakemessage.php">recently reseased survey results</a>, end users cannot distinguish between fake popups and real ones, and on their way to continue doing what they were doing, click OK on that pesky warning message telling them that they're about to get infected with malware. Taking into consideration the fact that the popup windows the researchers used look like cheap creative compared to the average fake security software's layout high quality GUIs, it is perhaps worth restating your research questions with something in the lines of - <b>What motivates end users to install an antivirus application going under the name of Super Antivirus 2009 or Mega Virus Cleaner 2008?</b> The fact that the fake status bar is telling them that they're infected with 47 spyware cookies, or the fact that they ended up at the fake site while browsing their trusted web services? <br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/6uvXj2AuS_A/s1600-h/fake_windows_xp_activation2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/fa1jUBjFGOU/s200-R/fake_windows_xp_activation2.png" /></a>The increase of <a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">rogue security software domains</a> is happening due to the high payout affiliation based model, the standardized creative allowing the participants to come up with their own fake names if they want to, and due to the fact that the fake security threats scareware approach seems to be perfectly taking advantage of the overall suspicion on the effectiveness of their legitimate security software.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mw30M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mw30M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WJFzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WJFzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jNfpm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jNfpm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9lodm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9lodm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6go3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6go3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TLsPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TLsPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JuYBm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JuYBm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413264124" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 15:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card theft">credit card theft</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/mega virus cleaner">mega virus cleaner</category>
      <category domain="http://securityratty.com/tag/creative">creative</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413264124/fake-windows-xp-activation-trojan-wants.html">Fake Windows XP Activation Trojan Wants Your CVV2 Code</source>
    </item>
    <item>
      <title><![CDATA[Inc 500/5000 Conference Summary]]></title>
      <link>http://securityratty.com/article/9368d02fff1906cea272fe55093a6965</link>
      <guid>http://securityratty.com/article/9368d02fff1906cea272fe55093a6965</guid>
      <description><![CDATA[It didnt really sink in until after the final black-tie awards ceremony finished last Saturday night that I had a chance to comprehend how starting a company that achieves this list is a once in a...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/slinc5002.jpg" border="0" alt="slinc5002" width="240" height="181" align="left" /> It didn’t really sink in until after the final black-tie awards ceremony finished last Saturday night that I had a chance to comprehend how starting a company that achieves <a href="http://www.inc.com/inc5000/">this list</a> is a once in a lifetime experience.</p>
<p>When I walked up on stage and accepted the <a href="http://www.inc.com/inc5000/2008/company-profile.html?id=200803500" target="_blank">Inc 500 award</a>, it hit me square in the face that this is a rare accomplishment, and even more difficult for a product company that started without the benefit of VC funding.</p>
<p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/slinc5003.jpg" border="0" alt="slinc5003" width="240" height="181" /><br />
<em>Dave with wife, Anne, at the awards ceremony</em><br />
Over <a href="http://blog.inc.com/inc5000/" target="_blank">the 2 day period</a>, I heard from some <a href="http://secure.lenos.com/lenos/inc/Inc500WashingtonDC/speakers.asp" target="_blank">great speakers with entrepreneurial passion</a>, many who never had accomplished making the list. It is so <a href="http://www.prospectmx.com/inc-500-conference-and-awards" target="_blank">highly competitive and just plain hard</a> to do.</p>
<p>I loved <a href="http://blog.sciencelogic.com/good-to-great-built-to-last-whats-next-for-creating-great-companies/09/2008" target="_blank">hearing</a> some of the <a href="http://www.business-opportunities.biz/2008/09/24/inside-small-biz-guru-michael-gerbers-dreaming-room/" target="_blank">speeches during the conference</a> and getting to know other <a href="http://www.johnwinsor.com/my_weblog/2008/09/inc-500.html" target="_blank">entrepreneurs that attended</a> the conference talk about how they created their niche and ultimately built a successful company from a good idea.</p>
<p>Because I enjoyed hearing some of what I like to call &#8220;golden nuggets of wisdom&#8221; so much, I thought in my conference wrap-up I would pass on a few to our blog readers:</p>
<p><strong></strong></p>
<p><strong><a href="http://www.tompeters.com/" target="_blank">Tom Peters – Author In Search of Excellence and The New World of WOW</a></strong></p>
<p>“Only 7% of our great nation works for Fortune 500 companies. Small businesses and the <a href="http://www.jonlowder.com/2008/09/why-i-havent-be.html" target="_blank">entrepreneurs are the jet fuel</a> that makes our country fly.”</p>
<p>“Brand is shorthand for a collection of experiences, memories of what it will be like the next time a customer deals with you. With the <a href="http://www.debbieweil.com/blog/tom-peters/" target="_blank">advent of blogs and consumer activism</a>, Brand is impossible to fake; it is like the temperature in the room… it is there… it exists.”</p>
<p><strong><a href="http://www.carrots.com/" target="_blank">Chester Elton – SVP Carrot Culture Group</a></strong></p>
<p>“At the casino – they train the heck out of the Valet! Why do they spend 3 months on Valet training? Because he is the first and the last person to greet and interact with a visitor during their trip! Who is your company Valet?”</p>
<p><strong><a href="http://www.ideo.com/search/cluster/paul-bennett/" target="_blank">Paul Bennett – Chief Creative officer IDEO</a> – speaking on &#8212; Creating a culture of optimism:</strong></p>
<p>“You need to ditch B-B and B-C Need to become P-P Person to Person.”</p>
<p>“You don’t buy loyalty… you earn it… this is an interesting challenge, but small allows us to behave like human beings… Going off script and doing something human is a great place to start.”</p>
<p>“Stop obsessing about ROI and start obsessing about ROC! Return on Customer/Consumer is much more powerful than ROI!!!!”</p>
<p>“Happy people, unabashedly doing, happy things, makes for happy companies, which create happy businesses which enable happy cultures… IN WHICH THRIVE”</p>
<p><strong><a href="http://carlson.umn.edu/Page5365.aspx" target="_blank">Marilyn Carlson Nelson – Chairman and CEO Carlson Companies</a> – A family owned $40 Billion empire including TGI Fridays, Radisson Hotels…</strong></p>
<p>“My leadership was tested terribly - after 9/11 the travel industry was particularly harmed. It was an extraordinary time for Carlson. “</p>
<p>“Put tactics around these strategic initiatives”</p>
<ul>
<li>Whomever you serve, serve with caring</li>
<li>Whenever you dream – dream with your all</li>
<li>Wherever you go, go as a leader</li>
<li>And never, never give up</li>
<li>Whatever you do – do it with integrity</li>
</ul>
<p>“That builds trust, trust builds relationships and relationships build results.”</p>
<p>=============================================</p>
<p>Actually, I took about 40 pages of notes throughout the two days… So I can’t say that this will be my last summary post on the Inc 500/5000 conference, but I can say that the conference did leave a strong impression about how I can help shape the future of ScienceLogic in an even more positive way.</p>
]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 14:00:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <category domain="http://securityratty.com/tag/happy companies">happy companies</category>
      <category domain="http://securityratty.com/tag/happy">happy</category>
      <category domain="http://securityratty.com/tag/successful company">successful company</category>
      <category domain="http://securityratty.com/tag/happy businesses">happy businesses</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/product company">product company</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/ceo carlson companies">ceo carlson companies</category>
      <source url="http://blog.sciencelogic.com/inc-5005000-conference-summary/09/2008">Inc 500/5000 Conference Summary</source>
    </item>
    <item>
      <title><![CDATA[John Zanni Delivers Keynote at the Tier1 Hosting Transformation Summit]]></title>
      <link>http://securityratty.com/article/e6b5db3dba618f48e7fa728ff2173006</link>
      <guid>http://securityratty.com/article/e6b5db3dba618f48e7fa728ff2173006</guid>
      <description><![CDATA[As General Manager of Worldwide Hosting, John Zanni is a key guy for every Managed Service Provider delivering Microsoft based solutions. At this years Hosting Transformation Summit , John gave a...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="spla_image" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/spla-image.png" width="244" align="left" border="0"> As General Manager of Worldwide Hosting, <a href="http://www.microsoft.com/presspass/features/2008/jul08/07-29qazanni.mspx" target="_blank">John Zanni is a key guy for every Managed Service Provider</a> delivering Microsoft based solutions. At this year&#8217;s <a href="http://www.hostingtransformation.com/na/2008/" target="_blank">Hosting Transformation Summit</a>, John <a href="http://www.hostingtransformation.com/na/2008/agenda.php" target="_blank">gave a keynote</a> titled: &#8220;Leadership Perspective: Cloud Computing – is Virtualization Enough?&#8221;</p>
<p>John talked <a href="http://blogs.zdnet.com/BTL/?p=10007" target="_blank">about Microsoft’s mission</a>, his perspectives on key industry trends and market opportunity; he touched on <a href="http://www.betanews.com/article/Will_Microsofts_virtualization_spur_a_lot_more_cloud_computing/1221867502" target="_blank">Cloud Computing and Virtualization</a> and took some Q&amp;A from the audience of <a href="http://technet.microsoft.com/en-us/serviceproviders/default.aspx" target="_blank">Managed Service Provider</a> executives.</p>
<p>One of his first proclamations - Microsoft has really embraced the heterogeneous environment. Really? How in the world is Microsoft going to help convince IT line managers, or mid level managers to believe this statement? I think they have a long way to go to achieve this vision with any credibility in the marketplace.&nbsp; I do know that they are making small strides.</p>
<p>Microsoft has been widely credited with some very good blogs that are self critical and introspective. They have also been quite active in the standards boards within <a href="http://www.dmtf.org/home" target="_blank">DMTF</a> and many others such as <a href="http://www.openwsman.org/" target="_blank">Open WSMAN</a> and CIMON (<a href="http://www.openpegasus.org/" target="_blank">Open Pegasus</a>). Microsoft in February published 30,000 pages detailed technical specifications – protocol documentation for Exchange, since that time they have published another 15,000 pages. They have had over 224,000 downloads since February 21, 2008. Thus they are trying to be more open by making some of these <a href="http://www.microsoft.com/about/legal/intellectualproperty/protocols/default.mspx" target="_blank">secret sauce protocol resources</a> <a href="http://msdn.microsoft.com/openprotocols" target="_blank">directly available on the web</a>.</p>
<p>So for now, I will take a very cautious wait and see approach to this proclamation. Time will tell.</p>
<p><strong>Trends</strong></p>
<ul>
<li>Rapid growth continues
<li>Hosting Competition has a new face
<ul>
<li>Platform gorillas (amazooglesoft)
<li>Ad supported Web 2.0 hosters (Google, Facebook,) </li>
</ul>
<li>Utility Cloud Computing models are expanding to non-traditional hosting companies
<ul>
<li>Wells Fargo vSafe - hard to believe that a big bank would start to offer a SaaS offering
<li>New tools and markets digital ribbon, CohesiveIT </li>
</ul>
</li>
</ul>
<p><a href="http://mshostingsummit08.spaces.live.com/blog/cns!4308FE7290C0AF4!245.entry" target="_blank">IDC Data shows that growth of SaaS ISV’s is the biggest layer of growth</a>. The fastest growing services are complex, custom applications. IDC says this area will be bigger than the hosting area in the next 5 years. John said that <a href="http://blogs.msdn.com/ukisv/archive/2008/09/22/the-route-to-saas-and-beyond-final-seminar-places-remain-2nd-oct-08.aspx" target="_blank">Microsoft is spending a lot of time, money and energy on this right now</a>.</p>
<p>John said:</p>
<blockquote><p>“when Microsoft thinks about the building blocks that make-up the cloud, <a href="http://www.microsoft.com/virtualization/" target="_blank">virtualization is a core piece</a> of the puzzle. However you also need also identity services, Operating system with standard set of libraries to tap into… or remote storage that application developers will tap into.. Developers will consume these set of services, but you will also need a set of tools to manage your physical, virtual and geographically distributed datacenter infrastructure.” (that is where ScienceLogic comes in!!)</p>
</blockquote>
<p>He went on to say,</p>
<blockquote><p>“In some ways, virtualization enables decentralization – allows you to move from data centers, enables fast scaling out, business to move from on premise to the cloud and off again…. Automation is very important – this will help you scale your business – this is core to your future success.”</p>
</blockquote>
<p>He talked about a new breed of knowledge worker: He called them Digital Natives (compared to grey haired guys like me who are left out of this category).</p>
<p>Definition of a Digital natives? A young adult who has grown up with cellphone, web based applications, Facebook account, as their primary mode of communications.</p>
<p>John commented that we are 5 years into a 10 year journey. Only 12% of all servers in the world are virtualized today… in the next 4 years it will double to 25%. This is <a href="http://www.interopnews.com/news/vmware-ceo-maritz-addresses-virtualization-the-cloud-and-cha.html" target="_blank">the time to think through</a> how this business will affect you.</p>
<blockquote><p>‘Virtualization without good management is more dangerous than not using virtualization in the first place.” Thomas Bittman, Analyst Gartner</p>
</blockquote>
<p>Patching and provisioning nightmare – no scalable administration – sprawl chaos.</p>
<p>John posed a question to the audience: How do you partner to provide the ISV support in application development with specific market needs… partner by keeping the <a href="http://tarrysingh.blogspot.com/2008/09/microsofts-coo-on-cloud-computing.html" target="_blank">hosting to SaaS solution</a> providers up and running and provide the quality of service that their customers expect…. Complimentary services of storage and backup is a big win with a huge market-upside over the next 5 years..</p>
<p>John said that <a href="http://blogs.msdn.com/mhpta/archive/2008/04/10/microsoft-hosting-summit-2008.aspx" target="_blank">Microsoft continues</a> to make&nbsp; <a href="http://www.virtualization.info/2008/07/microsoft-bets-on-hosting-providers-to.html" target="_blank">huge investments with Managed Service Providers</a>.</p>
<ul>
<li>Investing in the <a href="http://www.microsoft.com/hosting/" target="_blank">windows hosting platform</a>
<li>Hyper V and SQL2008 GoLive program - getting beta code out to service provides to find as many bugs as early as possible.
<li><a href="http://blogs.msdn.com/stevecla01/archive/2008/09/22/explaining-software-plus-services.aspx" target="_blank">Software + Services (S+S)</a> incubation center program
<li>Partnering for <a href="http://tarrysingh.blogspot.com/2008/09/microsofts-coo-on-cloud-computing.html" target="_blank">cloud platform market offers</a>
<li>Cloud platform guidance and best practices </li>
</ul>
<p>During the Q&amp;A, David Burns from Cincinnati Bell asked the very best question… “when are you going to make it easier for the Service Provider market to <a href="http://www.virtualization.info/2008/09/microsoft-to-allow-3rd-parties-to.html" target="_blank">deal with the Microsoft Service Provider Licensing Agreement (SPLA)</a> quarterly statistics pull and change the SPLA pricing to be more efficient and creative for the new Virtualization and Cloud offerings you have talked about?&#8221;</p>
<p>John’s response: “We hear your frustrations loud and clear and are working on some new ideas for the future version of SPLA.” My interpretation – &#8220;Dear Service Providers don’t expect anything new or easier to deal with in the next 6 months!&#8221;</p>
<p>His closing remarks: &#8220;Cloud is evolving = very early stages, lots of hype, but think of how this evolution will effect your business and how you can plug into it.”</p>
]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 12:00:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/service provider market">service provider market</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service provider executives">service provider executives</category>
      <category domain="http://securityratty.com/tag/john">john</category>
      <category domain="http://securityratty.com/tag/john zanni">john zanni</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/microsoft based solutions">microsoft based solutions</category>
      <source url="http://blog.sciencelogic.com/john-zanni-delivers-keynote-at-the-tier1-hosting-transformation-summit/09/2008">John Zanni Delivers Keynote at the Tier1 Hosting Transformation Summit</source>
    </item>
    <item>
      <title><![CDATA[Mark Curphey On Builders and Breakers]]></title>
      <link>http://securityratty.com/article/207400daa5782f9a7cfce814ad45404e</link>
      <guid>http://securityratty.com/article/207400daa5782f9a7cfce814ad45404e</guid>
      <description><![CDATA[Superb post by Mark on what I think is the biggest problem we have in security. One thing you learn in consulting is that no matter what anyone tells you when you start a project about what problem...]]></description>
      <content:encoded><![CDATA[<p>Superb <a href="http://securitybuddha.com/2008/09/10/are-you-a-builder-or-a-breaker/">post</a> by Mark on what I think is the biggest problem we have in security. One thing you learn in consulting is that no matter what anyone tells you when you start a project about what problem you are trying to solve, it is <span style="font-style: italic;">always</span> a people problem. The single biggest problem in security is too many breakers not enough builders. Please understand I am not saying that breakers are not useful, we need them, and we need them to continue to get better so we can build more resilient systems. But the industry is about 90% breaking and 10% building and thats plain bad.</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Georgia; line-height: 19px; ">It’s still predominantly made up of an army of skilled hackers focused on better ways to break systems apart and find new ways to exploit vulnerabilities than “security architects” who are designing secure components, protocols and ultimately secure systems. If you don’t believe me go have a conversation with a&#160; so called application security&#160; consultant about SAML or security issues in Enterprise Message Buses and you’ll almost definitely draw blank stares. Ask application security consultants if they know about the latest HTTP or HTML spec and they’ll likely say yes (and want to demonstrate the latest issues) but if you ask them about the latest WS-x spec you’ll likely draw more blank stares.&#160; When was the last time you saw an attack drawn out as a UML sequence diagram? This is worrying and somewhat sad. I don’t think we are culturing, encouraging and nurturing people with the right skills to make a positive difference.&#160;</span></p></blockquote><br /><div>This is exactly my experience as well. Not only that, we have too much destruction and not enough construction, this is a big enough problem all by itself. I would go one step further and say we need creative destruction, breakers breaking things that lead to better systems over time. Maybe we need an OWASP Builders project?</div><br /><div>In any case, for my small part I am builder. I teach a <a href="http://arctecgroup.net/training.htm">class</a> (and will at <a href="http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference">OWASP</a>) that is 100% focused on building secure Web services, identity management, distribut authN, authZ, message security and so on. I can tell you first hand there are not a lot of people approaching the problem from a builder mindset.&#160;</div>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 08:02:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/issues">issues</category>
      <category domain="http://securityratty.com/tag/security issues">security issues</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/application security consultants">application security consultants</category>
      <category domain="http://securityratty.com/tag/message security">message security</category>
      <category domain="http://securityratty.com/tag/builders">builders</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/security architects">security architects</category>
      <category domain="http://securityratty.com/tag/resilient systems">resilient systems</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/mark-curphey-on-builders-and-breakers.html">Mark Curphey On Builders and Breakers</source>
    </item>
    <item>
      <title><![CDATA[New Security Warning Feature Added On Facebook]]></title>
      <link>http://securityratty.com/article/f424d001f760137de9402a229d810d0f</link>
      <guid>http://securityratty.com/article/f424d001f760137de9402a229d810d0f</guid>
      <description><![CDATA[Facebooks security team has introduced a new security related warning feature that alerts users about potentially malicious third-party websites they are about to visit. Facebook is persistently under...]]></description>
      <content:encoded><![CDATA[Facebook&#8217;s security team has introduced a new security related warning feature that alerts users about potentially malicious third-party websites they are about to visit. Facebook is persistently under attacks from phishers and malware authors who look for creative ways to efficiently exploit Facebook&#8217;s huge users base.
New Facebook feature is adding a warning message to links [...]]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 19:28:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/feature">feature</category>
      <category domain="http://securityratty.com/tag/facebook feature">facebook feature</category>
      <category domain="http://securityratty.com/tag/facebooks security team">facebooks security team</category>
      <category domain="http://securityratty.com/tag/malicious third-party websites">malicious third-party websites</category>
      <category domain="http://securityratty.com/tag/alerts users">alerts users</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <source url="http://cyberinsecure.com/new-security-warning-feature-added-on-facebook/">New Security Warning Feature Added On Facebook</source>
    </item>
  </channel>
</rss>
