<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dependability]]></title>
    <link>http://securityratty.com/tag/dependability</link>
    <description></description>
    <pubDate>Sun, 25 Mar 2007 20:30:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Real-Time OSINT vs Historical OSINT in Russia/Georgia Cyberattacks]]></title>
      <link>http://securityratty.com/article/20a44f5ecd81be809dacc26141c04b6b</link>
      <guid>http://securityratty.com/article/20a44f5ecd81be809dacc26141c04b6b</guid>
      <description><![CDATA[The original real-time OSINT analysis of the Russian cyberattacks against Georgia conducted on the 11th of August, not only closed the Russia vs Georgia cyberwar case for me personally, but also, once...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SPfiGY9ParI/AAAAAAAACT4/qFAdE-rdQZs/s1600-h/georgia_ddos13.JPG.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SPfiGY9ParI/AAAAAAAACT4/9N9uGXoRSB4/s200-R/georgia_ddos13.JPG.png" /></a>The original <a href="http://blogs.zdnet.com/security/?p=1670">real-time OSINT analysis of the Russian cyberattacks against Georgia</a> conducted on the 11th of August, not only closed the Russia vs Georgia cyberwar case for me personally, but also, once again proved that real-time OSINT is invaluable compared to <a href="http://www.scribd.com/doc/6967393/Project-Grey-Goose-Phase-I-Report">historical OSINT using a commercial social network visualization/data mining tool</a> which cannot and will never be able to access the Dark Web, accessible only through real-time <a href="http://ddanchev.blogspot.com/2006/09/cyber-intelligence-cyberint.html">CYBERINT practices</a>.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SPyTGJhYQJI/AAAAAAAACUI/P3h69SzYPm8/s1600-h/georgia_ddos_botnet_cc.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SPyTGJhYQJI/AAAAAAAACUI/LwvYHvdpiFQ/s200-R/georgia_ddos_botnet_cc.png" /></a>The value of real-time OSINT in such <a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">people's information warfare cyberattacks</a> -- with <a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">Chinese hacktivists</a> perfectly aware of the <a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">meaning of the phrase</a> -- relies on the relatively lower operational security (OPSEC) the initiators of a particular campaign apply at the beginning, so that it would scale faster and attract more participants. What the Russian government was doing is fueling the (cyber) fire - literally, since all it takes for a collectivist socienty's cyber militia to organize, is a "call for action" which was taking place at the majority of forums, with the posters of these messages apparently using a spamming application to achieve better efficiency.<br />
<br />
<a href="http://intelfusion.net/wordpress/?p=430">The results</a> from 56 days of <a href="http://intelfusion.net/wordpress/?p=398">Project Grey Goose</a> in action got published last week, a project <a href="http://ddanchev.blogspot.com/2008/09/summarizing-augusts-threatscape.html">I discussed back in August</a>, point out to the bottom of the food chain in the entire campaign - <b>stopgeorgia.ru</b> :<br />
<br />
<a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SPfkXQ-08xI/AAAAAAAACUA/qd9xv7kt2Qw/s1600-h/georgia_ddos8.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SPfkXQ-08xI/AAAAAAAACUA/dnYU_GbeEnw/s200-R/georgia_ddos8.JPG" /></a>"<i>Furthermore, coming up with <a href="http://intelfusion.net/wordpress/?p=398">Social Network analysis of the cyberattacks</a> would produce nothing more but a few fancy graphs of over enthusiastic Russian netizen's distributing the static list of the targets. The real conversations, as always, are <a href="http://blogs.nyu.edu/blogs/agc282/zia/2008/08/intelfusions_sna_of_russian_cy.html">happening in the "Dark Web" limiting the possibilities for open source intelligence</a> using a data mining software. Things changed, OPSEC is slowly emerging as a concept among malicious parties, whenever some of the "calls for action" in the DDoS attacks were posted at mainstream forums, they were immediately removed so that they don't show up in such academic initiatives</i>"<br />
<br />
So what's the bottom line? Nothing that I haven't already pointed out back in August : "<a href="http://voices.washingtonpost.com/securityfix/2008/10/report_russian_hacker_forums_f.html">Report: Russian Hacker Forums Fueled Georgia Cyber Attacks</a>" :<br />
<br />
"<i>But experts say evidence suggests that Russian officials did little to discourage the online assault, which was coordinated through a Russian online forum that appeared to have been prepped with target lists and details about Georgian Web site vulnerabilities well before the two countries engaged in a brief but deadly ground, sea and air war."</i>  <br />
<br />
<a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9117439&amp;source=NLT_PM&amp;nlid=8">Some more comments</a> :<br />
<br />
"<i>Just because there was no smoking gun doesn't mean there's no connection," said Jeff Carr, the principal investigator of Project Grey Goose, a group of around 15 computer security, technology and intelligence experts that investigated the August attacks against Georgia. "I can't imagine that this came together sporadically," he said. "I don't think that a disorganized group can coalesce in 24 hours with its own processes in place. That just doesn't make sense.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SPyW6yXyA5I/AAAAAAAACUQ/roWip-fqbeE/s1600-h/georgia_packet_clearing_house.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SPyW6yXyA5I/AAAAAAAACUQ/7oAwAggiAKE/s200-R/georgia_packet_clearing_house.jpg" /></a>It wouldn't make sense if this was the first time Russian hacktivists are maintaining the same rhythm as real-life events - <a href="http://blogs.zdnet.com/security/?p=1408">which of course isn't</a>.<br />
<br />
Moreover, exactly what would have constituted a "smoking gun" proving that the Russian government was involved in the campaign, remains unknown -- I'm still sticking to my comment regarding <a href="http://georgiaupdate.gov.ge/doc/10006744/CYBERWAR-%20fd_2_new.pdf">the web site defacement creative</a>. If they truly wanted to compromise themselves, they would have cut Georgia off the Internet, at least from the perspective offered by this graph courtesy of the <a href="http://www.pch.net/">Packet Clearing House</a> speaking for their dependability on Russian ISPs. <br />
<br />
As for <a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">the script kiddies</a> at <b>stopgeorgia.ru</b>, <a href="http://74.125.39.104/search?hl=en&amp;q=cache%3Astopgeorgia.ru%2F%3Fpg%3Dser&amp;aq=f&amp;oq=">they were informed enough to feature my research into their "negative public comments section"</a>. To sum up - the "DoS battle stations operational in the name of the "<i><a href="http://www.alexandrasamuel.com/dissertation/pdfs/Samuel-Hacktivism-entire.pdf">Please, input your cause</a></i>" mentality is always going to be there.<b><br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BxRfM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BxRfM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iUQ7M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iUQ7M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9vGjm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9vGjm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=85DIm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=85DIm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mX8FM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mX8FM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XswSM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XswSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wZ9Jm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wZ9Jm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/426491766" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 05:58:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/cyberattacks">cyberattacks</category>
      <category domain="http://securityratty.com/tag/cyber">cyber</category>
      <category domain="http://securityratty.com/tag/georgia cyber attacks">georgia cyber attacks</category>
      <category domain="http://securityratty.com/tag/real-time osint">real-time osint</category>
      <category domain="http://securityratty.com/tag/project">project</category>
      <category domain="http://securityratty.com/tag/project grey goose">project grey goose</category>
      <category domain="http://securityratty.com/tag/forums">forums</category>
      <category domain="http://securityratty.com/tag/cut georgia">cut georgia</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/426491766/real-time-osint-vs-historical-osint-in.html">Real-Time OSINT vs Historical OSINT in Russia/Georgia Cyberattacks</source>
    </item>
    <item>
      <title><![CDATA[Wakeup Call for Risk Management]]></title>
      <link>http://securityratty.com/article/5c961827ce1d8ef57419fb5d2d847236</link>
      <guid>http://securityratty.com/article/5c961827ce1d8ef57419fb5d2d847236</guid>
      <description><![CDATA[Blogger: Dan Blum
With the crisis in financial markets still unfolding, it is important to draw what lessons we can from the experience. Since the roots of the crisis lie in a monumental failure of...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>With the crisis in financial markets still unfolding, it is important to draw what lessons we can from the experience. Since the roots of the crisis lie in a monumental failure of risk management, it’s important to understand more about what happened, and then draw some parallels to our business risk management and&nbsp; IT risk management situations.</p>

<p>The risk management failure in the housing market and on Wall Street had multiple interdependent dimensions:</p>

<ul><li><strong>Mortgage lenders abandoned long standing prudent loan practices</strong>. They made too many loans that buyers might not be able to repay. Exotic instruments like ARMs, option ARMs, and interest only loans proliferated. In many cases, all pretense of lending standards were abandoned, so-called “liar loans” approved.</li>

<li><strong>Capital was grossly over-leveraged</strong>. Mortgage lenders and other financial services packaged loans into securities, which they sold to raise capital to support more lending. Real capital reserve requirements to back loans were reduced. Of course, if borrowers could not repay loans, all or parts of the derivative securities would become worthless.</li>

<li><strong>Risk was aggregated at Fannie Mae, Freddie Mac, and mortgage loan insurance companies</strong>. These companies bought or insured some mortgage loans, providing something of a backstop should loans fail. Government sponsored enterprises (GSEs) Fannie and Freddie in turn became over-leveraged and securities that they sold were in turn repackaged in the murky brew of mortgage-backed securities called collateralized debt obligations (CDOs) and other exotic instruments returning generous yields. </li>

<li><strong>Non-Caveat Emptor.</strong> Institutional wealth funds and financial services firms who should have known better bought securities that had been deliberately structured to obfuscate risk. They bought securities they didn’t understand with buried tranches of toxic subprime loans..</li></ul>

<p>It was a great Ponzi scheme – one that kept working as long as housing prices were going up; the recipients of subprime loans could always flip that house to the next buyer. Everyone made money. As Chuck Prince of Citigroup famously put it during <a href="http://search.ft.com/ftArticle?sortBy=gadatearticle&amp;queryText=chuck+prince+dancing&amp;y=0&amp;aje=true&amp;x=0&amp;id=070710000610&amp;ct=0&amp;page=6&amp;nclick_check=1">a July, 2007 interview</a>: “So long as the music is playing, you’ve got to keep dancing. We’re still dancing.” But one month later, the music stopped. Since then, Citigroup and other financial institutions have taken massive writeoffs with more to come. Wall Street titans like Bear Sterns, Lehman Brothers, Merrill Lynch, and AIG have fallen or been bought out.</p>

<p>What can we learn from this risk management debacle?</p>

<p>As business risk managers and investors, we should ask questions like these:</p>

<ul><li><strong>Does the executive incentive structure of the company encourage managers to dance around risk?</strong> Many Wall Street firms paid senior managers 5 times their salary in bonuses tied to annual growth alone.</li>

<li><strong>Is the company over-leveraged?</strong> Is it borrowing too much money and betting it on ventures with uncertain outcomes?</li>

<li><strong>Are financial models used for risk management realistic?</strong> Earlier, I described the mortgage market of the past few years as a Ponzi scheme, where risk management models must have assumed prices would keep rising. Unlike the dotcom boom whose demise many predicted, very few in the industry foresaw the sharp declines to come in housing prices and sales volumes. Historically, the U.S. housing market has been a steadily rising one, but on the other hand the 2000s saw unprecedented rates of price increases. In reality, what goes up must come down. </li>

<li><strong>Has your company’s risk council ever performed worst case scenario analysis and built adequate reserves?</strong> In the days before economics emerged as a would-be “hard” deterministic science, business leaders may have been more cautious, more aware of and more accepting of uncertainty. Events like the Great Tulip Bubble came once in decades or centuries – not every few years. Note that legendary investor George Soros has proposed a Theory of Reflexivity that, if true, helps explain the recent extremes of boom and bust cycles. This theory holds that market participants model market behaviors based on self-interest, and for a time, their manipulations change the reality of the market – until gravitational forces bring it back to earth. Has the music of ephemeral success played to the backbeat of deterministic-sounding economic models gone to your heads and infected your risk management models? </li>

<li><strong>Are cost cutting efforts pursued blindly?</strong> Outsourcing and other forays into treacherous global waters may be giving away the crown jewels. Smart companies cut costs, but they do it in smart ways. Smart companies think like intelligence agencies as they parcel out work to different partners with varying levels of dependability, and they check on those partners.</li></ul>

<p>Risk management failures can also occur at the more technical level of IT security. As IT risk managers, we might ask questions like these:</p>

<ul><li><strong>Are the accounting and financial systems your IT department supports under adequate control?</strong> As Fred Cohen wrote in <a href="http://www.burtongroup.com/Client/Research/Document.aspx?cid=750">one of our documents</a>: “Many companies use computers to manage financial systems, and despite the Sarbanes-Oxley Act (SOX) claims about accounts being properly kept, there are many attacks on financial systems that remain. For example, most of the largest financial systems in the world running on common financial databases do not use <a href="http://en.wikipedia.org/wiki/Double-entry_bookkeeping">double-entry bookkeeping</a> and are thus susceptible to all manner of frauds by insiders.” We find it troubling that a prudent control dating back to the 12th century is going out of style in the name of convenience and cost cutting. Kind of like credit checking became anachronistic during the housing bubble, eh?</li>

<li><strong>Is the “separation” in your “separation of duty” (SoD) for real?</strong> Sure the SOX auditors are looking for SoD, and maybe you have different administrators with different accounts maintaining different systems or functions. But when they say Western civilization may be but one weak password from collapse they’re not lying. Look what happened to Sarah Palin’s email account! Weak and straggly SoD is a problem across all critical IT systems where deperimiterization and server consolidation may be bringing down protective barriers, identity management is weak, and strong process controls (e.g., where two people must sign on, one perform a critical operation such as backbone router reconfiguration, and the second observe) abandoned in the name of expediency. </li>

<li><strong>Are risks being aggregated to unacceptable levels in centralized control systems?</strong> There are many ways that risks aggregate within enterprise IT infrastructures as we pursue automation and cost cutting. Network risks aggregate when centralized domain name system control is implemented. Application risks aggregate when common infrastructure is shared among applications. And enterprises aggregate platform risks when they use low-assurance endpoints, authentication, and directory systems with single sign-on to access large numbers of resources and don’t separate high consequence systems. </li>

<li><strong>Non-caveat emptor:</strong> Has IT security really done the worst case consequence analysis, attack graphs, and vulnerability analysis to know when putting more eggs in a supposedly stronger basket aggregates risks to an unacceptable level? Or are you depending only on vendor claims about some black box appliance equivalent of a risk-obfuscated CDO security? Caveat emptor (buyer beware) again! (The good news is we’ll keep talking about promoting vendor and product rating systems so you don’t have to do all the detailed product analysis yourself, but that’s another post.)</li></ul>

<p>There are many parallels between the monumental risk management failure in the financial markets, and the probable weaknesses in our day to day business risk management and IT risk management. Abandonment of prudent practices for profit; excessive leverage and centralization; ill-constructed risk analysis models; risk obfuscation; and a failure of caveat emptor seem to be common problems. Please take this as a wakeup call to sharpen up the risk management thinking, process, and execution.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/397240912" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 06:11:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management debacle">risk management debacle</category>
      <category domain="http://securityratty.com/tag/risk management failure">risk management failure</category>
      <category domain="http://securityratty.com/tag/failure">failure</category>
      <category domain="http://securityratty.com/tag/risk management realistic">risk management realistic</category>
      <category domain="http://securityratty.com/tag/business risk management">business risk management</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management situations">risk management situations</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/397240912/wakeup-call-for.html">Wakeup Call for Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Up Scope]]></title>
      <link>http://securityratty.com/article/b7bdb7ad6863d0034b53046a3701c2b9</link>
      <guid>http://securityratty.com/article/b7bdb7ad6863d0034b53046a3701c2b9</guid>
      <description><![CDATA[The scope of the magazine is being expanded to incorporate reliability and dependability concerns and its readership will include members of the IEEE Reliability Society. This expansion is appropriate...]]></description>
      <content:encoded><![CDATA[The scope of the magazine is being expanded to incorporate reliability and dependability concerns and its readership will include members of the IEEE Reliability Society. This expansion is appropriate because the requirements for a system to be reliable, safe, secure (i.e. its dependability or trustworthiness attributes) often need to be considered together in order to achieve the desired result.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=afd6d1bce3dc7ddac0a02fa8498c1ed0"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=afd6d1bce3dc7ddac0a02fa8498c1ed0"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=afd6d1bce3dc7ddac0a02fa8498c1ed0" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 22 May 2008 10:32:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/reliability">reliability</category>
      <category domain="http://securityratty.com/tag/ieee reliability society">ieee reliability society</category>
      <category domain="http://securityratty.com/tag/dependability">dependability</category>
      <category domain="http://securityratty.com/tag/dependability concerns">dependability concerns</category>
      <category domain="http://securityratty.com/tag/scope">scope</category>
      <category domain="http://securityratty.com/tag/trustworthiness attributes">trustworthiness attributes</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/include">include</category>
      <source url="http://www.pheedo.com/click.phdo?i=afd6d1bce3dc7ddac0a02fa8498c1ed0">Up Scope</source>
    </item>
    <item>
      <title><![CDATA[CCNP BOOT CAMP]]></title>
      <link>http://securityratty.com/article/67211fa0db1aea1a7bf80d1acc0cc839</link>
      <guid>http://securityratty.com/article/67211fa0db1aea1a7bf80d1acc0cc839</guid>
      <description><![CDATA[The CCNP certification (Cisco Certified Network Professional) indicates advanced knowledge of networks. Cisco certified CCNP certification validates a network professional's ability to configure,...]]></description>
      <content:encoded><![CDATA[<div align="justify"><span style="font-family:verdana;font-size:85%;">The </span><a href="http://www.netzoneindia.net/ccnp.html"><span style="font-family:verdana;font-size:85%;">CCNP certification</span></a><span style="font-family:verdana;font-size:85%;"> (Cisco Certified Network Professional) indicates advanced knowledge of networks. Cisco certified CCNP certification validates a network professional's ability to configure, install and operate LAN,WAN, and dial access services or troubleshoot converged local and wide area networks with 100 to 500 or more nodes. Network Professionals who achieve the CCNP have demonstrated the knowledge and skills required to manage the routers and switches that form the network core, as well as edge applications that integrate voice, wireless, and security into the network. The content emphasizes topics such as security, converged networks, quality of service (QoS), virtual private networks (VPN) and broadband technologies.<br /><br />The BenefitsThe CCNP boot camp would enable you to successfully attain a CCNP certification, which in turn would allow you to install, configure, operate and troubleshoot<br /><br />Boost Traffic flow, redundancy or dependability and Campus performance. LAN’s routed and switched WAN’s and networks from remote access.<br />Establish campus Network using Multilayer Switching Technologies.<br />Deploy organization’s VPN, QOS and converged networks.<br />Troubleshoot an environment that uses </span><a href="http://www.netzoneindia.net/tabindex.html"><span style="font-family:verdana;font-size:85%;">CISCO</span></a><span style="font-family:verdana;font-size:85%;"> routers and Switches for multi-protocol organisations hosts and services.</span></div>]]></content:encoded>
      <pubDate>Sun, 25 Mar 2007 20:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ccnp">ccnp</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network professionals">network professionals</category>
      <category domain="http://securityratty.com/tag/network core">network core</category>
      <category domain="http://securityratty.com/tag/network professional">network professional</category>
      <category domain="http://securityratty.com/tag/ccnp certification">ccnp certification</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <category domain="http://securityratty.com/tag/cisco routers">cisco routers</category>
      <source url="http://bootcampcourses.blogspot.com/2007/03/ccnp-boot-camp.html">CCNP BOOT CAMP</source>
    </item>
  </channel>
</rss>
