<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: full-blown]]></title>
    <link>http://securityratty.com/tag/full-blown</link>
    <description></description>
    <pubDate>Thu, 25 Sep 2008 12:05:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Data Mining for Terrorists Doesn't Work]]></title>
      <link>http://securityratty.com/article/205a9261660e694f495f2a2726701cd2</link>
      <guid>http://securityratty.com/article/205a9261660e694f495f2a2726701cd2</guid>
      <description><![CDATA[According to a massive report from the National Research Council, data mining for terrorists doesn't work. Here's a good summary: The report was written by a committee whose members include William...]]></description>
      <content:encoded><![CDATA[<p>According to a <a href="http://www.nap.edu/catalog.php?record_id=12452">massive report</a> from the National Research Council, data mining for terrorists doesn't work.  <a href="http://news.cnet.com/8301-13578_3-10059987-38.html?part=rss&subj=news&tag=2547-1_3-0-20">Here's</a> a good summary:</p>

<blockquote>The report was written by a committee whose members include William Perry, a professor at Stanford University; Charles Vest, the former president of MIT; W. Earl Boebert, a retired senior scientist at Sandia National Laboratories; Cynthia Dwork of Microsoft Research; R. Gil Kerlikowske, Seattle's police chief; and Daryl Pregibon, a research scientist at Google.

<p>They admit that far more Americans live their lives online, using everything from VoIP phones to Facebook to RFID tags in automobiles, than a decade ago, and the databases created by those activities are tempting targets for federal agencies. And they draw a distinction between subject-based data mining (starting with one individual and looking for connections) compared with pattern-based data mining (looking for anomalous activities that could show illegal activities).</p>

<p>But the authors conclude the type of data mining that government bureaucrats would like to do--perhaps inspired by watching too many episodes of the Fox series 24--can't work. "If it were possible to automatically find the digital tracks of terrorists and automatically monitor only the communications of terrorists, public policy choices in this domain would be much simpler. But it is not possible to do so."</p>

<p>A summary of the recommendations:</p>

<ul><li>U.S. government agencies should be required to follow a systematic process to evaluate the effectiveness, lawfulness, and consistency with U.S. values of every information-based program, whether classified or unclassified, for detecting and countering terrorists before it can be deployed, and periodically thereafter.

<p><li>Periodically after a program has been operationally deployed, and in particular before a program enters a new phase in its life cycle, policy makers should (carefully review) the program before allowing it to continue operations or to proceed to the next phase.</p>

<p><li>To protect the privacy of innocent people, the research and development of any information-based counterterrorism program should be conducted with synthetic population data... At all stages of a phased deployment, data about individuals should be rigorously subjected to the full safeguards of the framework.</p>

<p><li>Any information-based counterterrorism program of the U.S. government should be subjected to robust, independent oversight of the operations of that program, a part of which would entail a practice of using the same data mining technologies to "mine the miners and track the trackers."</p>

<p><li>Counterterrorism programs should provide meaningful redress to any individuals inappropriately harmed by their operation.</p>

<p><li>The U.S. government should periodically review the nation's laws, policies, and procedures that protect individuals' private information for relevance and effectiveness in light of changing technologies and circumstances. In particular, Congress should re-examine existing law to consider how privacy should be protected in the context of information-based programs (e.g., data mining) for counterterrorism.</ul></blockquote></p>

<p><a href="http://www.nytimes.com/2008/10/08/washington/08data.html">Here</a> <a href="http://blog.wired.com/27bstroke6/2008/10/data-mining-for.html">are</a> <a href="http://techdirt.com/articles/20081007/1242002479.shtml">more</a> news articles on the report.  I <a href="http://www.schneier.com/essay-108.html">explained</a> why data mining wouldn't find terrorists back in 2005.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=w2YwM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=w2YwM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=sK5kM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=sK5kM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 02:35:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/synthetic population data">synthetic population data</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/program enters">program enters</category>
      <category domain="http://securityratty.com/tag/research scientist">research scientist</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <category domain="http://securityratty.com/tag/microsoft research">microsoft research</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/data_mining_for_1.html">Data Mining for Terrorists Doesn't Work</source>
    </item>
    <item>
      <title><![CDATA[Why Risk Management Doesnt Work (?!)]]></title>
      <link>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</link>
      <guid>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</guid>
      <description><![CDATA[Several folks (Hi Daniel , Brent , David !) sent email &amp; twitters asking us our opinion on a Dark Reading article called Why Risk Management Doesnt Work which if you click on the link should come up...]]></description>
      <content:encoded><![CDATA[<p>Several folks (Hi <a href="http://dmiessler.com/">Daniel</a>, <a href="http://stateofsecurity.com/">Brent</a>, <a href="http://www.twitter.com/debix">David</a>!) sent email &amp; twitters asking us our opinion on a Dark Reading article called &#8220;<a href="http://www.darkreading.com/document.asp?doc_id=165107">Why Risk Management Doesn&#8217;t Work</a>&#8221; which if you click on the link should come up for you after seeing someone&#8217;s advertisement for a few seconds.</p>
<p>I&#8217;m assuming the author wants us to read the title as <strong>&#8220;Things to Look Out For in Performing Risk Analysis&#8221;</strong> and not <strong>&#8220;Risk Management is Folly - Stop, Stop, Stop!&#8221;</strong> The former is fine, the latter isn&#8217;t supported by the evidence presented by the subjects of the article.<br />
The subjects of the article are a <strong><a href="http://www.verizonbusiness.com/resources/security/databreachreport.pdf">good study from Wade Baker &amp; Co. at Verizon</a></strong>, and a report from RSA&#8217;s Security for Business Innovation Council. Let&#8217;s take a look at each of these and examine why what they&#8217;re saying might contribute to poor risk management, shall we?</p>
<p><strong>1.)  THE VERIZON REPORT</strong></p>
<p>The Verizon report is an analysis of some 530 forensic investigations their company performed.  It is well worth your time as it&#8217;s chock full of interesting information.  As it relates to the Dark Reading piece, a coarse summary would be that &#8220;likelihood&#8221; is &#8220;different&#8221; for different people and so you can&#8217;t use the same &#8220;likelihood&#8221; across different industries.</p>
<p>Distilled through the lens of FAIR:</p>
<blockquote><p>&#8220;different threat communities may be applicable based on Probability of Action factors which include: Value, Level of Effort and Risk (of Getting Caught).&#8221;</p></blockquote>
<p>Or, even further distilled and in the words of my six year old son,</p>
<blockquote><p>&#8220;Duh-uh&#8221;.</p></blockquote>
<p>With regards to what I assume is the purpose of the article (What Doesn&#8217;t Work in Risk Analysis) this concept  seems just to rehash the old GIGO argument regarding risk analysis.  Great.  Can&#8217;t argue with that, nor it&#8217;s corollary QIQO (quality in, quality out).</p>
<p>But let me ask you -  <strong><em>is this really a problem common in your analysis</em></strong>?  Did reading this article make you go &#8220;Crap, we&#8217;ve been using data normalized across multiple industries in our analysis! They&#8217;re all wrong!&#8221;  Or have you already been accounting for the unique value proposition your company has to the specific threat community you&#8217;re worried about?  See, maybe I&#8217;m just not your average analyst, but even in my NIST/OCTAVE days, this has *never* been an issue for me.</p>
<p>Let me be specific, this is not a problem with Verizon&#8217;s very cool report.  It&#8217;s just that I don&#8217;t see what the big deal is.  This article is starting to feel like someone is running through the motions, trying to play the &#8221; a crazy title gets people to read a boring article&#8221; game.</p>
<p>Speaking of cool reports - You know what would be cool?  I think it would be interesting to see is the quality of these companies&#8217; &#8220;risk management process&#8221; established using good criteria,  and then correlated to the frequency and magnitude of real-world losses across the aggregate sample.  In other words, can we establish evidence that strong risk management practices not just reduce &#8220;risk&#8221; but also reduce actual incidents.</p>
<p><strong>2.)  THE RSA COUNCIL &#8220;EXPLORES WHY LEGACY METHODS OF EVALUATING INFORMATION SECURITY RISK DON&#8217;T WORK IN TODAY&#8217;S CONNECTED WORLD, IN WHICH ANY NEW BUSINESS INNOVATION INHERENTLY CARRIES SOME LEVEL OF RISK TO INFORMATION.&#8221;</strong></p>
<p>This report from the RSA council puts forth a seemingly obvious proposition, that risk must be balanced by reward.  Why is this news?  Now as I read the article it&#8217;s not clear if:</p>
<ul>
<li>The RSA Council is claiming that the CISO&#8217;s office should be the ones determining reward.  Absurd.</li>
</ul>
<p>or</p>
<ul>
<li>Businesses aren&#8217;t doing a good job at determining risk and reward.</li>
</ul>
<p>Let&#8217;s go with the latter.  So I&#8217;m pretty sure (good) businesses do a good job at estimating reward.  Businesses I&#8217;ve been a part of?  We LOVE(D) estimating reward.  We don&#8217;t tend to start projects all willy-nilly. No we tend to be careful to identify the size of the market and what it will cost to address the market.  So what could the problem be that this RSA council is trying to address?  Maybe it has to do with something like the following:</p>
<p>Yesterday, I got a demo of an IT-GRC application that shall remain nameless.  It seemed to be very good at the &#8220;C&#8221; bits - lots of information on regulations and expectations and even what sorts of controls would answer the regulations (which is goofy, but we&#8217;ll have to talk about that later).  It also gave you the ability to build workflow quite nicely.  But it measured NOTHING.  There really was no observable &#8220;G&#8221; and &#8220;R&#8221; was really Medium X Low X Low = High sorts of stuff.  So let&#8217;s use this relatively expensive tool as evidence of what your average CISO is armed with going into a Risk/Reward sort of meeting.  I imagine a nice board room with wood-grain paneling and glass bowls filled with little chocolate covered mints designed to give everyone involved in the meeting (CEO, CFO, CIO, CSO, VP S&amp;M, etc&#8230;) a little sugar rush when needed and fresh breath.  The conversation goes a little something like this (apologies to <strong><a href="http://securosis.com/2008/09/17/the-fallacy-of-complete-and-accurate-risk-quantification/">Rich</a></strong>):</p>
<blockquote><p><em><strong>Business Guy Who Wants to Make Money Because That&#8217;s What Businesses Do:</strong></em> Based on market studies, we believe that initial gross revenues from the new product and technology rollout will be eleventy gazillion dollars based on a 37% market penetration in Scandinavia, alone.</p>
<p><em><strong>CSO: </strong></em> Well now, we have a likelihood of &#8220;High&#8221; and a &#8220;C&#8221; impact of Medium, and an &#8220;I&#8221; impact of Low, and an &#8220;A&#8221; impact of &#8220;High&#8221; and because we are a (bank/hospital/retailer/basically any business that breathes anymore) we weight &#8220;C&#8221; by a factor of 2 - we multiplied those all together and got a &#8220;High&#8221;.</p>
<p>So can you guys delay the product rollout by 9 months and give me a bunch more money that&#8217;s not in the budget so that I can get this thing down to a &#8220;Medium&#8221;, please?</p></blockquote>
<p>Again, I just don&#8217;t see the problem with Information Risk Management being that our businesses have no idea what the rewards of business might be.  Now maybe we need get a seat in that boardroom just to be able to talk about our &#8220;Mediums&#8221;, sure.  And maybe we&#8217;re infantile in our ability to describe our problem space.  But I cannot fathom that &#8220;<em>Risk Management Doesn&#8217;t Work</em>&#8221; because businesses haven&#8217;t been considering &#8220;reward&#8221;.</p>
<p><strong>WHY RISK MANAGEMENT MAY  NOT BE WORKIN&#8217; FOR YOU</strong></p>
<p>Two meta-categories of causation:</p>
<ul>
<li>No skills</li>
</ul>
<p>and/or</p>
<ul>
<li>No resources</li>
</ul>
<p>Any ancillary &#8220;cause&#8221; can be mapped to one of these categories.  You could have significant resources but crappy models, and have conversations like our imaginary CSO, above.  You could have really good models and people trained and motivated to use them, but scarce time &amp; money, so no conversation happens.</p>
<p>Now my question for you is - which does it make sense to acquire *first* to solve the &#8220;<em>Why Risk Management Doesn&#8217;t Work</em>&#8221; problems, skills or resources?</p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 13:15:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information risk management">information risk management</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/poor risk management">poor risk management</category>
      <category domain="http://securityratty.com/tag/information security risk">information security risk</category>
      <category domain="http://securityratty.com/tag/reduce risk">reduce risk</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/cool report">cool report</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=459">Why Risk Management Doesnt Work (?!)</source>
    </item>
    <item>
      <title><![CDATA[Air Force Will Fight Online, Without 'Cyber Command']]></title>
      <link>http://securityratty.com/article/8e3f2b1858422281bbe1c72a42d6efb0</link>
      <guid>http://securityratty.com/article/8e3f2b1858422281bbe1c72a42d6efb0</guid>
      <description><![CDATA[The Air Force is going ahead with plans to put together a force that will wage wars online. But it won't be a full-fledged Cyber Command as previously...]]></description>
      <content:encoded><![CDATA[The Air Force is going ahead with plans to put together a force that will wage wars online. But it won't be a full-fledged Cyber Command as previously advertised.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=1c9ee8172514f72305a38a81dba5d7e4" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=1c9ee8172514f72305a38a81dba5d7e4" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=GHEAM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=GHEAM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=S7pRm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=S7pRm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=1UzLm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=1UzLm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=diBRM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=diBRM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=eDhTM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=eDhTM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=UahTm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=UahTm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Yfprm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Yfprm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=piZeM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=piZeM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/414935546" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/414935549" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 11:55:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/air force">air force</category>
      <category domain="http://securityratty.com/tag/force">force</category>
      <category domain="http://securityratty.com/tag/cyber command">cyber command</category>
      <category domain="http://securityratty.com/tag/wage wars online">wage wars online</category>
      <category domain="http://securityratty.com/tag/ahead">ahead</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/previously">previously</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/414935549/air-force-will.html">Air Force Will Fight Online, Without 'Cyber Command'</source>
    </item>
    <item>
      <title><![CDATA[Knock, Knock, Knockin' on Carder's Door]]></title>
      <link>http://securityratty.com/article/91e9037a424229d43cc68b82d0bb0d52</link>
      <guid>http://securityratty.com/article/91e9037a424229d43cc68b82d0bb0d52</guid>
      <description><![CDATA[This video of Cha0's bust earlier this month in Turkey , is a perfect example of what happens when someone starts over-performing in the field of carding




Try counting the desktops, and notice the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQj7Y15eeI/AAAAAAAACOg/OlrVz7y_1FE/s1600-h/ATM_skimmers_Cha0_Turkey.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQj7Y15eeI/AAAAAAAACOg/J_laYTr2Fq0/s200-R/ATM_skimmers_Cha0_Turkey.bmp" /></a>This <a href="http://www.haber7.com/video-galeri.php?vID=282">video of Cha0's bust earlier this month in Turkey</a>, is a perfect example of what happens when someone starts <a href="http://blog.wired.com/27bstroke6/2008/09/turkish-police.html">over-performing in the field of carding</a>.<br />
<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOQmPSdX5kI/AAAAAAAACOo/4ofM99nwamg/s1600-h/ATM_skimmers_Cha0_Turkey_pos.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOQmPSdX5kI/AAAAAAAACOo/O8s4fMefCSw/s200-R/ATM_skimmers_Cha0_Turkey_pos.bmp" /></a>Try counting the desktops, and notice the "full package" a carder can dream of - the box full of ATM skimmers, the holograms, the plastic cards machine, the suitcase with the POS (point of sale) terminals, the house and swimming pool, and, of course, the hard cash.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fQP5M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fQP5M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yoAlM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yoAlM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BlbTm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BlbTm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WFXMm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WFXMm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9nsKM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9nsKM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=P8GhM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=P8GhM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=abtlm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=abtlm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409379971" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 06:59:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/plastic cards machine">plastic cards machine</category>
      <category domain="http://securityratty.com/tag/carder">carder</category>
      <category domain="http://securityratty.com/tag/atm skimmers">atm skimmers</category>
      <category domain="http://securityratty.com/tag/hard cash">hard cash</category>
      <category domain="http://securityratty.com/tag/bust">bust</category>
      <category domain="http://securityratty.com/tag/sale">sale</category>
      <category domain="http://securityratty.com/tag/turkey">turkey</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/cha0">cha0</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409379971/knock-knock-knockin-on-carders-door.html">Knock, Knock, Knockin' on Carder's Door</source>
    </item>
    <item>
      <title><![CDATA[Copycat Web Malware Exploitation Kit Comes with Disclaimer]]></title>
      <link>http://securityratty.com/article/f53d9a8c84706cb980c1a5fe00e3e2f8</link>
      <guid>http://securityratty.com/article/f53d9a8c84706cb980c1a5fe00e3e2f8</guid>
      <description><![CDATA[Such disclaimers make you wonder what's the point of including a notice forwarding the responsibility for the upcoming cybercrime activities to the buyer, when the seller himself is offering daily...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOPmoVr-3KI/AAAAAAAACNQ/L7Fxlk4j_Gg/s1600-h/1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOPmoVr-3KI/AAAAAAAACNQ/IZ-phgyZJpY/s200-R/1.JPG" /></a>Such disclaimers make you wonder what's the point of including a notice forwarding the responsibility for the upcoming cybercrime activities to the buyer, when the seller himself is offering daily updates with undetected bots, and is promising to include new exploits within the kit.<br />
<br />
For the time being, this recently released copycat web exploitation malware kit, includes two PDF exploits, IE snapshot, and naturally MDAC, with a DIY builder for the binary. Here's the disclaimer, greatly reminding us of <a href="http://www.theregister.co.uk/2008/04/28/malware_copyright_notice/">Zeus's copyright notice</a> : <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQEl4WjyJI/AAAAAAAACNw/bup8hAFSOIA/s1600-h/3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQEl4WjyJI/AAAAAAAACNw/J0Uxe3C2IPI/s200-R/3.JPG" /></a>"<i>Purchasing this product, you hold the full responsibility for its usage and for consequences which may have been caused by incorrect usage or the usage with some evil intent or violation of the usage rules. The author excludes the placement of the scripts somewhere on the Internet, you can only place them on localhost, virtual machine or on a test botnet (minibotnet). WARNING! The usage of this product with evil intent leads to the criminal responsibility!</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOQE_GioZeI/AAAAAAAACN4/-TgImabe7zw/s1600-h/5.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOQE_GioZeI/AAAAAAAACN4/TC5-5hqbJ0I/s200-R/5.JPG" /></a>What happens when the buyer tries to resell the kit? - "<i>If you try to resell, decode, remove the boundaries, you will lose all the  support, updates and guarantees.</i>" which is surreal considering that the kit is open source one, and just like we've seen with a recent modification of Zeus if it were to include unique features -- which it doesn't -- others would build upon its foundations.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SOQFHcVCuhI/AAAAAAAACOA/gyW259ojaII/s1600-h/7.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SOQFHcVCuhI/AAAAAAAACOA/XvJB5TF7UCE/s200-R/7.JPG" /></a><br />
Going through the exploitation statistics of a sample campaign, you can clearly see that out of the 859 unique visits 250 got exploited with outdated and already patched vulnerabilities. Therefore, diversifying the exploits set would have increased the number of exploited hosts.<br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQFq13TnPI/AAAAAAAACOI/Ubkw74c4Wn0/s1600-h/9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQFq13TnPI/AAAAAAAACOI/nvO4FBQ3s3k/s200-R/9.JPG" /></a>With IE6 visitors exploited at 46% as a whole, it would be hard not to notice that just like Stormy Wormy's historical persistence of using outdated vulnerabilities, a great majority of today's botnets have been aggregated using old exploits.<br />
<br />
Trying to enforce the intellectual property of a malware kit means you're claiming ownership, and therefore the disclaimer becomes irrelevant.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7NZmM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7NZmM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DOidM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DOidM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7V8tm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7V8tm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wAlLm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wAlLm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6EqeM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6EqeM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZZ3BM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZZ3BM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0wv6m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0wv6m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409055131" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 22:58:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/usage rules">usage rules</category>
      <category domain="http://securityratty.com/tag/usage">usage</category>
      <category domain="http://securityratty.com/tag/exploits">exploits</category>
      <category domain="http://securityratty.com/tag/pdf exploits">pdf exploits</category>
      <category domain="http://securityratty.com/tag/incorrect usage">incorrect usage</category>
      <category domain="http://securityratty.com/tag/evil intent">evil intent</category>
      <category domain="http://securityratty.com/tag/evil intent leads">evil intent leads</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409055131/copycat-web-malware-exploitation-kit.html">Copycat Web Malware Exploitation Kit Comes with Disclaimer</source>
    </item>
    <item>
      <title><![CDATA[FileAdvisor: software file search engine]]></title>
      <link>http://securityratty.com/article/856af459093a6fe1d8cb8a725ef66103</link>
      <guid>http://securityratty.com/article/856af459093a6fe1d8cb8a725ef66103</guid>
      <description><![CDATA[Troy Larson sent me a heads up on Bit9's FileAdvisor , a service they describe as &quot;a comprehensive catalog of executables, drivers, and patches found in commercial Windows applications and software...]]></description>
      <content:encoded><![CDATA[<a href="http://www.itsec.e-symposium.com/speakers/troy-larson.php" target="_blank">Troy Larson</a> sent me a heads up on Bit9's <a href="http://fileadvisor.bit9.com/services/search.aspx" target="_blank">FileAdvisor</a>, a service they describe as "a comprehensive catalog of executables, drivers, and patches found in commercial Windows applications and software packages. Malware and other unauthorized software that affects Windows computers is also indexed." <br />I immediately checked the FileAdvisor db for malware results as well non-Windows binaries and was pleasantly surprised with immediate and comprehensive results. You do have to register, but I was further impressed with the fact that they offered the option for a short or full <a href="http://fileadvisor.bit9.com/services/register.aspx" target="_blank">registration</a>.<br />This appears to be worthy of a bookmark in your incident handler/malware researcher/forensic investigator toolkit.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/10/fileadvisor-software-file-search-engine.html&title=FileAdvisor:%20software%20file%20search%20engine " title="FileAdvisor: software file search engine ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/10/fileadvisor-software-file-search-engine.html" title="FileAdvisor: software file search engine ">digg</a>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 10:34:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/fileadvisor">fileadvisor</category>
      <category domain="http://securityratty.com/tag/commercial windows applications">commercial windows applications</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware results">malware results</category>
      <category domain="http://securityratty.com/tag/software packages">software packages</category>
      <category domain="http://securityratty.com/tag/affects windows computers">affects windows computers</category>
      <category domain="http://securityratty.com/tag/comprehensive results">comprehensive results</category>
      <category domain="http://securityratty.com/tag/incident handlermalware">incident handlermalware</category>
      <source url="http://holisticinfosec.blogspot.com/2008/10/fileadvisor-software-file-search-engine.html">FileAdvisor: software file search engine</source>
    </item>
    <item>
      <title><![CDATA[Security + Logging + Virtualization Podcast]]></title>
      <link>http://securityratty.com/article/3ef5ee6b581fa908366fdbdec8f17d6a</link>
      <guid>http://securityratty.com/article/3ef5ee6b581fa908366fdbdec8f17d6a</guid>
      <description><![CDATA[Here is a fun podcast a bunch of us (yes, including Chris , of course! ) did on security, logging and virtualization ( audio , full transcript

It is actually a fun read / listen , if you are into...]]></description>
      <content:encoded><![CDATA[<a href="http://briefingsdirect.blogspot.com/2008/09/virtualization-use-requires-improved.html">Here</a> is a fun podcast a bunch of us (yes, including <a href="http://rationalsecurity.typepad.com/blog/">Chris</a>, <span style="font-style: italic;">of course!</span>)  did on security, logging and virtualization (<a href="http://media.libsyn.com/media/interarbor/BriefingsDirect_LogLogic_Podcast_2.mp3">audio</a>,<a href="http://briefingsdirect.blogspot.com/2008/09/virtualization-use-requires-improved.html"> full transcript</a>).<br /><br />It is actually a fun <a href="http://briefingsdirect.blogspot.com/2008/09/virtualization-use-requires-improved.html">read </a>/ <a href="http://media.libsyn.com/media/interarbor/BriefingsDirect_LogLogic_Podcast_2.mp3">listen</a>, if you are into either/all of these three :-)<br /><br />Here is the brief blurb on that from the<a href="http://briefingsdirect.blogspot.com"> podcaster site</a>: "To help learn about new ways that systems log tools and analysis are aiding the ramp-up to virtualization use, I [<a href="http://briefingsdirectblog.blogspot.com/2008/09/improved-insights-and-analysis-from-it.html">Dana Gardner</a>] recently spoke with <a href="http://www.linkedin.com/in/charu">Charu Chaubal</a>, senior architect for technical marketing, at <a href="http://www.vmware.com/">VMware</a>; <a href="http://www.linkedin.com/in/choff">Chris Hoff</a>, chief security architect at <a href="http://www.unisys.com/">Unisys</a>, and <a href="http://www.chuvakin.org/">Dr. Anton Chuvakin</a>, chief logging evangelist and a <a href="http://en.wikipedia.org/wiki/Anton_Chuvakin">security expert</a> at <a href="http://www.loglogic.com/">LogLogic</a>."<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=n88xM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=n88xM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=OlK9M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=OlK9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=tCDWM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=tCDWM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/408598332" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 09:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security expert">security expert</category>
      <category domain="http://securityratty.com/tag/chief security architect">chief security architect</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/chief">chief</category>
      <category domain="http://securityratty.com/tag/anton chuvakin">anton chuvakin</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/chris hoff">chris hoff</category>
      <category domain="http://securityratty.com/tag/chuvakin">chuvakin</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/408598332/security-logging-virtualization-podcast.html">Security + Logging + Virtualization Podcast</source>
    </item>
    <item>
      <title><![CDATA[Be careful what hand you play, and when you play it]]></title>
      <link>http://securityratty.com/article/3f792de863bd77b5be976522d12fce8f</link>
      <guid>http://securityratty.com/article/3f792de863bd77b5be976522d12fce8f</guid>
      <description><![CDATA[Yet another analogy from the credit crunch shows us security folks that even if we changed jobs we probably wouldn't be able to escape our frustrations. The executive branch is currently trying to win...]]></description>
      <content:encoded><![CDATA[Yet another analogy from the credit crunch shows us security folks that even if we changed jobs we probably wouldn't be able to escape our frustrations. 

The executive branch is currently trying to win over Congress and convince them to hand over a large sum of money, or else something really bad is going to happen. This is a situation I'm sure many security folks have found themselves in, albeit under less extreme circumstances.

The people with the check books seldom know anything about what you're doing. Congress is full of politicians, not economists or experts on the banking system. They need to rely on their gut feeling to do the right thing. Same thing with your management, <B>so it's up to you to guide them towards the right decision -- in their language</b>...
]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security folks">security folks</category>
      <category domain="http://securityratty.com/tag/check books seldom">check books seldom</category>
      <category domain="http://securityratty.com/tag/congress">congress</category>
      <category domain="http://securityratty.com/tag/extreme circumstances">extreme circumstances</category>
      <category domain="http://securityratty.com/tag/credit crunch">credit crunch</category>
      <category domain="http://securityratty.com/tag/executive branch">executive branch</category>
      <category domain="http://securityratty.com/tag/hand">hand</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/analogy">analogy</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1358">Be careful what hand you play, and when you play it</source>
    </item>
    <item>
      <title><![CDATA[Interop NY 2008: Wrap-up]]></title>
      <link>http://securityratty.com/article/1f9f6e5f6c1183d8706458aa161f8afd</link>
      <guid>http://securityratty.com/article/1f9f6e5f6c1183d8706458aa161f8afd</guid>
      <description><![CDATA[This year was a strange year at Interop NY. While the financial industry in NY was crumbling around us, things were strangely normal at Interop . Despite entire departments being laid-off at Lehman...]]></description>
      <content:encoded><![CDATA[<p>This year was a strange year at Interop NY.  While the financial industry in NY was crumbling around us, things were <a href="http://www.networkworld.com/community/node/33059" target="_blank">strangely normal at Interop</a>.  Despite entire departments being laid-off at Lehman and elsewhere, while the show was going on, the show itself seemed mostly unaffected.  We even saw this with our annual survey - in 2007 18% of respondents were from the financial services industry, this year the sector respresented 19%.</p>
<p>Interop NY 2008 was up considerably in size from the show in 2007.  <a href="http://blog.sciencelogic.com/interview-with-lenny-heymann-interop-general-manager/09/2008" target="_blank">According to Lenny Heymann</a>, the GM of Interop, this is a trend that they expect to continue.  My personal experience was that the size of the vendors was also up this year.  I think there were so few startups that &#8220;Startup City&#8221; was pulled from the show completely.  In any case, the show floor was full and there was plenty of attendee traffic to go around.</p>
<p>Definitely helping out from a traffic and draw perspective was the addition of the Web 2.0 Expo - Interop was co-located with both Mobile Business Expo and the Web 2.0 show. It seems like that buzzword still hasn&#8217;t lost most of its luster.</p>
<p>From the InteropNet perspective, the main feeling was one of being rushed.  With the show only lasting two days, and the InteropNet team only having a couple of days of ramp up time, everything was compressed into a much shorter period than in Las Vegas.  While this would normally be a challenge, it&#8217;s an even bigger challenge at the Javits where the InteropNet team was allowed to do almost nothing ourselves because of union rules.  You&#8217;d be surprised how frustrated you can make a network guy who&#8217;s told that he has to stand there and watch the electrician plug things in, rather than just doing it himself.  The only thing faster than the InteropNet team getting the Interop NY network up, was my pedicab ride to the InteropNet Booze Cruise.<br />
<object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/6h8JECK6naw&#038;hl=en&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/6h8JECK6naw&#038;hl=en&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"></embed></object></p>
<p>In any case, everything came off without a hitch, and EM7 performed flawlessly catching a couple of power outages that last day and alerting everyone before the batteries on the UPSes had a chance to run down.</p>
<p>Over the next couple of weeks I&#8217;ll analyze the data from the show to see how many tickets were handled, amount of bandwidth consumed, etc and we&#8217;ll do a comparison to Interop Las Vegas.</p>
<p>We&#8217;re (both ScienceLogic and me personally) looking forward to Interop 2009.</p>
]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 16:48:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/las vegas">las vegas</category>
      <category domain="http://securityratty.com/tag/interop las vegas">interop las vegas</category>
      <category domain="http://securityratty.com/tag/interopnet team">interopnet team</category>
      <category domain="http://securityratty.com/tag/mobile business expo">mobile business expo</category>
      <category domain="http://securityratty.com/tag/expo">expo</category>
      <category domain="http://securityratty.com/tag/bigger challenge">bigger challenge</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/attendee traffic">attendee traffic</category>
      <source url="http://blog.sciencelogic.com/interop-ny-2008-wrap-up/09/2008">Interop NY 2008: Wrap-up</source>
    </item>
    <item>
      <title><![CDATA[SDL Sessions at BlueHat]]></title>
      <link>http://securityratty.com/article/bddb4f5b0c8437f73140811dafbc6401</link>
      <guid>http://securityratty.com/article/bddb4f5b0c8437f73140811dafbc6401</guid>
      <description><![CDATA[Bryan here. Last January, I wrote a post on this blog bemoaning the difficulty of making security interesting and sexy to developers. Applied research conferences generally place a much greater...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Bryan here. Last January, I wrote a post on this blog bemoaning the difficulty of making security interesting and “</FONT><A href="http://blogs.msdn.com/sdl/archive/2008/01/29/sexy-development-lifecycle.aspx"><FONT face=Calibri color=#0000ff size=3>sexy</FONT></A><FONT face=Calibri size=3>” to developers. Applied research conferences generally place a much greater emphasis on revealing new vulnerabilities and new attack techniques, and much less emphasis on educating people on how to actually fix those vulnerabilities. I was at </FONT><A href="http://www.rsaconference.com/"><FONT face=Calibri color=#0000ff size=3>RSA Conference</FONT></A><FONT size=3><FONT face=Calibri> last April, and I attended a session by a very well-regarded, high-profile security researcher. He gave an eloquent and educational presentation on the dangers of a significant new attack vector, but all the prescriptive guidance he gave for dealing with the threat amounted to something like, “If you’re worried about this kind of thing, talk to your browser manufacturer.” No offense to this presenter, but if I’m going to listen to 70 minutes of discussion of a dangerous threat, I want to leave the room with a clear understanding of what I can do to solve the problem! It’s not enough just to know that the problem exists.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>So, in conjunction with the </FONT><A href="http://blogs.technet.com/bluehat/"><FONT face=Calibri size=3>BlueHat</FONT></A><FONT size=3><FONT face=Calibri> team, I am pleased to announce that the SDL team will be organizing the sessions for the second day of the fall BlueHat conference. The BlueHat SDL sessions will be laser-focused on not just describing vulnerabilities but also solving them. Every attendee should leave every presentation with a clear idea of exactly what he or she needs to do to protect themselves from the threat that was discussed during the session.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>The sessions will begin, appropriately, with the topic of secure design. Danny Dhillon of </FONT><A href="http://www.emc.com/"><FONT face=Calibri size=3>EMC</FONT></A><FONT face=Calibri size=3> and the SDL team’s own Adam Shostack will each present their organization’s approach to threat modeling. As a bonus, Adam will also be demonstrating the new </FONT><A href="http://download.microsoft.com/download/1/5/0/150636A9-9EA8-4D00-9E6B-2723F4C188B4/Microsoft%20SDL%20Threat%20Modeling%20Tool%203.0.pdf"><FONT face=Calibri size=3>SDL Threat Modeling tool</FONT></A><FONT face=Calibri size=3> that you might have heard about </FONT><A href="http://blogs.msdn.com/sdl/archive/2008/09/16/sdl-press-tour-announcements.aspx"><FONT face=Calibri size=3>last week</FONT></A><FONT size=3><FONT face=Calibri>. <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Next up is Matt Miller, a recent and very welcome </FONT><A href="http://blogs.msdn.com/michael_howard/archive/2008/08/18/matt-miller-joins-the-security-science-team.aspx"><FONT face=Calibri size=3>addition</FONT></A><FONT face=Calibri size=3> to the Microsoft Security Science team. Matt has a fantastic presentation on the evolution of buffer overflow attacks and on the corresponding development of overflow mitigations. From there we will switch gears to look at some managed code implementation issues: </FONT><A href="http://www.isecpartners.com/"><FONT face=Calibri size=3>iSEC Partners</FONT></A><FONT size=3><FONT face=Calibri>’ Scott Stender and Alex Vidergar will demonstrate coding techniques to mitigate elusive concurrency vulnerabilities in web applications.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>At this point we will have covered the Design and Implementation phases of the SDL; where better to go from here than Verification? One of the most important activities in the Verification phase is fuzzing, and we have a trio of security experts from the Microsoft Security Science team to talk about it. Jason Shirk, Lars Opstad, and Dave Weinstein will answer three of the most common fuzzing questions: How should I fuzz? When have I fuzzed enough? And what do I do now that I’ve fuzzed? <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Finally, we will wrap up the Verification phase talks with a return appearance to BlueHat by </FONT><A href="http://www.stachliu.com/"><FONT face=Calibri size=3>Stach &amp; Liu</FONT></A><FONT size=3><FONT face=Calibri>’s Vinnie Liu. Vinnie will compare different approaches to security verification – static code analysis, blackbox analysis, and manual code review – and make recommendations as to when each approach is best used.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Even if you can’t make it in to BlueHat in person, you can still watch the sessions via streaming media on </FONT><A href="http://technet.microsoft.com/"><FONT face=Calibri color=#0000ff size=3>TechNet</FONT></A><FONT face=Calibri size=3>. Additionally, webcast interviews with the speakers – condensed “Cliff’s Notes” versions of their full presentations – will be posted on </FONT><A href="http://channel9.msdn.com/Search/Default.aspx?Term=bluehat"><FONT face=Calibri color=#0000ff size=3>Channel 9</FONT></A><FONT size=3><FONT face=Calibri>. And we’ll be continuing the BlueHat tradition of inviting speakers and other industry notables to guest blog about their topics and the latest security trends. More information on all of these resources will be posted here when it becomes available.<o:p></o:p></FONT></FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8965212" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 12:05:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <category domain="http://securityratty.com/tag/bluehat">bluehat</category>
      <category domain="http://securityratty.com/tag/sessions">sessions</category>
      <category domain="http://securityratty.com/tag/sdl team">sdl team</category>
      <category domain="http://securityratty.com/tag/sdl threat">sdl threat</category>
      <category domain="http://securityratty.com/tag/bluehat sdl sessions">bluehat sdl sessions</category>
      <category domain="http://securityratty.com/tag/bluehat conference">bluehat conference</category>
      <category domain="http://securityratty.com/tag/verification phase talks">verification phase talks</category>
      <category domain="http://securityratty.com/tag/verification phase">verification phase</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/09/25/sdl-sessions-at-bluehat.aspx">SDL Sessions at BlueHat</source>
    </item>
  </channel>
</rss>
