<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: hype]]></title>
    <link>http://securityratty.com/tag/hype</link>
    <description></description>
    <pubDate>Tue, 05 Aug 2008 04:46:27 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ScienceLogic Makes it Onto the Inc 500 List of Fastest-Growing Private Companies in US]]></title>
      <link>http://securityratty.com/article/13adee3492b3b68c7eae4ade342986fb</link>
      <guid>http://securityratty.com/article/13adee3492b3b68c7eae4ade342986fb</guid>
      <description><![CDATA[Just the facts maam
Rank on Inc. 500: #350
Three-year revenue growth: 840
Rank on Top 100 DC-area companies: #27
DC area ranked #1 for most companies on the Inc. 500 list; #2 for most companies on the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/08/inc500-logo.jpg"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="203" alt="inc500_logo" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/inc500-logo-thumb.jpg" width="244" border="0"></a> </p>
<p>Just <a href="link http://www.inc.com/inc5000/2008/articles/introduction.html" target="_blank">the facts</a> ma’am:</p>
<ul>
<li><a href="link to http://www.inc.com/inc5000/2008/company-profile.html?id=200803500" target="_blank">Rank on Inc. 500: #350</a>
<li>Three-year revenue growth: 840%
<li><a href="http://www.inc.com/inc5000/2008/lists/washington-arlington-alexandria-dc-va-md-wv.html?o=0&amp;c=200803500" target="_blank">Rank on Top 100 DC-area companies: #27</a>
<li>DC area ranked #1 for most companies on the Inc. 500 list; #2 for most companies on the Inc. 5000 list (behind NYC)
<li>2<sup>nd</sup> fastest-growing software company in the DC area (Note: we got categorized as IT Services but of course we really fall under “Software”. They never seem to have a “Technology Appliances” category…)</li>
</ul>
<p><a href="http://www.sciencelogic.com/pressrelease_20080820.htm" target="_blank">Read the full press release here</a>.
<p>We’re loving it because of the awards we’ve applied for over the last few years and haven’t won. (Or maybe only I care about this since I had to fill out all those applications. Hmmm, I’m sensing a pattern here…) But in this case, it’s all about the numbers.
<p>We love this part of our story because it comes down to customers actually believing in you and your product enough to plunk down the money – and keep coming back for more once you prove yourself the first time. It’s not about the hype or the latest flash in the pan or “sponsorship” or how much money some VC gives you. It comes down to you, your product and your happy customers.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:45:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/dc-area companies">dc-area companies</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/software company">software company</category>
      <category domain="http://securityratty.com/tag/happy customers">happy customers</category>
      <category domain="http://securityratty.com/tag/three-year revenue growth">three-year revenue growth</category>
      <category domain="http://securityratty.com/tag/technology appliances category">technology appliances category</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <source url="http://blog.sciencelogic.com/sciencelogic-makes-it-onto-the-inc-500-list-of-fastest-growing-private-companies-in-us/08/2008">ScienceLogic Makes it Onto the Inc 500 List of Fastest-Growing Private Companies in US</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-08-15 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/c3237e147aa048495488e182bb006937</link>
      <guid>http://securityratty.com/article/c3237e147aa048495488e182bb006937</guid>
      <description><![CDATA[The Daily Incite - August 15, 2008 | Security Incite: Ding dong, SIM is dead? Yeah, not so much... My opinion is that the first generation of SIM didn't do what it needed to. It was too hard, too...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-august-15-2008">The Daily Incite - August 15, 2008 | Security Incite:    Ding dong, SIM is dead? Yeah, not so much...</a><br/>
My opinion is that the first generation of SIM didn&#039;t do what it needed to. It was too hard, too expensive, took too long to see value. There are lots of folks that are working on those issues. Of course, we still aren&#039;t there yet, but the industry is making progress. And the biggest reason I don&#039;t see the idea of SIM dying (although the implementation will clearly change and evolve) is because CUSTOMERS NEED IT.</li>
<li><a href="http://securityincite.com/TDI-2008-08-15#TBP3">Lets start the hype engine for 2009</a><br/>
For the 5th year in a row, I suspect 2009 will be very much like 2008. We are still bailing out the leaky boat with a small cup. Sure, there are new and different attack vectors. And things like &quot;the cloud&quot; are causing us to revisit our general security architectures. And compliance certainly isn&#039;t going away as a key issue for security folks everywhere. BUT, maybe in 2009 we can start actually implementing the stuff we bought in 2006 and making sure we are more effectively doing the blocking and tackling that we all know can use some improvement.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/366256321" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sim">sim</category>
      <category domain="http://securityratty.com/tag/folks">folks</category>
      <category domain="http://securityratty.com/tag/security folks">security folks</category>
      <category domain="http://securityratty.com/tag/attack vectors">attack vectors</category>
      <category domain="http://securityratty.com/tag/key issue">key issue</category>
      <category domain="http://securityratty.com/tag/security architectures">security architectures</category>
      <category domain="http://securityratty.com/tag/start">start</category>
      <category domain="http://securityratty.com/tag/security incite">security incite</category>
      <category domain="http://securityratty.com/tag/leaky boat">leaky boat</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/366256321/anton18">Links for 2008-08-15 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.15.08]]></title>
      <link>http://securityratty.com/article/803e2f6db1563e98882d0a71faf66398</link>
      <guid>http://securityratty.com/article/803e2f6db1563e98882d0a71faf66398</guid>
      <description><![CDATA[Cloud Computing will also cure the common cold! Not really. But amidst all the hype and overly-used marketing speak its hard to tell the difference. Researchers from the University of Michigan...]]></description>
      <content:encoded><![CDATA[<p>Cloud Computing will also cure the common cold! Not really. But amidst all the hype and overly-used marketing speak it&#8217;s hard to tell the difference. Researchers from the University of Michigan announced CloudAV, a network service using the <a href="http://www.infoworld.com/article/08/08/08/Researchers_look_to_cloud_computing_to_fight_malware_1.html?source=NLC-TB&amp;cgd=2008-08-08">&#8220;cloud-computing&#8221; concept to fight malware</a>. Please stop the insanity! I&#8217;m just waiting for someone to put &#8220;my&#8221; and &#8220;cloud computing&#8221; together&#8230;</p>
<p>Here&#8217;s an interesting post on High Earth Orbit about the usage and promotion of <a href="http://highearthorbit.com/open-source-in-defense/">open source software for defense</a> contracts. As a developer of open source tools, Andrew Turner of course brings up some &#8220;pros&#8221; for the government to push open source, but it&#8217;s the &#8220;cons&#8221; that are really interesting. A big &#8220;con&#8221; &#8211; the US government having something called &#8220;<a href="http://tech.slashdot.org/article.pl?sid=08/08/04/2253246">sovereign immunity</a>&#8221; which apparently means something like it can&#8217;t be sued unless it consents to be sued. Hunh &#8211; the Republic of ScienceLogic-Land? Closing the loop here, a federal appeals court just boosted open-source software licenses by saying that any infringements can now get more <a href="http://weblog.infoworld.com/openresource/archives/2008/08/court_rules_tha.html?source=rss">severe remedies under copyright law</a> (instead of contract law); here&#8217;s the case, <a href="http://blawgletter.typepad.com/bbarnett/2008/08/can-you-copyrig.html">Jacobsen v Katzer</a>. But apparently not if it&#8217;s the <a href="http://arstechnica.com/news.ars/post/20080804-air-force-cracks-software-carpet-bombs-dmca.html">US government</a>?? Who knows more?</p>
<p>Does Linus Torvalds hate everyone except for developers? You have to check out this article on an email exchange he had with Network World this week, talking about how fed up he is with the &#8220;<a href="http://www.infoworld.com/article/08/08/14/Torvalds_Fed_up_with_the_security_circus_1.html">security circus</a>&#8221;. Over the course of the exchange and some other comments from last month, he manages to blast security folk, OpenBSD (on security) in particular, vendors and PR people (of course). In the midst of the barrage of colorful language, it&#8217;s difficult to really get his point &#8211; which if you can dig it out, ends up being surprisingly sensible.</p>
<p>Sharon Taylor, Chief Architect of ITIL V3, recently wrote that with the release of the latest version of ITIL<a href="http://itmanagersinbox.com/345/itil-v3-and-business-service-management/">, BSM is now an &#8216;ITIL best practice</a>.&#8217; You say potato&#8230; &#8220;The distinction between IT and the business has blurred, and the language of IT has been replaced with the language of the business.&#8221;</p>
]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 16:04:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/source software">source software</category>
      <category domain="http://securityratty.com/tag/open-source software licenses">open-source software licenses</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/blast security folk">blast security folk</category>
      <category domain="http://securityratty.com/tag/colorful language">colorful language</category>
      <category domain="http://securityratty.com/tag/language">language</category>
      <category domain="http://securityratty.com/tag/itil">itil</category>
      <category domain="http://securityratty.com/tag/email exchange">email exchange</category>
      <source url="http://blog.sciencelogic.com/links-list-81508/08/2008">Links List 8.15.08</source>
    </item>
    <item>
      <title><![CDATA[Torvalds: Fed up with 'security circus']]></title>
      <link>http://securityratty.com/article/03794a644c4b8cfbbd3c072f5854c60e</link>
      <guid>http://securityratty.com/article/03794a644c4b8cfbbd3c072f5854c60e</guid>
      <description><![CDATA[The industry needs a middle ground between vulnerability secrecy and hype, says the creator of the Linux...]]></description>
      <content:encoded><![CDATA[The industry needs a middle ground between vulnerability secrecy and hype, says the creator of the Linux kernel.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=6XRpfr"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=6XRpfr" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/365747203" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/middle ground">middle ground</category>
      <category domain="http://securityratty.com/tag/linux kernel">linux kernel</category>
      <category domain="http://securityratty.com/tag/vulnerability secrecy">vulnerability secrecy</category>
      <category domain="http://securityratty.com/tag/hype">hype</category>
      <category domain="http://securityratty.com/tag/creator">creator</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/365747203/article.do">Torvalds: Fed up with 'security circus'</source>
    </item>
    <item>
      <title><![CDATA[Fog of the Future: Cloud Computings on the Horizon]]></title>
      <link>http://securityratty.com/article/b0444080036cffd2f313acaf1bcf9b99</link>
      <guid>http://securityratty.com/article/b0444080036cffd2f313acaf1bcf9b99</guid>
      <description><![CDATA[If you trust the media and are looking to the future, you might be thinking a good deal about Cloud Computing according to ComputerWorld, this could be the next big movement
Ive heard the buzzwords...]]></description>
      <content:encoded><![CDATA[<p>If you trust the media and are looking to the future, you might be thinking a good deal about <a rel="nofollow" target="_blank" href="http://blogs.computerworld.com/forecast_calls_for_clouds_are_we_ready">Cloud Computing</a> &#8212; according to ComputerWorld, this could be the next big movement.</p>
<p>I&#8217;ve heard the buzzwords but wasn&#8217;t exactly sure what they meant&#8211;luckily, when there&#8217;s media hype, there are definitions, too. According to <a rel="nofollow" target="_blank" href="http://www.thestandard.com/news/2008/08/04/quicker-path-clouds">this article</a>, cloud computing is exemplified by Software as a Service &#8212; outsourced, hosted platforms and software that perform services for companies. </p>
<p>Another <a rel="nofollow" target="_blank" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9111689">article </a>puts it slightly differently:</p>
<blockquote><p>OK, let us look at what form of computing in being provided via the cloud. In this model, all IT applications and facilities (i.e. compute, storage and network) are provided as a service rather than dedicated infrastructure. This is intended to allow any user, independent of client platform, to access IT services without knowledge or concern of their location or form. Sound familiar &#8212; it&#8217;s a service-oriented architecture (SOA)!</p>
<p>In addition, cloud computing incorporates almost every computing manifestation within the IT world: distributed, grid, utility, on-demand, open-source, Web services, P2P, Web 2.0 and, last but not least, software as a service.</p>
<p>It also accommodates thin, thick and mobile clients and allows integration of corporate, commercial and service provider cloud-accessed resources. As an example, in this model, storage is a service resource that is accessed via the cloud, not a dedicated user resource.</p></blockquote>
<p>Honestly I read that last one first and found the definition a bit dense. It sounds like a summation of everything that makes up our Internet infrastructure already, so how is that different than the Internet itself? Well, cloud computing isn&#8217;t about what service or devices are being supported &#8212; it&#8217;s more about how it&#8217;s being provided&#8211; it is a location-independent style of computing. The first article calls it &#8220;platform as a service.&#8221;</p>
<p>Have you heard better definitions of what cloud computing is and does? Share them in the comments below. Thanks!</p>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 08:56:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service resource">service resource</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/perform services">perform services</category>
      <category domain="http://securityratty.com/tag/web services">web services</category>
      <category domain="http://securityratty.com/tag/internet infrastructure">internet infrastructure</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/365101308/">Fog of the Future: Cloud Computings on the Horizon</source>
    </item>
    <item>
      <title><![CDATA[Who's Behind the Georgia Cyber Attacks?]]></title>
      <link>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</link>
      <guid>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</guid>
      <description><![CDATA[Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate most, it's lowering down the quality of the...]]></description>
      <content:encoded><![CDATA[<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/WYu9dc61zMQ/s1600-h/georgia_ddos8.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img height="51" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/1TazKONjKVw/s200-R/georgia_ddos8.JPG" style="border: 0pt none ;" width="200" /></a>Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate&nbsp; most, it's lowering down the quality of the discussion I hate the most. Even if you're excluding all the factual evidence (<a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a>), common sense must prevail.<br />
<br />
Sometimes, the degree of incompetence can in fact be pretty entertaining, and greatly explains why certain countries are lacking behind others with years in their inability to understand the rules of information warfare, or the basic premise of unrestricted warfare, that there are no rules on how to achieve your objectives.<br />
<br />
So who's behind the Georgia cyber attacks, encompassing of plain simple ping floods, web site defacements, to sustained DDoS attacks, which no matter the fact that Geogia has switched hosting location to the U.S remain ongoing? It's <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9112443&amp;taxonomyId=82&amp;intsrc=kc_top">Russia's self-mobilizing cyber militia, the product of a collectivist society</a> having the capacity to wage cyber wars and literally dictating the rhythm in this space. What is militia anyway : <br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/hxG1PZAcltY/s1600-h/information_warfare.1.gif" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/B0-V902UtRA/s200-R/information_warfare.1.gif" style="border: 0pt none ;" /></a>"<i>civilians trained as soldiers but not part of the regular army; the entire body of physically fit civilians eligible by law for military service; a military force composed of ordinary citizens to provide defense, emergency law enforcement, or paramilitary service, in times of emergency; without being paid a regular salary or committed to a fixed term of service; an army of trained civilians, which may be an official reserve army, called upon in time of need; the national police force of a country; the entire able-bodied population of a state; or a private force, not under government control; An army or paramilitary group comprised of citizens to serve in times of emergency</i>"<br />
<br />
Next to the "blame the Russian Business Network for the lack of large scale implementation of DNSSEC" mentality, certain news articles also try to wrongly imply that <a href="http://arstechnica.com/news.ars/post/20080813-georgian-attacks-might-not-be-russians-after-all.html%20">there's no Russian connection in these attacks</a>, and that the attacks are not "state-sponsored", making it look like that there should be a considerable amount of investment made into these attacks, and that the Russian government has the final word on whether or not its DDoS capabilities empowered citizens should launch any attacks or not. In reality, the only thing the Russian government was asking itself during these attacks was "why didn't they start the attacks earlier?!".<br />
<br />
Thankfully, there are some visionary folks out there understanding the situation. Last year, I asked the following question - <a href="http://www.imedialearn.com/imediapoll/poll.php?code=f1156c39d3c972139c62bc91c17e2c53">What is the most realistic scenario on what exactly happened in the recent DDoS attacks aimed at Estonia, from your point of view?</a> and some of the possible answers still fully apply in this situation :<br />
<br />
- It was a Russian government-sponsored hacktivism, or shall we say a government-tolerated one<br />
<br />
- Too much media hype over a sustained ICMP flood, given the publicly obtained statistics of the network traffic<br />
<br />
- Certain individuals of the collectivist Russian society, botnet masters for instance, were automatically recruited based on a nationalism sentiments so that they basically forwarded some of their bandwidth to key web servers<br />
<br />
- In order to generate more noise, DIY DoS tools were distributed to the masses so that no one would ever know who's really behind the attacks<br />
<br />
- Don't know who did it, but I can assure you my kid was playing !synflood at that time<br />
<br />
- Offended by the not so well coordinated removal of the Soviet statue, Russian oligarchs felt the need to send back a signal but naturally lacking any DDoS capabilities, basically outsourced the DDoS attacks<br />
<br />
- A foreign intelligence agency twisting the reality and engineering cyber warfare tensions did it, while taking advantage of the momentum and the overall public perception that noone else but the affected Russia could be behind the attacks<br />
<br />
- I hate scenario building, reminds me of my academic years, however, yours are pretty good which doesn't necessarily mean I actually care who did it, and pssst - it's not cyberwar, as in cyberwar you have two parties with virtual engagement points, in this case it was bandwidth domination by whoever did it over the other. A virtual shock and awe<br />
<br />
- I stopped following the news story by the time every reporter dubbed it the first cyber war, and started following it again when the word hacktivism started gaining popularity. So, hacktivists did it to virtually state their political preferences <br />
<br />
Departamental cyber warfare would never reach the flexibity state of people's information warfare where everyone is a cyber warrior given he's empowered with access to the right tools at a particular moment in time.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">People's Information Warfare Concept</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html">Combating Unrestricted Warfare</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/cyber-storm-ii-cyber-exercise.html">The Cyber Storm II Cyber Exercise</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">Chinese Hacktivists Waging People's Information Warfare Against CNN</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">The DDoS Attacks Against CNN.com</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/chinas-cyber-espionage-ambitions.html">China's Cyber Espionage Ambitions</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/north-koreas-cyber-warfare-unit-121.html">North Korea's Cyber Warfare Unit 121</a><br />
<div><a href="http://ddanchev.blogspot.com/2006/09/chinese-hackers-attacking-us.html">Chinese Hackers Attacking U.S Department of Defense Networks</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">Electronic Jihad v3.0 - What Cyber Jihad Isn't</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihads-targets-list.html">Electronic Jihad's Targets List</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/teaching-cyber-jihadists-how-to-hack.html">Teaching Cyber Jihadists How to Hack</a></div><div><a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">Empowering the Script Kiddies</a></div><div><a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html">OSINT Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html">Corporate Espionage Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html">Malware Infected Hosts as Stepping Stones</a></div><div><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a></div><div><a href="http://ddanchev.blogspot.com/2006/05/current-emerging-and-future-state-of.html">The Current, Emerging, and Future State of Hacktivism</a></div><div><a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">Internet PSYOPS - Psychological Operations</a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Tcck1K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Tcck1K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=X9Eb0K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=X9Eb0K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sJIFNk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sJIFNk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dY7m7k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dY7m7k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rRiYlK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rRiYlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XCeTAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XCeTAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IYEN6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IYEN6k" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/364867192" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 06:16:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/georgia cyber attacks">georgia cyber attacks</category>
      <category domain="http://securityratty.com/tag/warfare">warfare</category>
      <category domain="http://securityratty.com/tag/departamental cyber warfare">departamental cyber warfare</category>
      <category domain="http://securityratty.com/tag/cyber warfare tensions">cyber warfare tensions</category>
      <category domain="http://securityratty.com/tag/information warfare concept">information warfare concept</category>
      <category domain="http://securityratty.com/tag/information warfare">information warfare</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/russian oligarchs">russian oligarchs</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/364867192/whos-behind-georgia-cyber-attacks.html">Who's Behind the Georgia Cyber Attacks?</source>
    </item>
    <item>
      <title><![CDATA[The Risk of Anthrax]]></title>
      <link>http://securityratty.com/article/96c08b49a95008d4904855cb113bf42e</link>
      <guid>http://securityratty.com/article/96c08b49a95008d4904855cb113bf42e</guid>
      <description><![CDATA[Some reality to counter the hype. The Bottom Line
While there has been much consternation and alarm-raising over the potential for widespread proliferation of biological weapons and the possible use...]]></description>
      <content:encoded><![CDATA[<p>Some <a href="http://www.stratfor.com/weekly/busting_anthrax_myth">reality</a> to counter the hype.</p>

<blockquote><strong>The Bottom Line</strong>

<p>While there has been much consternation and alarm-raising over the potential for widespread proliferation of biological weapons and the possible use of such weapons on a massive scale, there are significant constraints on such designs. The current dearth of substantial biological weapons programs and arsenals by governments worldwide, and the even smaller number of cases in which systems were actually used, seems to belie -- or at least bring into question -- the intense concern about such programs.</p>

<p>While we would like to believe that countries such as the United States, the United Kingdom and Russia have halted their biological warfare programs for some noble ideological or humanitarian reason, we simply can’t. If biological weapons were in practice as effective as some would lead us to believe, these states would surely maintain stockpiles of them, just as they have maintained their nuclear weapons programs. Biological weapons programs were abandoned because they proved to be not as effective as advertised and because conventional munitions proved to provide more bang for the buck. </blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=cDpkeK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=cDpkeK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=nHCblK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=nHCblK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 10:29:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/weapons">weapons</category>
      <category domain="http://securityratty.com/tag/biological weapons programs">biological weapons programs</category>
      <category domain="http://securityratty.com/tag/programs">programs</category>
      <category domain="http://securityratty.com/tag/nuclear weapons programs">nuclear weapons programs</category>
      <category domain="http://securityratty.com/tag/biological weapons">biological weapons</category>
      <category domain="http://securityratty.com/tag/biological warfare programs">biological warfare programs</category>
      <category domain="http://securityratty.com/tag/surely maintain stockpiles">surely maintain stockpiles</category>
      <category domain="http://securityratty.com/tag/noble ideological">noble ideological</category>
      <category domain="http://securityratty.com/tag/humanitarian reason">humanitarian reason</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/the_risk_of_ant.html">The Risk of Anthrax</source>
    </item>
    <item>
      <title><![CDATA[Red Herring Fallacies: The Straw Man Argument]]></title>
      <link>http://securityratty.com/article/fd8b4d90abc87b580bec45cf10aafeeb</link>
      <guid>http://securityratty.com/article/fd8b4d90abc87b580bec45cf10aafeeb</guid>
      <description><![CDATA[According to our friend Wikipedia, the Straw Man argument is a red-herring fallacy where one party in a debate describes a position that, on the surface, resembles an opponents actual view but is...]]></description>
      <content:encoded><![CDATA[<p>According to our friend Wikipedia, the <a href="http://en.wikipedia.org/wiki/Straw_man" target="_blank">Straw Man argument</a> is a <a href="http://en.wikipedia.org/wiki/List_of_fallacies" target="_blank">red-herring fallacy</a> where one party in a debate describes a position that, on the surface, resembles an opponent&#8217;s actual view but is easier to refute.  Then, in counterpoint, the debating partner attributes an easily refutable position to the opponent (for example, deliberately overstating the opponent&#8217;s position). Wikipedia says:</p>
<blockquote><p><strong>1. Person A has position X.</strong></p>
<p><strong>2. Person B ignores X and instead presents position Y.</strong><br />
Y is a distorted version of X and can be set up in several ways, including:</p>
<ol>
<li>Presenting a misrepresentation of the opponent&#8217;s position and then refuting it, thus giving the appearance that the opponent&#8217;s actual position has been refuted.</li>
<li>Quoting an opponent&#8217;s words out of context — i.e., choosing quotations that are not representative of the opponent&#8217;s actual intentions.<a title="Quote mining" href="http://en.wikipedia.org/wiki/Quote_mining"> </a></li>
<li>Presenting someone who defends a position poorly as <em>the</em> defender and then refuting that person&#8217;s arguments, thus giving the appearance that <em>every</em> upholder of that position, and thus the position itself, has been defeated.</li>
<li>Inventing a fictitious persona with actions or beliefs that are criticized, such that the person represents a group of whom the speaker is critical.</li>
<li>Oversimplifying an opponent&#8217;s argument, then attacking the simplified version.</li>
</ol>
<p><strong>3. Person B attacks position Y.</strong></p>
<p><strong>4. Person B draws a conclusion that X is false/incorrect/flawed.</strong><br />
This sort of &#8220;reasoning&#8221; is fallacious because attacking a distorted version of a position simply does not constitute an attack on the position itself.</p></blockquote>
<p>For example, there has been some lively discussions recently around the notion that CEP is overhyped.</p>
<blockquote><p>Debate:      &#8220;CEP is Overhyped.&#8221;</p>
<p>Person A:   &#8220;CEP has been overhyped.&#8221;</p>
<p>Person B:     &#8220;CEP is just hype.&#8221;</p></blockquote>
<p>The point of the discussion by person A was to point out that CEP has been overhyped.  Person B has exaggerated this to a harder to defend position, &#8220;CEP is mere hype.&#8221; or &#8220;CEP is just hype.&#8221;</p>
<p>From the customer perspective, I don&#8217;t think that fallacies and red-herring arguments are good for CEP.   Believe me, if we could take an &#8220;out of the box&#8221; stream processing rules-engine and bolt it on to a network and insure a client it would detect complex fraud, or diagnose network faults accurately, and not put my entire professional reputation on the line, I would do it in a heartbeat.</p>
<p>It is not the speed of the an engine which makes a good CEP engine, it is the capability of the analytics to deliver high-quality, high-confidence complex event detection in real-time.</p>
]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 05:40:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/position">position</category>
      <category domain="http://securityratty.com/tag/defend position">defend position</category>
      <category domain="http://securityratty.com/tag/easily refutable position">easily refutable position</category>
      <category domain="http://securityratty.com/tag/opponents position">opponents position</category>
      <category domain="http://securityratty.com/tag/position simply">position simply</category>
      <category domain="http://securityratty.com/tag/position poorly">position poorly</category>
      <category domain="http://securityratty.com/tag/cep engine">cep engine</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/attacks position">attacks position</category>
      <source url="http://www.thecepblog.com/2008/08/07/red-herring-fallacies-the-straw-man-argument/">Red Herring Fallacies: The Straw Man Argument</source>
    </item>
    <item>
      <title><![CDATA[Beijing Olympics Lottery Phishers Verify Their Victims]]></title>
      <link>http://securityratty.com/article/28fe52f3c075902c10a853e9765300e5</link>
      <guid>http://securityratty.com/article/28fe52f3c075902c10a853e9765300e5</guid>
      <description><![CDATA[Websense has recently discovered another rogue Beijing Olympics website, this time for fake ticket lottery. The Web site uses the hostname that is a clear typo-squat to the official Olympic Games Web...]]></description>
      <content:encoded><![CDATA[Websense has recently discovered another rogue Beijing Olympics website, this time for fake ticket lottery.

The Web site uses the hostname that is a clear typo-squat to the official Olympic Games Web site at beijing2008.cn. Benefiting from the hype around the purchasing of tickets for the Games, the social engineering tactic behind this scam is to [...]]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 18:49:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake ticket lottery">fake ticket lottery</category>
      <category domain="http://securityratty.com/tag/olympics website">olympics website</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/websense">websense</category>
      <category domain="http://securityratty.com/tag/games">games</category>
      <category domain="http://securityratty.com/tag/hype">hype</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/hostname">hostname</category>
      <category domain="http://securityratty.com/tag/rogue">rogue</category>
      <source url="http://cyberinsecure.com/beijing-olympics-lottery-phishers-verify-their-victims/">Beijing Olympics Lottery Phishers Verify Their Victims</source>
    </item>
    <item>
      <title><![CDATA[On CEP as a Discipline]]></title>
      <link>http://securityratty.com/article/a9d1f2721b6335854aee35ef66fda256</link>
      <guid>http://securityratty.com/article/a9d1f2721b6335854aee35ef66fda256</guid>
      <description><![CDATA[In CEP as a Discipline , David Luckham wrote
Actually, it is fair to say that some of CEP can be found in other disciplines. Event processing has been going on in one form or another, for the past 50...]]></description>
      <content:encoded><![CDATA[<p>In  <a href="http://http://forum.complexevents.com/viewtopic.php?f=13&amp;t=121" target="_blank">CEP as a Discipline</a>,  David Luckham wrote: </p>
<blockquote><p><em>&#8220;Actually, it is fair to say that some of CEP can be found in other disciplines. Event processing has been going on in one form or another, for the past 50 years. Simulation, Networking, Active DBs, Middleware.</p>
<p>{ &#8230;. }</p>
<p>CEP has only just begun. The foundations are unexplored. Its an open field of research issues.&#8221;</em></p></blockquote>
<p>Actually, on slide 12 of this presentation from 2006 <a class="postlink" href="http://www.complexevents.com/slides/TIBCO_MARCH_2006.ppt">Processing Patterns for PredictiveBusiness</a>, we show that the foundations for complex event processing have been in place for many years and in many disciplines such as multisensor data fusion, control theory, sensor management, planning, correlation, estimation, tracking, information fusion, data fusion, data mining and more.</p>
<p>One obvious problem (or at least obvious to many of us) with the current group think marketing CEP is that many have ignored the established foundations for event processing and complex event processing that have been mature for many decades. It is not very efficient (nor good for customers) to pick a phrase, or concept, like &#8220;CEP&#8221; and ignore the relevant mulitiple disciplines that have been used to solve complex classes of distributed event processing problems for decades.</p>
<p>Therefore, &#8220;CEP has only begun&#8221; is only true for those who have &#8216;drank the CEP koolaid&#8221; and do not understand (yet) that they are &#8220;reinventing the event processing wheel&#8221; and ignoring (by accident or purposely, I have no idea of the motives) the prior-art and/or selectively picking the prior art or research associated with their company, byline, favorite researcher, CEO, etc. This is a fundamental issue (and constraint) with CEP, in my opinion. Complex event processing does not stand alone as an art or a science, nor should it, nor should it be based on single dimensional, or small groups of single dimensional, technologies.</p>
<p>If you want to see many of the foundations of CEP, you don&#8217;t need to go much further than slide 12 of this  presentation from 2006, <a class="postlink" href="http://www.complexevents.com/slides/TIBCO_MARCH_2006.ppt">Processing Patterns for PredictiveBusiness</a>.</p>
<p>Based on my observation, it reminds me of a small group of folks on a discovery mission where their ship lands on the shore of a distant land and they call this &#8220;new land&#8221; &#8212; &#8220;CEP&#8221; because they feel they have discovered a new land.  Nevermind the big cities that already exist or the many people already &#8220;in the fields&#8221; of their new land.  These &#8221;CEP explorers&#8221; are seemingly in some kind of modern day epic struggle to define themselves as &#8220;discoverers&#8221; or &#8220;founders&#8221; and they are coming up with new names of the lakes, rivers, streams and mountains that defined the landscape long before their ship arrived.</p>
<p>Note: It is encouraging to see folks slowly &#8220;catching up&#8221;&#8230;. maybe in a few years we will move CEP beyond the &#8220;not invented here&#8221; mind share that we see today.</p>
<p>Also note that, recently we saw a flurry of posts where many people rightly stated that &#8220;CEP was overhyped&#8221; - but then in rebuttal the EPTS community leaders came back with &#8220;Is CEP a mere hype?&#8221; or &#8220;Is CEP a hype?&#8221;. spinning the discussion to an extreme position that is wildly different than &#8220;CEP is Overhyped&#8221;.   </p>
]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 04:46:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/move cep">move cep</category>
      <category domain="http://securityratty.com/tag/land cep">land cep</category>
      <category domain="http://securityratty.com/tag/multisensor data fusion">multisensor data fusion</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/prior art">prior art</category>
      <category domain="http://securityratty.com/tag/art">art</category>
      <source url="http://www.thecepblog.com/2008/08/05/on-cep-as-a-discipline/">On CEP as a Discipline</source>
    </item>
  </channel>
</rss>
