<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: low]]></title>
    <link>http://securityratty.com/tag/low</link>
    <description></description>
    <pubDate>Wed, 24 Sep 2008 07:19:12 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Motivation Behind Adaptive Analytics and CEP]]></title>
      <link>http://securityratty.com/article/2a2a666360a23f6491ff25e41de8c981</link>
      <guid>http://securityratty.com/article/2a2a666360a23f6491ff25e41de8c981</guid>
      <description><![CDATA[This is a continuation of The Genesis of Complex Event Processing: Asymmetric Capabilities and CEP, Event Noise and Asymmetric Event Processing where I have been discussing the motivation behind CEP...]]></description>
      <content:encoded><![CDATA[<p>This is a continuation of <a title="The Genesis of Complex Event Processing: Asymmetric Capabilities" rel="bookmark" href="../2008/09/29/the-genesis-of-complex-event-processing-asymmetric-capabilites/">The Genesis of Complex Event Processing: Asymmetric Capabilities</a> and <a title="CEP, Event Noise and Asymmetric Event Processing" rel="bookmark" href="../2008/10/02/cep-event-noise-and-asymmetric-event-processing/">CEP, Event Noise and Asymmetric Event Processing</a> where I have been discussing the motivation behind CEP and adaptive analytics in cyberspace.</p>
<p>Around the same time that Professor Luckham and his team was working on CEP applications in network management and security management, I was leading efforts to build network and security management control centers for the <a href="http://www.af.mil">United States Air Force</a>.  In the beginning, dating back to 1994, my Internet-related work was for <a href="http://www.acc.af.mil/" target="_blank">Air Combat Command (ACC)</a>, working out of ACC headquarters at <a href="http://www.langley.af.mil/" target="_blank">Langley Air Force Base</a>.</p>
<p>In 1997, I lead a technical team that developed countermeasures against an actual distributed Internet-based attack on the Langley AFB SMTP email infrastructure.  This attack was documented in a technical paper, <a href="http://www.thecepblog.com/e-mail-bombs-and-countermeasures-cyber-attacks-on-availability-and-brand-integrity/" target="_blank"><em>E-Mail Bombs and Countermeasures: Cyber Attacks on Availability and Brand Integrity,</em> IEEE Network Magazine, Vol. 12, No. 2, pp. 10-17, March/April 1998</a>.  In addition, this attackand countermeasures I designed was featured in Popular Science Magazine in an 1998 article, <a href="http://www.thecepblog.com/warcom-by-frank-vizard/" target="_blank">War.Com</a> and other news channels.  I also published a number of related papers on this topic.</p>
<p>Our team used a rule-based approach for countermeasures against massive email bombs attacks on the Langley Air Force Base email infrastructure.   We called this rule-based system, <em>BombShelter.</em> and it was written in <a href="http://www.perl.org/" target="_blank">PERL</a>.  I developed both the original software architecture and the original working prototype for BombShelter (in two days) and then we turned the software over to our team who used the rule-based approach for daily attack countermeasures.</p>
<p>I watched for days, and then weeks, as my team designed rules, and the attackers wrote new attacks that circumvented the rules.  Some folks in the Pentagon used to say that I &#8220;lead the effort to fight the first war in cyberspace&#8221;.   It might have have been the first cyberwar, I am not sure, but it was certainly the first publicly documented cyberwar.  There is no doubt about this.</p>
<p>Without getting into all the historical footnotes and significance of this cyberwar that was fought with experts and rule-based systems, I would like to jump to an important conclusion.</p>
<blockquote><p><em>Rule-based systems are useful, but have limited functionality and scaleability in most complex event processing applications.</em></p></blockquote>
<p>Rule-based systems are human resource intensive because rule-based systems cannot learn and adapt on their own, humans learn and then write new rules.  This is how rule-based systems work.</p>
<p>This is the motivation behind why I spend a lot of time to search for new, more efficient and adaptive methods as alternatives to rule-based systems.   After extensive research, I published a series of papers on the future of intrusion detection in the Internet.  <a href="http://www.thecepblog.com/intrusion-detection-systems-and-multisensor-data-fusion/" target="_blank"><em>Intrusion Detection Systems &amp; Multisensor Data Fusion - Creating Cyberspace Situational Awareness</em></a> <a class="external autonumber" title="http://www.silkroad-asia.com/papers/pdf/acm-p99-bass.pdf" rel="nofollow" href="http://www.silkroad-asia.com/papers/pdf/acm-p99-bass.pdf">[1]</a>, helped lead an evolution in Internet security, particularly in the area of network-based intrusion detection systems (IDS).</p>
<p>In my published research work, motivated by limitations with rule-based approaches, I used the same mature functional model that is used to process missile attacks, control global air traffic, and other complex event processing applications in physical space; but I applied these concepts to cyberspace.</p>
<p>Around the same time, Professor Luckham and others were working on similar problems, all related to real-time detection and response to threats in cyberspace.  They were also funded by the US government.</p>
<blockquote><p>Sidebar: Stream processing of transaction- based systems (databases), another area of interest, was focused on a totally different problem, which was the low latency processing of straight-thru processing in databased-oriented systems.   These stream processing systems were, and remain however,  rule-based systems.  The problems we were trying to solve in cyberspace, however, cannot be efficiently and pragmatically solved by rule-based systems alone.  Only relatively simple scenarios can be efficiently detected by rule-based stream processing systems.</p></blockquote>
<p>The vast majority of complex event processing classes of problems require rules plus advanced algorithms that can learn and adapt in real-time.    I know this, not from reading papers or taking university classes on rule-bases systems, but from working on some very challenging operational problems in real-time.    This is why I remain interested in complex event processing and why I continue to elaborate on why rule-based systems have limitations.</p>
]]></content:encoded>
      <pubDate>Sat, 11 Oct 2008 09:15:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/intrusion detection systems">intrusion detection systems</category>
      <category domain="http://securityratty.com/tag/rule-bases systems">rule-bases systems</category>
      <category domain="http://securityratty.com/tag/transaction- based systems">transaction- based systems</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/real-time detection">real-time detection</category>
      <category domain="http://securityratty.com/tag/real-time">real-time</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/countermeasures">countermeasures</category>
      <source url="http://www.thecepblog.com/2008/10/11/the-motivation-behind-adaptive-analytics-and-cep/">The Motivation Behind Adaptive Analytics and CEP</source>
    </item>
    <item>
      <title><![CDATA[Why Risk Management Doesnt Work (?!)]]></title>
      <link>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</link>
      <guid>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</guid>
      <description><![CDATA[Several folks (Hi Daniel , Brent , David !) sent email &amp; twitters asking us our opinion on a Dark Reading article called Why Risk Management Doesnt Work which if you click on the link should come up...]]></description>
      <content:encoded><![CDATA[<p>Several folks (Hi <a href="http://dmiessler.com/">Daniel</a>, <a href="http://stateofsecurity.com/">Brent</a>, <a href="http://www.twitter.com/debix">David</a>!) sent email &amp; twitters asking us our opinion on a Dark Reading article called &#8220;<a href="http://www.darkreading.com/document.asp?doc_id=165107">Why Risk Management Doesn&#8217;t Work</a>&#8221; which if you click on the link should come up for you after seeing someone&#8217;s advertisement for a few seconds.</p>
<p>I&#8217;m assuming the author wants us to read the title as <strong>&#8220;Things to Look Out For in Performing Risk Analysis&#8221;</strong> and not <strong>&#8220;Risk Management is Folly - Stop, Stop, Stop!&#8221;</strong> The former is fine, the latter isn&#8217;t supported by the evidence presented by the subjects of the article.<br />
The subjects of the article are a <strong><a href="http://www.verizonbusiness.com/resources/security/databreachreport.pdf">good study from Wade Baker &amp; Co. at Verizon</a></strong>, and a report from RSA&#8217;s Security for Business Innovation Council. Let&#8217;s take a look at each of these and examine why what they&#8217;re saying might contribute to poor risk management, shall we?</p>
<p><strong>1.)  THE VERIZON REPORT</strong></p>
<p>The Verizon report is an analysis of some 530 forensic investigations their company performed.  It is well worth your time as it&#8217;s chock full of interesting information.  As it relates to the Dark Reading piece, a coarse summary would be that &#8220;likelihood&#8221; is &#8220;different&#8221; for different people and so you can&#8217;t use the same &#8220;likelihood&#8221; across different industries.</p>
<p>Distilled through the lens of FAIR:</p>
<blockquote><p>&#8220;different threat communities may be applicable based on Probability of Action factors which include: Value, Level of Effort and Risk (of Getting Caught).&#8221;</p></blockquote>
<p>Or, even further distilled and in the words of my six year old son,</p>
<blockquote><p>&#8220;Duh-uh&#8221;.</p></blockquote>
<p>With regards to what I assume is the purpose of the article (What Doesn&#8217;t Work in Risk Analysis) this concept  seems just to rehash the old GIGO argument regarding risk analysis.  Great.  Can&#8217;t argue with that, nor it&#8217;s corollary QIQO (quality in, quality out).</p>
<p>But let me ask you -  <strong><em>is this really a problem common in your analysis</em></strong>?  Did reading this article make you go &#8220;Crap, we&#8217;ve been using data normalized across multiple industries in our analysis! They&#8217;re all wrong!&#8221;  Or have you already been accounting for the unique value proposition your company has to the specific threat community you&#8217;re worried about?  See, maybe I&#8217;m just not your average analyst, but even in my NIST/OCTAVE days, this has *never* been an issue for me.</p>
<p>Let me be specific, this is not a problem with Verizon&#8217;s very cool report.  It&#8217;s just that I don&#8217;t see what the big deal is.  This article is starting to feel like someone is running through the motions, trying to play the &#8221; a crazy title gets people to read a boring article&#8221; game.</p>
<p>Speaking of cool reports - You know what would be cool?  I think it would be interesting to see is the quality of these companies&#8217; &#8220;risk management process&#8221; established using good criteria,  and then correlated to the frequency and magnitude of real-world losses across the aggregate sample.  In other words, can we establish evidence that strong risk management practices not just reduce &#8220;risk&#8221; but also reduce actual incidents.</p>
<p><strong>2.)  THE RSA COUNCIL &#8220;EXPLORES WHY LEGACY METHODS OF EVALUATING INFORMATION SECURITY RISK DON&#8217;T WORK IN TODAY&#8217;S CONNECTED WORLD, IN WHICH ANY NEW BUSINESS INNOVATION INHERENTLY CARRIES SOME LEVEL OF RISK TO INFORMATION.&#8221;</strong></p>
<p>This report from the RSA council puts forth a seemingly obvious proposition, that risk must be balanced by reward.  Why is this news?  Now as I read the article it&#8217;s not clear if:</p>
<ul>
<li>The RSA Council is claiming that the CISO&#8217;s office should be the ones determining reward.  Absurd.</li>
</ul>
<p>or</p>
<ul>
<li>Businesses aren&#8217;t doing a good job at determining risk and reward.</li>
</ul>
<p>Let&#8217;s go with the latter.  So I&#8217;m pretty sure (good) businesses do a good job at estimating reward.  Businesses I&#8217;ve been a part of?  We LOVE(D) estimating reward.  We don&#8217;t tend to start projects all willy-nilly. No we tend to be careful to identify the size of the market and what it will cost to address the market.  So what could the problem be that this RSA council is trying to address?  Maybe it has to do with something like the following:</p>
<p>Yesterday, I got a demo of an IT-GRC application that shall remain nameless.  It seemed to be very good at the &#8220;C&#8221; bits - lots of information on regulations and expectations and even what sorts of controls would answer the regulations (which is goofy, but we&#8217;ll have to talk about that later).  It also gave you the ability to build workflow quite nicely.  But it measured NOTHING.  There really was no observable &#8220;G&#8221; and &#8220;R&#8221; was really Medium X Low X Low = High sorts of stuff.  So let&#8217;s use this relatively expensive tool as evidence of what your average CISO is armed with going into a Risk/Reward sort of meeting.  I imagine a nice board room with wood-grain paneling and glass bowls filled with little chocolate covered mints designed to give everyone involved in the meeting (CEO, CFO, CIO, CSO, VP S&amp;M, etc&#8230;) a little sugar rush when needed and fresh breath.  The conversation goes a little something like this (apologies to <strong><a href="http://securosis.com/2008/09/17/the-fallacy-of-complete-and-accurate-risk-quantification/">Rich</a></strong>):</p>
<blockquote><p><em><strong>Business Guy Who Wants to Make Money Because That&#8217;s What Businesses Do:</strong></em> Based on market studies, we believe that initial gross revenues from the new product and technology rollout will be eleventy gazillion dollars based on a 37% market penetration in Scandinavia, alone.</p>
<p><em><strong>CSO: </strong></em> Well now, we have a likelihood of &#8220;High&#8221; and a &#8220;C&#8221; impact of Medium, and an &#8220;I&#8221; impact of Low, and an &#8220;A&#8221; impact of &#8220;High&#8221; and because we are a (bank/hospital/retailer/basically any business that breathes anymore) we weight &#8220;C&#8221; by a factor of 2 - we multiplied those all together and got a &#8220;High&#8221;.</p>
<p>So can you guys delay the product rollout by 9 months and give me a bunch more money that&#8217;s not in the budget so that I can get this thing down to a &#8220;Medium&#8221;, please?</p></blockquote>
<p>Again, I just don&#8217;t see the problem with Information Risk Management being that our businesses have no idea what the rewards of business might be.  Now maybe we need get a seat in that boardroom just to be able to talk about our &#8220;Mediums&#8221;, sure.  And maybe we&#8217;re infantile in our ability to describe our problem space.  But I cannot fathom that &#8220;<em>Risk Management Doesn&#8217;t Work</em>&#8221; because businesses haven&#8217;t been considering &#8220;reward&#8221;.</p>
<p><strong>WHY RISK MANAGEMENT MAY  NOT BE WORKIN&#8217; FOR YOU</strong></p>
<p>Two meta-categories of causation:</p>
<ul>
<li>No skills</li>
</ul>
<p>and/or</p>
<ul>
<li>No resources</li>
</ul>
<p>Any ancillary &#8220;cause&#8221; can be mapped to one of these categories.  You could have significant resources but crappy models, and have conversations like our imaginary CSO, above.  You could have really good models and people trained and motivated to use them, but scarce time &amp; money, so no conversation happens.</p>
<p>Now my question for you is - which does it make sense to acquire *first* to solve the &#8220;<em>Why Risk Management Doesn&#8217;t Work</em>&#8221; problems, skills or resources?</p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 13:15:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information risk management">information risk management</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/poor risk management">poor risk management</category>
      <category domain="http://securityratty.com/tag/information security risk">information security risk</category>
      <category domain="http://securityratty.com/tag/reduce risk">reduce risk</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/cool report">cool report</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=459">Why Risk Management Doesnt Work (?!)</source>
    </item>
    <item>
      <title><![CDATA[Asus reports virus loaded into Eee Box PCs]]></title>
      <link>http://securityratty.com/article/e83ae00d7ef005995b0a9c82102a4cda</link>
      <guid>http://securityratty.com/article/e83ae00d7ef005995b0a9c82102a4cda</guid>
      <description><![CDATA[Asustek Computer's Japanese arm has alerted owners of its new Eee Box low-cost desktop PC that the machine shipped with a...]]></description>
      <content:encoded><![CDATA[Asustek Computer's Japanese arm has alerted owners of its new Eee Box low-cost desktop PC that the machine shipped with a virus.]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/japanese arm">japanese arm</category>
      <category domain="http://securityratty.com/tag/asustek computer">asustek computer</category>
      <category domain="http://securityratty.com/tag/virus">virus</category>
      <category domain="http://securityratty.com/tag/owners">owners</category>
      <category domain="http://securityratty.com/tag/machine">machine</category>
      <source url="http://www.networkworld.com/news/2008/100708-asus-reports-virus-loaded-into.html?fsrc=rss-security">Asus reports virus loaded into Eee Box PCs</source>
    </item>
    <item>
      <title><![CDATA[Monetizing Infected Hosts by Hijacking Search Results]]></title>
      <link>http://securityratty.com/article/30b128b9fa2c48983d32dbcc4818d136</link>
      <guid>http://securityratty.com/article/30b128b9fa2c48983d32dbcc4818d136</guid>
      <description><![CDATA[When logs with accounting data are no longer of interest due to low liquidity on the underground market, monetization of the infected hosts comes into play

This web based malware seems like an early...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOPovcbgMHI/AAAAAAAACNY/PtnyHCXQm30/s1600-h/pict1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOPovcbgMHI/AAAAAAAACNY/kLv97AsLUco/s200-R/pict1.jpg" /></a>When logs with accounting data are no longer of interest due to low liquidity on the underground market, monetization of the infected hosts comes into play.<br />
<br />
This web based malware seems like an early BETA aiming to scale, however it's only unique features are its ability to hijack the infected user's searches and server relevant ads courtesy of the affiliate networks the administrator participates in, and also, an integrated DDoS module that the author simply stole from another kit. Strangely, it's 2008 yet the author also included the ability to turn on the telnet service on an infected host. <br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZH-8W6ZI/AAAAAAAACOQ/DVWUfx2tkJg/s1600-h/pict2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZH-8W6ZI/AAAAAAAACOQ/kSX1geifdWA/s200-R/pict2.jpg" /></a>With the search queries feature easy to duplicate by other kits, this web based malware is a great example of how the time-to-market mentality lacking any kind of personal experience -- the malware cannot intercept SSL sessions compared to the majority of crimeware kits that can -- ends up in a weird hybrid of random features.<br />
&nbsp; <br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZQQsgnMI/AAAAAAAACOY/f1UOwGyrhSo/s1600-h/pict3.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZQQsgnMI/AAAAAAAACOY/4K4tbpQnUys/s200-R/pict3.jpg" /></a><a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Customerization</a> will inevitably prevail over the product concept mentality.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dgQOM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dgQOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oQzAM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oQzAM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1wqEm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1wqEm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4U2Mm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4U2Mm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DbC0M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DbC0M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=605TM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=605TM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9wzem"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9wzem" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409220865" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 03:33:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/web based malware">web based malware</category>
      <category domain="http://securityratty.com/tag/kits">kits</category>
      <category domain="http://securityratty.com/tag/author simply">author simply</category>
      <category domain="http://securityratty.com/tag/author">author</category>
      <category domain="http://securityratty.com/tag/crimeware kits">crimeware kits</category>
      <category domain="http://securityratty.com/tag/intercept ssl sessions">intercept ssl sessions</category>
      <category domain="http://securityratty.com/tag/product concept mentality">product concept mentality</category>
      <category domain="http://securityratty.com/tag/queries feature easy">queries feature easy</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409220865/monetizing-infected-hosts-by-hijacking.html">Monetizing Infected Hosts by Hijacking Search Results</source>
    </item>
    <item>
      <title><![CDATA[Modelling The Global Financial Meltdown]]></title>
      <link>http://securityratty.com/article/15c8ebf58fa47d569eb7cdbc4039c683</link>
      <guid>http://securityratty.com/article/15c8ebf58fa47d569eb7cdbc4039c683</guid>
      <description><![CDATA[Yesterday I received a call from Penny Grosman , Senior Editor, Wall Street &amp; Technology . Penny was interested in my opinion, Will risk management applications be the next killer app for CEP on Wall...]]></description>
      <content:encoded><![CDATA[<p>Yesterday I received a call from <a href="http://www.wallstreetandtech.com/penny-crosman/" target="_blank">Penny Grosman</a>, Senior Editor, <a href="http://www.wallstreetandtech.com/" target="_blank">Wall Street &amp; Technology</a>.   Penny was interested in my opinion, &#8220;Will risk management applications be the next killer app for CEP&#8221; on Wall Street.    I enjoyed talking with Penny.  She caught up with me leaving a tailor&#8217;s shop in Chiang Mai, so I hope she did not mind hearing my stories of buying unique Northern Thai cotton fabric and designing my own casual shirts in the economic turndown.</p>
<p>We read many stories on the net where folks claim that the current financial crisis could have been avoided with more or better use of technology.     This is expected, as software companies and IT professionals will often try to piggy-backtheir business development strategy on the &#8220;crisis of the day&#8221; to sell more goods and services.    Honestly, in this current situation, the main technology that we needed was simple, accurate financial models.</p>
<p>For example, in the chart above, the US economy was doing quite well with US federal funds rates low.   Housing prices in the US were skyrocketing and there was a concern about inflation.    There was an understandable concern the sustainability of that economy.</p>
<p style="text-align: center;"><img class="aligncenter" style="vertical-align: bottom;" src="http://www.thewrittenblog.com/main_1/images/97kcpv16xjh0uvsi8k7kdhaw.gif" alt="" width="277" height="415" /></p>
<p>So, in perhaps one the most ill-advised Federal Reserve actions of many decades, the folks at the helm of the Fed decided to raise their lending rates around 500 percent over a two year period.</p>
<p>As we all know, primarily because of the action by the Fed, the world faces perhaps the worst economic disaster in modern times, while the US Executive Branch and the Congress fight over how to spend $700 Billion taxpayer dollars to inject liquidity into the markets to try to head off a global financial disaster.</p>
<p>It is amazing to me that the US Federal Government, or their advisors, does not have simple financial models with cause-and-effect analysis such as:</p>
<ul>
<li>Homeowners with adjustable rate mortuages will not be able to make payments;and</li>
<li>Housing prices will fall dramatically; then</li>
<li>Homeowners will default on loans where the collateral is much less than the asset value, and</li>
<li>Banks will suffer great losses, and</li>
<li>Lending will come to a halt, then</li>
<li>Banks will collapse, then</li>
<li>Wall Street will exit the markets in panic</li>
<li>&#8230; and more trouble&#8230;.. !!</li>
</ul>
<p>There are and continue to be a lot of discussion and opinions about how risk management needs improvement. and I agree.   We will also read folks talk about how technology can be used to help solve this problem, including CEP/EP and related software (see also <!-- This wrapper class appears only on Page and Single Post pages. --><a title="Capital Market CEP Fantasy Land" rel="bookmark" href="../2008/06/23/capital-market-cep-fantasy-land/">Capital Market CEP Fantasy Land</a>). However, as much I would be pleased to see more CEP/EP applications and use cases, I do not believe that event processing technology is really very useful to solve the core problem of the current financial crisis.</p>
<p>The core problem is, seemingly, that our &#8220;financial experts&#8221; do not even have simple models that will illustrate what will or could happen when you raise the fed lending rates 500 percent in two years in an economy pregnant with adjustable rate mortgages.</p>
<p>To me, this does not appear to be rocket science.  The negligence by the US Federal Reserve and their advisors is astonishing.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 02:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/simple financial models">simple financial models</category>
      <category domain="http://securityratty.com/tag/financial models">financial models</category>
      <category domain="http://securityratty.com/tag/current financial crisis">current financial crisis</category>
      <category domain="http://securityratty.com/tag/crisis">crisis</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/wall street">wall street</category>
      <category domain="http://securityratty.com/tag/main technology">main technology</category>
      <category domain="http://securityratty.com/tag/folks">folks</category>
      <source url="http://www.thecepblog.com/2008/10/02/modelling-the-global-financial-meltdown/">Modelling The Global Financial Meltdown</source>
    </item>
    <item>
      <title><![CDATA[The asymmetry of data loss - data thief has an upper hand]]></title>
      <link>http://securityratty.com/article/1279b28b3737ccdc02880482fc1987c9</link>
      <guid>http://securityratty.com/article/1279b28b3737ccdc02880482fc1987c9</guid>
      <description><![CDATA[I read this awesome book by Dan Geer, Economics and Strategies of Data Security . This gave me structure for my thoughts about a complex topic such as data security
When a data owner's (a business)...]]></description>
      <content:encoded><![CDATA[<P>I read this&nbsp;awesome book by Dan Geer, <A href="http://www.verdasys.com/thoughtleadership/">Economics and Strategies of Data Security</A>. This gave me structure&nbsp;for my thoughts about a complex topic such as data security. </P>
<P>When&nbsp;a&nbsp;data owner's (a business)&nbsp;sensitive data is breached it is&nbsp;difficult to quantify the monetary loss. According to respectable survey sources, the average cost of sensitive data breach for a large size company is about $50,000. I am attempting here to think about this in simple mathametical terms:</P>
<P>There is a data breach. From the data owner's perspective the loss is:</P>
<P><FONT color=#3366ff>Loss&nbsp;= Cost to protect data&nbsp;+ Loss of business due to data theft aka cost of competitive disadvantage</FONT></P>
<P>From the data thief's perspective</P>
<P><FONT color=#3333ff>Net Gain= [Cost of producing the data&nbsp; *&nbsp; Data freshness factor] - Cost to steal the data + Profit of business due to data aka gain of competitive advantage</FONT></P>
<P>From the above two equations it is very clear that this is not a zero sum game. There is a clear cost asymmetry for a data owner and for a data thief. When there is an asymmetry there is an opportunity. Data owner&nbsp;would not even know that the&nbsp;data is lost because&nbsp;the original copy of the data may be still intact - data thief could have simply copied the data.&nbsp;Data theft does not look like&nbsp;a car theft, there is no vacuum left behind.&nbsp;</P>
<P><STRONG><EM>This motivates a data thief to keep the cost to steal low, steal highly valuable data that has&nbsp;a long shelf life and in a way that data owner will never even be aware of theft.</EM></STRONG></P>
<P>From&nbsp;a data thief's perspective, the cost to steal data if kept high would disincentive him. Moreover, Data freshness factor, i.e. how valuable this data is over period of time plays an important role.&nbsp;A good example is content of today's newspaper is hardly valuable tomorrow, but the content of newspaper two days ahead (if can be procured)would be invaluable. Data relevance is a function of time and other marketplace variables - &nbsp;Data freshness Factor accounts for that variable. A good way to discourage data thief is to increase his/her cost to steal the data. There are other inferences from the above equation. If there exists&nbsp;no competitive advantage&nbsp;with the stolen data, hardly any thief would even venture&nbsp;to steal the&nbsp;data in the first place. If the cost of producing data is very low, then probably thief can just produce the data himself and would not attempt to steal the data. If the cost of&nbsp;theft is kept high, it would definitely deter the data thief from stealing data using technical mechanisms, then the data thief would&nbsp;exploit weak links in data security&nbsp;such as use of social engineering to get access to the data.</P>
<P>From data owner perspective protecting data becomes very important. How much would the owner be willing to spend? Not definitely the cost equal to cost of producing the data. 1% to 10% of cost of producing data is considered prudent. For a data owner it is difficult to estimate cost of data protection of a specific data, because it is not easy to chunkify data protection costs. Moreover, as Dan Geer says in his book, a data owner has to protect himself from number of intruders not just one.</P>
<P><EM><STRONG>It pays for a data owner to: be aware of data breaches (or data leaks), employ appropriate&nbsp;mechanisms to protect the data; the cost of protection which&nbsp;is fractional cost of&nbsp;the valuable&nbsp;data and&nbsp;enhance information security awareness of personnel who handle the data.</STRONG></EM></P>
<P><STRONG><EM>Data loss is not a zero sum game. The advantage is in favor of a data thief (data thieves rather).&nbsp;Data owner does not give much thought&nbsp;on&nbsp;the value of data&nbsp;unless&nbsp;there is a data theft.&nbsp;But,&nbsp;a&nbsp;data thief&nbsp;has every reason to think about economics of data theft before he acts to steal the data else data thief won't survive in this game and he is very well aware of his advantageous position.</EM></STRONG></P>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 02:33:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data owner perspective">data owner perspective</category>
      <category domain="http://securityratty.com/tag/data owner">data owner</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/thief">thief</category>
      <category domain="http://securityratty.com/tag/owner">owner</category>
      <category domain="http://securityratty.com/tag/data freshness factor">data freshness factor</category>
      <category domain="http://securityratty.com/tag/data protection costs">data protection costs</category>
      <category domain="http://securityratty.com/tag/discourage data thief">discourage data thief</category>
      <category domain="http://securityratty.com/tag/protect data">protect data</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2008/10/1/3910766.html">The asymmetry of data loss - data thief has an upper hand</source>
    </item>
    <item>
      <title><![CDATA[Interop NY Survey Top IT Challenges, Trends and What IT is Spending Money On]]></title>
      <link>http://securityratty.com/article/c1238f65d5c0144adeaaf578e8e7de08</link>
      <guid>http://securityratty.com/article/c1238f65d5c0144adeaaf578e8e7de08</guid>
      <description><![CDATA[I wont belabor the point again but just mention it as context for the 2nd annual survey we conducted at Interop NY this year. As I was dragging myself to the very early keynotes at VMworld , things...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/survey-poll.jpg" border="0" alt="survey_poll" width="240" height="240" align="left" /> I won’t belabor the point again but just mention it as context for the <a href="http://www.sciencelogic.com/pressrelease_20080925.htm" target="_blank">2nd annual survey</a> we conducted at <a href="http://www.interop.com/" target="_blank">Interop NY</a> this year. As I was dragging myself to the very early keynotes at <a href="http://www.vmworld.com/vmworld/index.jspa" target="_blank">VMworld</a>, things were <a href="http://www.dailyreckoning.com.au/bailout-debate-rages-on/2008/09/25/" target="_blank">falling apart on Wall Street</a>, entire departments at <a href="http://www.doctorhousingbubble.com/lehman-brothers-the-rise-and-fall-of-lehman-brothers-a-history-that-goes-beyond-the-great-depression/" target="_blank">Lehman were being let go</a>, and the boys were in NYC getting the <a href="http://www.interop.com/lasvegas/exhibition/interopnet/" target="_blank">InteropNet</a> show network up and running.</p>
<p>By all accounts the show did go on, and we have some very interesting results to share with you all.</p>
<p>Take the Top Challenges question. Once again, “Supporting New Technologies/Enabling Innovation” was most popular. But that’s a no-brainer and as one memorable respondent told me, “the definition of what I do”. What was more important was seeing the big jump that “Reducing Management Costs” made on the list, from #5 last year to #2 this year and only 1 percentage point behind #1. Tightening the belt is top of mind for everyone. (<em>As I write, the <a href="http://eddriscoll.com/archives/014056.php" target="_blank">Dow closed down today over 700 points</a></em>)</p>
<p>Overall, IT professionals told us they were tackling the practical projects that should and could get done – from deploying Security Information Management solutions to getting Asset Management and Inventory Tools in place. For the first time, we saw a close correlation between what people said was important and what actually got done. Of low importance and even lower actual deployments – <a href="http://www.processor.com/editorial/article.asp?article=articles%2Fp2931%2F33p31%2F33p31.asp" target="_blank">ITIL</a> and <a href="http://www.processor.com/editorial/article.asp?article=articles%2Fp2931%2F33p31%2F33p31.asp" target="_blank">CMDB</a>, <a href="http://www.pcmag.com/article2/0,2817,2325880,00.asp" target="_blank">IPv6</a>, <a href="http://www.greenm3.com/2008/09/state-cios-driv.html" target="_blank">Green IT</a> and <a href="http://www.techlinks.net/blogs/publishing/archive/2008/09/22/is-the-internet-ready-for-cloud-computing.aspx" target="_blank">Cloud Computing</a>.</p>
<p>And perhaps people “fessed” up about virtualization. Instead of the usual “high importance, not so many deployments now, but more deployments planned” theme we’ve been seeing around virtualization adoption, this year the very hot trend seemed to lose a bit of steam. Across the board, the numbers were down for <a href="http://www.echannelline.com/usa/story.cfm?item=23739" target="_blank">virtualization management</a>, with close to 50% of respondents telling us that their businesses were less than 10% virtualized (4% of that with no virtualization at all).</p>
<p>2008 Detailed Results – <a href="http://www.sciencelogic.com/pdf/InteropNY2008_Survey_Trends.pdf" target="_blank">showing trends year over year</a></p>
<p>Comparison of <a href="http://www.sciencelogic.com/pdf/FOSE2008_vs_2008InteropNY.pdf" target="_blank">Results from Interop NY 2008 vs FOSE 2008</a> (government IT)</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 23:00:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/virtualization management">virtualization management</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/top challenges question">top challenges question</category>
      <category domain="http://securityratty.com/tag/virtualization adoption">virtualization adoption</category>
      <category domain="http://securityratty.com/tag/importance">importance</category>
      <category domain="http://securityratty.com/tag/close correlation">close correlation</category>
      <category domain="http://securityratty.com/tag/2nd annual survey">2nd annual survey</category>
      <source url="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008">Interop NY Survey Top IT Challenges, Trends and What IT is Spending Money On</source>
    </item>
    <item>
      <title><![CDATA[The Genesis of Complex Event Processing: Asymmetric Capabilities]]></title>
      <link>http://securityratty.com/article/58ed1db82fe051447218ff6d60c32d71</link>
      <guid>http://securityratty.com/article/58ed1db82fe051447218ff6d60c32d71</guid>
      <description><![CDATA[More often than not, folks working in the field of complex event processing do not truly understand CEP. We often see the same folks try to position and mischaracterize CEP as business process...]]></description>
      <content:encoded><![CDATA[<p>More often than not, folks working in the field of complex event processing do not truly understand CEP.   We often see the same folks try to position and mischaracterize CEP as business process orchestration, business process management, event-driven architecture or even an evolution of service-oriented architecture.    Well-intended, this mischaracterization of CEP is often for sales and marketing purposes.  However, sometimes the mischaracterization of CEP is from a lack of understanding of what CEP was designed to accomplish.  These mischaracterizations have very little to do with the original intent of complex event processing.</p>
<p>Originally, researchers in CEP were not trying to solve a problem of streaming data or streaming events.   Often we read this mischaracterization by folks in the database/streaming domain, as they were focused on the low latency processing of streaming events.   A natural extension of this research has been stream processing software (often called &#8220;engines&#8221;) that process streaming data with continuous queries, for example market data feeds for algo-trading or best market order execution.  This mischaracterization is partly responsible for why we see many order processing applications in market data stream processing mislabled as &#8220;complex event processing&#8221; applications.</p>
<p>The genesis of complex event processing was not the stream processing need for &#8220;feeds and speed&#8221; but the processing capability to solve what can be characterized as the &#8220;problem of asymmetric capabilties&#8221;.   The term &#8220;asymmetric&#8221; has been used in the military domain. For example we often hear the term &#8220;<a href="http://en.wikipedia.org/wiki/Asymmetric_warfare" target="_blank">asymmetric warfare</a>.&#8221;  However, in general the concept of &#8220;asymmetrical processing capablities&#8221; is the true genesis for CEP and related processing concepts and domains.   It is this genesis that distinguishes CEP from EDA, SOA, SOR, and so many other technology oriented concepts.</p>
<p>In order to illustrate what I mean by &#8220;asymmetrical processing capablities&#8221; we will take the example of the evolution of rocketry.    In the early days, scientists learned how to make rockets, I assume with gunpowder and similar chemical compounds to launch rockets.   Over many years the application of rocketry advanced much faster than the ability to understand the situations created in the sky.    In other words, folks could fill the skies with rockets long before they had the capability to track and identify (or sense and respond to)  the rockets in real time.</p>
<p>Therefore, the concept of &#8220;asymmetrical processing capablities&#8221; is the situation where there is a capability, such as &#8220;launch a rocket, sense-and-respond,&#8221; that is asymmetric in nature.    In other words, the capability to detect multiple rocket launches creates an asymmetric situation where it is easy to launch rockets, but hard to detect and defend against those launches.</p>
<p>The same concept can be applied to everyday air travel.   If we could only fly airplanes, but did not have the capability to track the planes, understand situations in airspace, and then respond to changing situations, air travel would be quite difficult.   Lucky for us, the global traveller, there is symmetry in the capabilities to build and fly aircraft and the capabilities to detect, track and follow the evolving situations in the sky.</p>
<p>The genesis of CEP was to solve the problem of asymmetry in cyberspace, or if you prefer, distributed data networks.   The folks who identified, early on,  the problems associated with asymmetry in cyberspace were folks working the the field of network and security management.    This is because there has been, and is currently, a great asymmetry between the capablities to &#8220;launch a process or transaction&#8221; in cyberspace and the capabilties to detect and track what is going on in the same domain.</p>
<p>In my next post on this topic, we will go into some details of this asymmetry and review the first CEP projects from Stanford University in the context of asymmetric processing capabilities in cyberspace.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 13:31:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/asymmetric">asymmetric</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/market data stream">market data stream</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/term asymmetric warfare">term asymmetric warfare</category>
      <category domain="http://securityratty.com/tag/term asymmetric">term asymmetric</category>
      <category domain="http://securityratty.com/tag/distinguishes cep">distinguishes cep</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/asymmetric capabilties">asymmetric capabilties</category>
      <source url="http://www.thecepblog.com/2008/09/29/the-genesis-of-complex-event-processing-asymmetric-capabilites/">The Genesis of Complex Event Processing: Asymmetric Capabilities</source>
    </item>
    <item>
      <title><![CDATA[Have CrackBerry, Will Travel]]></title>
      <link>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</link>
      <guid>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</guid>
      <description><![CDATA[Blogger: Dan Blum
It is no surprise for us to hear loose lips flapping in India about a capability to decrypt Blackberry and other carrier traffic
After all, weve done basic threat analysis for years...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>It is no surprise for us to hear loose lips flapping in India about <a href="http://economictimes.indiatimes.com/At_last_govt_cracks_BlackBerry_code/articleshow/3510719.cms">a capability to decrypt Blackberry and other carrier traffic</a>.</p>

<p>After all, we’ve done basic threat analysis for years and it was only months ago that I was brought into a company-wide CISO meeting at a U.S. defense contractor to help them hash out their travel policy for mobile devices. Going into the meeting, I knew their policy restricted taking devices to a list of countries considered dangerous – but there was an exemption for BlackBerries.</p>

<p>Our research uncovered that BlackBerry is pretty secure in most respects. It has transport encryption along with optional password protection, remote kill, disk encryption, and S/MIME encryption. Viruses have not flourished on this functionally limited and closed platform. Few if any third party add on programs are required for additional protection. Nonetheless, I went into the meeting prepared to talk with the CISOs about the risks and security limitations of life on BlackBerry.</p>

<p>Was the BlackBerry exemption reasonable? At the time, BlackBerry transport encryption was not known to have been broken (to be fair, the article listed above still qualifies as rumor, not certainty of breakage). However, I pointed out that it is dangerous to assume well-equipped attackers like military or intelligence organizations can’t crack transport encryption. And even if they haven’t cracked the BlackBerry network and whole disk encryption features, sophisticated adversaries have other attack paths. Check out Neal Stephenson’s excellent book <a href="http://www.amazon.com/Cryptonomicon-Neal-Stephenson/dp/0060512806/ref=pd_bbs_sr_1?ie=UTF8&amp;s=books&amp;qid=1222262354&amp;sr=1-1">Cryptonomicon</a> for a description of how a talented adversary might “see” your keystrokes and screen images through a motel room wall, for example.</p>

<p>If one of your employees – such as a key scientist, project manager, or executive – is targeted for surveillance and is carrying sensitive data through certain countries, one could argue that he or she had better undergo serious counter-intelligence training.&nbsp; Learn to spot and shake tails, sneak into dark alleys for that BlackBerry fix. Learn to paper the closet with layers of aluminum foil and send messages in the dark. Defend that BlackBerry with encryption, long passphrases, and kung fu. But unless James Bond is running your company, I doubt this is what your executives have in mind for the next business trip!</p>

<p>Assuming your organization’s lower level employees are like needles in a haystack and won’t be bothered could be an exercise in wishful thinking. It is always possible that nation states are monitoring some or all of the airwaves. Not so long ago the NSA had a massive a covert surveillance program in place. Years before the government was reportedly snarfing up terabytes of emails and crunching them through a program called Carnivore. And of course, selective monitoring of people on watch lists continues on a large scale. This is just the surveillance we know about in the U.S. We suspect there’s more behind the scenes and especially in countries such as China. Even if you train your non-specifically-targeted low level employees to write and speak in search-keyword-free code, the carnivore programs of the world are pretty good at sniffing out those interesting needles – such as descriptions of your business plans, manufacturing processes, and trade secrets.</p>

<p>Sound paranoid? I admit that I don’t know what the probabilities of being targeted or monitored are – just that it can happen. It’s the height of arrogance to believe that a nation state can’t get your information if they’ve targeted it and you’re within their borders. And it’s dangerous to rely on security by obscurity when medium or high consequence information must be protected.</p>

<p>What can be done? If key personnel can't dispense with the BlackBerry (or any other email device) during international travel to those countries where information may be most at risk, they (the users) should limit communications to what they’d feel comfortable uttering over a potentially-monitored telephone call. Controlling incoming communications – messages sent by others – is a harder problem. Until data loss prevention (DLP) products become more contextually sensitive about the travel issues, it may be best not to synchronize the BlackBerry with the overseas user’s home mailbox. Instead, have the user give out a temporary address for the BlackBerry and warn senders to be discreet. </p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/402766223" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 04:45:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry transport encryption">blackberry transport encryption</category>
      <category domain="http://securityratty.com/tag/transport encryption">transport encryption</category>
      <category domain="http://securityratty.com/tag/exemption">exemption</category>
      <category domain="http://securityratty.com/tag/blackberry exemption reasonable">blackberry exemption reasonable</category>
      <category domain="http://securityratty.com/tag/blackberry">blackberry</category>
      <category domain="http://securityratty.com/tag/disk encryption">disk encryption</category>
      <category domain="http://securityratty.com/tag/disk encryption features">disk encryption features</category>
      <category domain="http://securityratty.com/tag/blackberry fix">blackberry fix</category>
      <category domain="http://securityratty.com/tag/decrypt blackberry">decrypt blackberry</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/402766223/have-crackberry.html">Have CrackBerry, Will Travel</source>
    </item>
    <item>
      <title><![CDATA[Five Vulnerabilities Patched In Firefox 3.0.2 and 2.0.0.17, Two Of Them Are Critical]]></title>
      <link>http://securityratty.com/article/45bfc97f3446dbb78c702703d1ee29f4</link>
      <guid>http://securityratty.com/article/45bfc97f3446dbb78c702703d1ee29f4</guid>
      <description><![CDATA[Firefox 3.0.2 was released today with 5 fixes for security vulnerabilities. The Mozilla Foundation has addressed 2 critical and 2 moderate security vulnerabilities, 11 flaws in total. One of the bugs...]]></description>
      <content:encoded><![CDATA[Firefox 3.0.2 was released today with 5 fixes for security vulnerabilities.  	The Mozilla Foundation has addressed 2 critical and 2 moderate security vulnerabilities, 11 flaws in total. One of the bugs in both Firefox 2.0 and 3.0, although rated only low, was described by Mozilla as a variant of a &#8220;click-hijacking&#8221; vulnerability first reported [...]]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 07:19:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/firefox">firefox</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/mozilla">mozilla</category>
      <category domain="http://securityratty.com/tag/mozilla foundation">mozilla foundation</category>
      <category domain="http://securityratty.com/tag/critical">critical</category>
      <category domain="http://securityratty.com/tag/bugs">bugs</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/fixes">fixes</category>
      <category domain="http://securityratty.com/tag/total">total</category>
      <source url="http://cyberinsecure.com/five-vulnerabilities-patched-in-firefox-302-and-20017-two-of-them-are-critical/">Five Vulnerabilities Patched In Firefox 3.0.2 and 2.0.0.17, Two Of Them Are Critical</source>
    </item>
  </channel>
</rss>
