<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: march]]></title>
    <link>http://securityratty.com/tag/march</link>
    <description></description>
    <pubDate>Mon, 07 Jul 2008 15:20:21 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[No Trademark for Cloud Computing]]></title>
      <link>http://securityratty.com/article/4b9f7e842fb8a79ceb2a5ea157dab13c</link>
      <guid>http://securityratty.com/article/4b9f7e842fb8a79ceb2a5ea157dab13c</guid>
      <description><![CDATA[Just a couple of weeks ago, it was reported that Dell was in the final stages of being granted a trademark on Cloud Computing shocking and amusing pretty much everyone except for possibly Dell...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="157" alt="clouds-jwn6" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/clouds-jwn6.jpg" width="240" align="left" border="0" /> Just a couple of weeks ago, it was reported that Dell was in the final stages of being granted a trademark on &#8220;Cloud Computing&#8221; &#8211; <a href="http://languagelog.ldc.upenn.edu/nll/?p=434#more-434" target="_blank">shocking and amusing</a> pretty much everyone except for possibly Dell employees. But apparently the US Patent and Trademark Office paid attention to the flurry of negative responses and has since <a href="http://samj.net/2008/08/dells-notice-of-allowance-for-cloud.html" target="_blank">cancelled their &#8220;Notice of Allowance&#8221;</a> for the trademark. </p>
<p>I&#8217;d like to give everyone the benefit of the doubt here; perhaps Dell was using it in a much narrower sense. Perhaps the term has really only been used more commonly since the time Dell first applied for the trademark back in March 2007 and now. BUT&#8230;</p>
<p>- Dell&#8217;s definition is quite broad and certainly not Dell-specific. <a href="http://www.eweek.com/c/a/IT-Infrastructure/Dell-Attempts-to-Trademark-Cloud-Computing/" target="_blank">&#8220;The design of computer hardware for use in datacenters and mega-scale computing environments for others; customization of computer hardware for use in data centers and mega-scale computing environments for others; design and development of networks for use in data centers and mega-scale computing environments for others.&#8221;</a> Strike One.</p>
<p>- And according to the Wall Street Journal&#8217;s research, &#8220;<a href="http://blogs.wsj.com/biztech/2008/08/06/dells-tech-jargon-trademark/" target="_blank">cloud computing&#8221; has been in regular use since 2001</a>. Strike Two.</p>
<p>So now the &#8220;case&#8221; has been returned to examination and hopefully the PTO will follow up on everyone else&#8217;s research on this and decide that yes, cloud computing is one of those broad, ubiquitous terms that should NOT be trademarked by a single company. </p>
]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 16:01:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trademark">trademark</category>
      <category domain="http://securityratty.com/tag/dell">dell</category>
      <category domain="http://securityratty.com/tag/time dell">time dell</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/dell-specific">dell-specific</category>
      <category domain="http://securityratty.com/tag/possibly dell employees">possibly dell employees</category>
      <category domain="http://securityratty.com/tag/trademark office">trademark office</category>
      <category domain="http://securityratty.com/tag/computer hardware">computer hardware</category>
      <category domain="http://securityratty.com/tag/data centers">data centers</category>
      <source url="http://blog.sciencelogic.com/no-trademark-for-cloud-computing/08/2008">No Trademark for Cloud Computing</source>
    </item>
    <item>
      <title><![CDATA[Sorry CharlieCard, Your Security Model Is Broken]]></title>
      <link>http://securityratty.com/article/f11af6f7a39f4309ead15fadb8a610f7</link>
      <guid>http://securityratty.com/article/f11af6f7a39f4309ead15fadb8a610f7</guid>
      <description><![CDATA[It sure seems like the CharlieCard , which is used by the Boston subway system, has a serious security weakness. The MBTA has sued 3 MIT students to stop them from giving a planned talk at DEFCON...]]></description>
      <content:encoded><![CDATA[<p>It sure seems like the <a href="http://www.mbta.com/fares_and_passes/charlie/">CharlieCard</a>, which is used by the Boston subway system, has a serious security weakness.  The MBTA has <a href="http://www.theregister.co.uk/2008/08/09/defcon_speakers_sued/">sued 3 MIT students</a> to stop them from giving a planned  talk at DEFCON.</p>
<p>Doesn&#8217;t this seem backwards to you?  Shouldn&#8217;t the MBTA be suing the vendor who sold them the flawed system?  Security problems go away by mandating independant security testing before a product is accepted, not by trying to get security researchers to be quiet.  This is a good example of how the reactive approach doesn&#8217;t work.  The flaws are still in the system and suing researchers has just <a href="http://en.wikipedia.org/wiki/Streisand_effect">shined a bright light</a> on them.</p>
<p><strong>Update 08/09/2008 6:00pm EST:</strong></p>
<p>The <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9112160&amp;intsrc=news_ts_head">EFF is appealing the injunction</a> which is blocking the students from speaking about the results of their testing.</p>
<p>A telling quote from Kurt Opsahl, staff attorney at the EFF gets to the heart of the issue:</p>
<blockquote><p>&#8220;Courts have found that the First Amendment covers these things. We believe that this is a protected speech activity. When you discuss security issues, if you are telling the truth, that is something that should be protected.&#8221;</p></blockquote>
<p>Apparently the MBTA has known about this problem since at least March, 2008 when a graduate student from the University of Virginia announced <a href="http://www.boston.com/business/articles/2008/03/06/t_card_has_security_flaw_says_researcher/">he was able to break the encryption system</a>.</p>
<p>The U of VA researcher gave an interview where he described why security by obscurity is not a valid security approach for a cryptosystem:</p>
<blockquote><p><strong>Q:</strong> What are your thoughts on security by obscurity? Is NXP using this method of protection?</p>
<p><strong>A:</strong> Security-through-obscurity hardly ever works. The lack of proper peer-review often even hurts the security of the system. Our Mifare work discovered several vulnerabilities that could be fixed without increasing the cost of the cards. NXP did for a long time rely on obscurity for the security of some of their products, but now decided against this outdated design approach and instead bases the security of newer RFID cards on publicly scrutinized cryptography and independent evaluations.</p>
<p><strong>Q:</strong> Can you explain &#8220;Kerckhoffs Principle&#8221; and why it applies to your work?</p>
<p><strong>A:</strong> Kerchoff, who lived in the 19th century, observed that keeping anything secret is really hard. So instead of relying on the secrecy of your whole system, it would a lot easier to only rely on the secrecy of a small secret key. Security systems should hence be publicly known and analyzed, and only the key should be secret. When properly realised for RFID cards, Kerchoff&#8217;s principle means that by analyzing their own cards, thieves cannot compromise your cards. This is contrary to our Mifare work, where we only analyzed a few copies of the the secret algorithm that is found in all cards and were consequently able affect the security of all the other billion cards out there.</p></blockquote>
<p>The MBTA not only accepted a security system which relied on security by obscurity but once accepting this flawed model must try to maintain this obscurity with the court system.</p>
<p>The documents detailing the presentation are <a href="http://www.tgdaily.com/content/view/38817/108/">here.</a></p>
]]></content:encoded>
      <pubDate>Sat, 09 Aug 2008 10:57:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/valid security approach">valid security approach</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/encryption system">encryption system</category>
      <category domain="http://securityratty.com/tag/boston subway system">boston subway system</category>
      <category domain="http://securityratty.com/tag/discuss security issues">discuss security issues</category>
      <category domain="http://securityratty.com/tag/court system">court system</category>
      <category domain="http://securityratty.com/tag/security systems">security systems</category>
      <source url="http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/">Sorry CharlieCard, Your Security Model Is Broken</source>
    </item>
    <item>
      <title><![CDATA[Ohio official sues e-voting vendor for lost votes]]></title>
      <link>http://securityratty.com/article/e3f7e99e018f066a26d2beaba86ad414</link>
      <guid>http://securityratty.com/article/e3f7e99e018f066a26d2beaba86ad414</guid>
      <description><![CDATA[The Ohio Secretary of State Jennifer Brunner filed a lawsuit against e-voting vendor Premier Election Solutions for dropped votes in the state's March primary election. Premier Election Solutions was...]]></description>
      <content:encoded><![CDATA[The Ohio Secretary of State Jennifer Brunner filed a lawsuit against e-voting vendor Premier Election Solutions for dropped votes in the state's March primary election. Premier Election Solutions was formerly called Diebold Election Systems.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=C2QYgm"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=C2QYgm" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/359539486" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/diebold election systems">diebold election systems</category>
      <category domain="http://securityratty.com/tag/premier election solutions">premier election solutions</category>
      <category domain="http://securityratty.com/tag/march primary election">march primary election</category>
      <category domain="http://securityratty.com/tag/jennifer brunner filed">jennifer brunner filed</category>
      <category domain="http://securityratty.com/tag/ohio secretary">ohio secretary</category>
      <category domain="http://securityratty.com/tag/votes">votes</category>
      <category domain="http://securityratty.com/tag/lawsuit">lawsuit</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/359539486/article.do">Ohio official sues e-voting vendor for lost votes</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - July 2008]]></title>
      <link>http://securityratty.com/article/ad180724e0eff95212e4a6b6f36f73c1</link>
      <guid>http://securityratty.com/article/ad180724e0eff95212e4a6b6f36f73c1</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. This is an attempt to remind people of useful content!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>As you can easily, easily guess, the&#160; #1 spot this month is taken by my irreverent comments on a Terry Childs saga. Namely, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">On Doomsaying (Terry Childs case)</a>&quot;, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">So ... Am I? Maybe I Am!</a>&quot; and &quot;<a href="http://chuvakin.blogspot.com/2008/07/admins-good-guys-or-am-not-idiot.html">Admins , Good Guys or &quot;I am NOT an Idiot!&quot;</a>&quot;</li>    <li>Obviously, my earlier post/rant called &quot;<a href="http://chuvakin.blogspot.com/2008/06/you-are-security-idiot-if.html">You Are &quot;A Security Idiot&quot; If ...</a>&quot; takes the #2 spot. Yes, we all like to point out other people's problems, especially when they are epically huge :-)</li>    <li>Next up is my post &quot;<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a>&quot;. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>) </li>    <li>Also popular is my post &quot;<a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">Log Management - Day 1</a>,&quot; which talks about the very first thing you do when embarking on a journey to <a href="http://www.loglogic.com">log management</a>.</li>    <li>Finally, again this month, <a href="http://chuvakin.blogspot.com/search/label/poll">my logging polls</a> took the #1 spot!&#160; <a href="http://chuvakin.blogspot.com/2008/05/poll-8-log-analysis-context.html">Poll #8</a> that covered context data for log analysis <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">is analyzed here</a>. Other popular polls include a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>)&#160; and <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually look and <a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">poll #5</a> about logging challenges. </li>    <li>Strangely, a lot of people wanted to &quot;<a href="http://chuvakin.blogspot.com/2008/07/which-blogs-do-i-read.html">Which Blogs Do I Read?</a>&quot; - so my brief post on that made it to the top.</li> </ol>  <p>See you in August, unless you are all on vacations, that is :-)</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a></li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a></li> </ul>  <p>&#160;</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=dP6djK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=dP6djK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=ZJx4wK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=ZJx4wK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Avu9xK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Avu9xK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/353106236" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 12:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/popular posts">popular posts</category>
      <category domain="http://securityratty.com/tag/popular">popular</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/353106236/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</source>
    </item>
    <item>
      <title><![CDATA["Walking" with the SDL - Part 1]]></title>
      <link>http://securityratty.com/article/a385f01ff42122f11ba5929b9506795a</link>
      <guid>http://securityratty.com/article/a385f01ff42122f11ba5929b9506795a</guid>
      <description><![CDATA[Jeremy Dallman here. Back in March I wrote a post about Crawling Toward SDL . I used the imagery of learning to crawl, walk and run as a way to provide some basic starting points that would move your...]]></description>
      <content:encoded><![CDATA[<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3 face=Calibri>Jeremy Dallman here. Back in March I wrote a post about </FONT><A href="http://blogs.msdn.com/sdl/archive/2008/03/06/crawling-toward-sdl.aspx"><FONT size=3 face=Calibri>“Crawling” Toward SDL</FONT></A><FONT size=3><FONT face=Calibri>. I used the imagery of learning to “crawl, walk and run” as a way to provide some basic starting points that would move your organization toward implementing a version of Microsoft’s Security Development Lifecycle (SDL). <?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>In this series I am going to talk about “Walking” with the SDL. Walking is the point where your security development practices become a lifecycle – a repeatable, mostly reusable process that makes security a part of your development culture. To relate the analogy to SDL a bit more closely, think of <I style="mso-bidi-font-style: normal"><U>crawling</U></I> as the “SD” in SDL. For this post, we’ll talk about <I style="mso-bidi-font-style: normal"><U>walking</U></I> – or adding the “L” in SDL. <o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>I will be covering quite a bit on this topic, so I intend to split it up in to a multi-part series over a few days. I’ll condense it all into one big doc at the end. In Part One, I will review “crawling” and the foundation you need to have in place as well as discuss getting management approval. In Part Two we’ll cover the topic of expanding your security training. In the additional posts, we’ll discuss formalizing requirements, reusing threat modeling and attack surface review data, the importance of final security reviews, and managing post-release documentation. All of these are components to “walking” with the SDL.<o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>Before I jump into detailing what you can do to “walk” with the SDL, let’s look back at a snapshot of what you should already have in place from learning to “crawl.” At a high level, crawling involved three components. Each of these components requires specific activities or tools that your team must implement to begin developing secure code: <o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoNoSpacing><SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><SPAN style="mso-list: Ignore"><FONT size=3 face=Calibri>1.</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3 face=Calibri>Detailed awareness of your architecture and its </FONT><A href="http://msdn2.microsoft.com/en-us/magazine/cc163882.aspx"><FONT color=#0000ff size=3 face=Calibri>attack surface</FONT></A><FONT size=3><FONT face=Calibri>.<o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level2 lfo1" class=MsoNoSpacing><SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><SPAN style="mso-list: Ignore"><FONT size=3 face=Calibri>a.</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Threat Modeling<o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoNoSpacing><SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><SPAN style="mso-list: Ignore"><FONT size=3 face=Calibri>2.</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Tools that will perform security analysis on your application.<o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level2 lfo1" class=MsoNoSpacing><SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><SPAN style="mso-list: Ignore"><FONT size=3 face=Calibri>a.</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Strengthen compiler defenses<o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level2 lfo1" class=MsoNoSpacing><SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><SPAN style="mso-list: Ignore"><FONT size=3 face=Calibri>b.</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Use code analysis or static analysis tools such as PREfast, FxCop, AppVerif<o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level2 lfo1" class=MsoNoSpacing><SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><SPAN style="mso-list: Ignore"><FONT size=3 face=Calibri>c.</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Build a strong fuzz testing capability<o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoNoSpacing><SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><SPAN style="mso-list: Ignore"><FONT size=3 face=Calibri>3.</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Results that show how the analysis resulted in improved security<o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level2 lfo1" class=MsoNoSpacing><SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><SPAN style="mso-list: Ignore"><FONT size=3 face=Calibri>a.</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Response planning and response process in place<o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level2 lfo1" class=MsoNoSpacing><SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><SPAN style="mso-list: Ignore"><FONT size=3 face=Calibri>b.</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Use bugs to gather evidence and show that your work improved security<o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 0pt 1in" class=MsoNoSpacing><o:p><FONT size=3 face=Calibri>&nbsp;</FONT></o:p></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>Think of these pieces as the “gross motor skills” you need to start walking. You should already be using these components and have reached a conscious decision to start building a lifecycle around your secure development practices. As you start figuring out how to “walk”, I want to point out that each of the concepts I discuss in this post is a <I style="mso-bidi-font-style: normal">critical</I> component of the Microsoft Security Development Lifecycle. Adopting the SDL in your company involves a combination of integrating the existing SDL principles and the creating of unique requirements and components specific to your environment to build your own Security Development Lifecycle. <o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>With that in place, let’s start talking about what it means to “Walk with SDL.”<o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><B style="mso-bidi-font-weight: normal"><FONT size=3><FONT face=Calibri>Obtain Management Approval/Endorsement<o:p></o:p></FONT></FONT></B></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>Creating a Security Development Lifecycle <I style="mso-bidi-font-style: normal">will</I> cost time and money. In addition, it will likely require some process changes. In most organizations, this change will not happen unless you obtain the management approval and endorsement necessary to compel the organization to act.<o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>The key to successfully pitching SDL to your management can be found in the data you have been accumulating during the “crawl” phase. As you may recall from my crawling post, the simplest way to create evidence that clearly illustrates improved application security is to “mine” the data from your bug database. Connecting those bugs to known security vulnerabilities or to what would have been bad security issues that were avoided by fixing them in development is a powerful story. Of course your pitch should include other necessary components like anticipated costs, new software acquisition, possible vendor and consulting contracts and anticipated return on investment. <o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>However, the heart of your argument will be the story <I style="mso-bidi-font-style: normal">you</I> tell. The story is quite simply “If we hadn’t done this basic work in security, here is what we would have missed and how much it would have hurt…” followed by “if we continue to expand our security practices and make them a part of our process, we can better predict measurable security improvements that reduce the likelihood of future risks.”<o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3 face=Calibri>The new SDL website [</FONT><A href="http://www.microsoft.com/sdl"><FONT color=#0000ff size=3 face=Calibri>http://www.microsoft.com/sdl</FONT></A><FONT size=3 face=Calibri>] provides some valuable reference material on the </FONT><A href="http://msdn.microsoft.com/en-us/security/cc420637.aspx"><FONT size=3 face=Calibri>Business Case for SDL</FONT></A><FONT size=3><FONT face=Calibri>. I would recommend that looking through that information for some good supporting material. In Part Two, I will discuss expanding your security training as another&nbsp;component of “walking” with SDL.</FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>&nbsp;<o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri><U>I’d like to hear if anyone is using the concept of “crawling” and “walking” to implement SDL in your company. </U><o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo2" class=MsoNoSpacing><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>?</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>What unique challenges are you facing as you try to push for SDL adoption? <o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo2" class=MsoNoSpacing><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>?</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>What have you used to successfully communicate the importance of security to your management?<o:p></o:p></FONT></FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8750221" width="1" height="1">]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 12:55:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/development">development</category>
      <category domain="http://securityratty.com/tag/secure development practices">secure development practices</category>
      <category domain="http://securityratty.com/tag/development culture">development culture</category>
      <category domain="http://securityratty.com/tag/security development practices">security development practices</category>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security practices">security practices</category>
      <category domain="http://securityratty.com/tag/perform security analysis">perform security analysis</category>
      <category domain="http://securityratty.com/tag/application security">application security</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/07/18/walking-with-the-sdl-part-1.aspx">"Walking" with the SDL - Part 1</source>
    </item>
    <item>
      <title><![CDATA[Homer Simpson and the Kimya Botnet]]></title>
      <link>http://securityratty.com/article/decf0db42925ceff37d1b75ae34d14df</link>
      <guid>http://securityratty.com/article/decf0db42925ceff37d1b75ae34d14df</guid>
      <description><![CDATA[Television often relies on fake codes, phone-numbers and addresses to make up part of their fictional worlds. Sometimes, it can go slightly wrong - how many people tried to call Doctor Who last week
...]]></description>
      <content:encoded><![CDATA[
        Television often relies on fake codes, phone-numbers and addresses to make up part of their fictional worlds. Sometimes, it can go slightly wrong - <i>how many</i> people tried to <a href="http://www.telegraph.co.uk/news/newstopics/celebritynews/2261219/Doctor-Who-phone-number-has-fans-in-frenzy.html">call Doctor Who</a> last week?<br /><br />D'oh.<br /><br />Actually, "D'oh" is rather appropriate here. In an old episode of The Simpsons, it was revealed that Chunkylover53@aol.com was Homers Email address. Of course, every Simpsons fan with net access immediately added Chunkylover53 to their AIM contact list. As <a href="http://snpp.com/guides/internet.html">this article</a> points out....<br /><br /><i>Homer's e-mail address chunkylover53@aol.com, as seen on EABF03, was registered by writer-producer Matt Selman, who also replied to e-mails from fans testing it. "He logged in the night that the episode aired and it was immediately filled with the maximum number of responses. He's tried to answer every one of them and then as soon as he answers a hundred, a hundred more pop in," Al Jean told the New York Post in January 2003.</i><br /><br />The "Chunkylover53" AIM screen-name hasn't logged in for quite some time, apparently. Imagine the puzzled expressions worn by Simpsons fans when, all of a sudden, the account came back to life in the last few days with this in their "Away" message....<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="kimya0.gif" src="http://blog.spywareguide.com/images/kimya0.gif" class="mt-image-none" style="" height="203" width="526" /></span>
<br /><br />...yes, "Homer" has seemingly returned, and he comes bearing infection files!<br /><br />Of course, the "exclusive Simpsons episode" is nothing of the kind - what you <i>actually</i> download is a file about 150kb in size, and it looks like this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="kimya1.jpg" src="http://blog.spywareguide.com/images/kimya1.jpg" class="mt-image-none" style="" height="65" width="63" /></span></div><br /><br />Run the file, and you won't see a new Simpsons episode - you're actually more likely to see this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="kimya2.jpg" src="http://blog.spywareguide.com/images/kimya2.jpg" class="mt-image-none" style="" height="124" width="305" /></span></div><br /><br /> <div>....a strange error message that mentions "photos" (probably fake), followed by lots of real error messages as most of your desktop fails, leaving you with an entirely blank screen:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="kimya3.jpg" src="http://blog.spywareguide.com/images/kimya3.jpg" class="mt-image-none" style="" height="141" width="217" /></span></div><br /></div><div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/kimya4.html" onclick="window.open('http://blog.spywareguide.com/images/kimya4.html','popup','width=736,height=531,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/kimya4-thumb-336x242.jpg" alt="kimya4.jpg" class="mt-image-none" style="" height="242" width="336" /></a></span></div><br /></div><div><div align="center">Click to Enlarge (if you really must!)<br /></div><br />From this point onwards, the PC will likely need a reboot and will be sluggish until cleaned up, constantly throwing out error messages, crashing when attempting to open Windows Explorer etc.<br /><br />Now, given that the infection links are being passed around via IM Away messages, there was always going to be the possibility of an Instant Messaging worm attack. However, a lot of testing has taken place and so far, we haven't seen any malicious messages or URLs sent via AIM or MSN Messenger.<br /><br />That's no reason to get complacent though, because what we have seen taking place is possibly quite a bit worse. First of all, a number of hidden files are dropped onto the PC, including Rootkit technology (which the bad guys have helpfully pointed out in the code):<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="rootkitkim.jpg" src="http://blog.spywareguide.com/images/rootkitkim.jpg" class="mt-image-none" style="" height="175" width="180" /></span></div><br /><br />Worse, your PC is deposited into a Botnet of Turkish origin - here's the giveaway traffic stream via an Ethereal log:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="kimyabots.gif" src="http://blog.spywareguide.com/images/kimyabots.gif" class="mt-image-none" style="" height="38" width="475" /></span></div><br /><br />....awaiting further instructions from the Botnet C&amp;C center. This particular Botnet has been around since March of this year. The Turkish connection is interesting, because I haven't seen too many Turkish Botnets - and there's been quite a surge in hacking activity from Turkey recently (most notably the <a href="http://www.channelregister.co.uk/2008/06/18/photobucket_dns_hack/">DNS attacks</a> on Photobucket and ICAAN by NeTDevilz).<br /><br />Finally, the infection drops a number of other files onto the PC besides the Rootkit, which are seemingly related to a new variant of <a href="http://www.spywareguide.com/product_show.php?id=5470">this Chinese infection</a>.<br /><br />It's worth noting that there may only be Instant Messaging infection links sent out if the person running the Botnet Command Center decides to issue all the drones with such a command - so while we haven't seen any IM infection activity, it would be wise not to rule it out completely. We recommend infected users keep an eye on all Instant Messaging activity until they can clean the infection from their computer, just in case.<br /><br />Whoever is responsible for these messages has changed them a couple of times already - last night, the download link had been updated to look like this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="kimya66.gif" src="http://blog.spywareguide.com/images/kimya66.gif" class="mt-image-none" style="" height="372" width="406" /></span></div><br /><br />...and it currently advertises a link for a dating website:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="chunkyaway.jpg" src="http://blog.spywareguide.com/images/chunkyaway.jpg" class="mt-image-none" style="" height="53" width="288" /></span></div><br /><br />We've reported all links related to this attack, and at least two of the files claiming to be "exclusive Simpsons episodes" are currently offline, though there's bound to be more out there. For now, this is a good reminder to be cautious when randomly adding cool things seen on TV and film to your online applications - you can't always assume the person at the other end is entirely in control.<br /><br />We detect this as <a href="http://www.spywareguide.com/spydet_31515_kimya.html">Kimya</a>.<br /><br />Additional Research: Chris Mannon, FSL Senior Threat Researcher<br />Deepak Setty, FSL Senior Threat Research Engineer<br /></div>
        
    ]]></content:encoded>
      <pubDate>Fri, 11 Jul 2008 13:46:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/simpsons">simpsons</category>
      <category domain="http://securityratty.com/tag/simpsons fan">simpsons fan</category>
      <category domain="http://securityratty.com/tag/simpsons fans">simpsons fans</category>
      <category domain="http://securityratty.com/tag/exclusive simpsons episode">exclusive simpsons episode</category>
      <category domain="http://securityratty.com/tag/infection">infection</category>
      <category domain="http://securityratty.com/tag/infection files">infection files</category>
      <category domain="http://securityratty.com/tag/real error messages">real error messages</category>
      <category domain="http://securityratty.com/tag/error messages">error messages</category>
      <category domain="http://securityratty.com/tag/infection activity">infection activity</category>
      <source url="http://blog.spywareguide.com/2008/07/who-hacked-homer.html">Homer Simpson and the Kimya Botnet</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Zen X-Fi, Apple iPod/iPhone Remote, Bullet Train-Fi, St. Louis-Fi]]></title>
      <link>http://securityratty.com/article/1d2b63469455e47a5cfcc67d96ede795</link>
      <guid>http://securityratty.com/article/1d2b63469455e47a5cfcc67d96ede795</guid>
      <description><![CDATA[Creative unveils ZEN X-Fi: The handheld music player, one of the first to have what appears to have real flair without being an iPod ripoff, can stream music from a local collection over Wi-Fi. It...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.electronista.com/articles/08/07/10/creative.zen.x.fi/"><strong>Creative unveils ZEN X-Fi:</strong></a> The handheld music player, one of the first to have what appears to have real flair without being an iPod ripoff, can stream music from a local collection over Wi-Fi. It also includes a Secure Digital slot, instant messaging (via Yahoo and MSN), an FM tuner, and a wide LCD scree. The unit is on sale in Singapore for about $170 for an 8GB model without Wi-Fi; a Wi-Fi-enabled model is $250 for $16 GB and $300 for 32 GB. They're due in the US "soon." </p>

<p><img src="http://wifinetnews.com//images/2008/remote_iphone_app.jpg" alt="remote_iphone_app.jpg" border="0" width="160" height="240" align="right" /><strong>iPhone, iPod touch now Wi-Fi remote control (see screen capture at right):</strong> The iPhone 2.0 software was soft released today, with a download available from Apple that's not yet being pushed via iTunes software when users' systems check for updates. The free Remote software, downloadable from the new App Store on the iPhone or Applications area in the iTunes Store, controls copies of iTunes on the local network once you've used a simple pairing technique. The same is true for the Apple TV with a free 2.1 software update for the digital box that's available now. (Also, you can snap screen shots in iPhone 2.0: Hold down the Home button and then press the top button. The capture is stored in your photo roll.)</p>

<p><a href="http://asiajin.com/blog/2008/06/28/japanese-super-train-shinkansen-with-full-wi-fi-between-tokyo-and-osaka/"><strong>Japanese bullet train gets Wi-Fi by next March:</strong></a> This was <a href="http://wifinetnews.com/archives/006718.html"><strong>first announced in 2006</strong></a>; it's still on track, pun intended. The line runs from Tokyo to Osaka.</p>

<p><a href="http://www.stltoday.com/pr/business/PR07090805321370"><strong>Network 1 expands its service St. Louis area:</strong></a> The company will offer service in 8 additional cities for a total of 15 in the St. Louis, Mo., area. The network provider is building out a neighborhood at a time using ostensibly commodity equipment. They charge $20 to $50 per month for service, and are focused on residential, rather than outdoor cloud access.</p>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 10:40:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/itunes software">itunes software</category>
      <category domain="http://securityratty.com/tag/iphone">iphone</category>
      <category domain="http://securityratty.com/tag/wi-fi remote control">wi-fi remote control</category>
      <category domain="http://securityratty.com/tag/free remote software">free remote software</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/itunes">itunes</category>
      <category domain="http://securityratty.com/tag/network provider">network provider</category>
      <source url="http://wifinetnews.com/archives/008390.html">Wee-Fi: Zen X-Fi, Apple iPod/iPhone Remote, Bullet Train-Fi, St. Louis-Fi</source>
    </item>
    <item>
      <title><![CDATA[CBAC & Medical Identity Theft]]></title>
      <link>http://securityratty.com/article/02105d066a63c57c66a00f92ef63e99d</link>
      <guid>http://securityratty.com/article/02105d066a63c57c66a00f92ef63e99d</guid>
      <description><![CDATA[Good story to keep in mind for those of you working on CBAC. Claims neeed protection and verification. Why steal an identity when you can capture a claim? (hattip: askelizabeth
The Sopranokovs
The...]]></description>
      <content:encoded><![CDATA[<p>Good story to keep in mind for those of you working on CBAC. Claims neeed protection and verification. Why steal an identity when you can capture a claim? (hattip: <a href="http://askelizabeth.typepad.com/weblog/2008/07/medical-identity-theft-the-new-frontier-for-organized-crime.html">askelizabeth</a>)

</p><blockquote><p>
	The Sopranokovs 
	</p></blockquote><blockquote><p>The Russian mob comes to town with a new scam—medical identity theft. 	
	</p></blockquote><blockquote><p>When FBI special agent Ted Price peered through the window of a dingy brick storefront on Southwest Morrison Street in March, it was what he didn’t see that caught his attention. 	</p></blockquote><blockquote><p>The business, called UnimedCorner, claimed to provide ailing seniors with orthotics—braces and other devices to correct foot, joint and back problems. 	
	</p></blockquote><blockquote><p>Price and other federal investigators were skeptical. 	
	</p></blockquote><blockquote><p>On Unimed’s showroom floor, Price saw wheelchairs, motorized scooters, a variety of canes and, on the walls, a selection of amateurish paintings and framed photographs. There was no evidence, however, of the kinds of equipment for which Unimed had billed Medicare nearly $2 million in the previous couple of months. 	
	</p></blockquote><blockquote><p>“I observed wheelchairs and canes through the window but did not see any orthotics in the store,” Price later wrote in a search-warrant affidavit. “It is a sign of fraud that the store is not stocking the items [for which] it is billing.” 	
	</p></blockquote><blockquote><p>By the time Price arrived on the scene, the company’s owner, a shadowy Russian immigrant named Alexandr Shcherbakov, was long gone. 	
	</p></blockquote><blockquote><p>Today, Shcherbakov’s store sits undisturbed. The message light on the phone blinks, dead potted plants droop and a stuffed toy monkey slumps in a glass display case. 	
	</p></blockquote><blockquote><p>And behind the cash register hangs a framed poster of television’s best-known mobsters, the Sopranos. 	
	</p></blockquote><blockquote><p>From interviews and information presented in federal affidavits, it is clear Shcherbakov moved to Oregon to commit a crime elegant and lucrative enough to make Tony Soprano envious: medical identity theft. 	
	</p></blockquote><blockquote><p>... 	
	</p></blockquote><blockquote><p>“Medical identity theft is the new frontier for organized crime,” says Alex Johnson, a former FBI agent who investigates fraud for Regence BlueShield. “Pretty much anybody can set up a mom-and-pop operation and start cranking out claims.”
	
	Someday, most Americans will need a cane, wheelchair, home hospital bed or another of the items healthcare professionals call “durable medical equipment,” or DME. 	
	</p></blockquote><blockquote><p>For those over 64 and without private insurance, there’s a good chance federally funded Medicare will pick up the tab for that equipment. Last year, according to federal statistics, Medicare spent $8.6 billion on DME. 	
	</p></blockquote><blockquote><p>Here’s the way the system is supposed to work: A doctor prescribes a device such as a wheelchair for a patient, who presents his prescription to a DME supplier. The supplier provides the equipment and bills Medicare, which typically pays 80 percent of the cost.
	
	Unlike pharmacists, who fill prescriptions under strict scrutiny of state and federal watchdogs, DME suppliers are lightly regulated.
	
	“DME is very vulnerable to fraud,” says Consuelo Woodhead, the chief healthcare fraud prosecutor for the U.S. Attorney’s Office in Los Angeles. “It doesn’t require any background in medicine, any kind of professional licensure or appreciable capital. </p></blockquote><blockquote><p>There are barriers of entry in other medical fields, but not in DME.”
	
	To operate, DME suppliers simply need a place of business, a business license and liability insurance. Unlike pharmacists, DME suppliers operate under an honor system: The feds count on them to supply the equipment they claim to provide to the beneficiaries who need it. 	
	</p></blockquote><blockquote><p>That honor system is not working. 	
	</p></blockquote><blockquote><p>The epicenter of DME fraud, according to the federal Department of Health and Human Services, is South Florida, where Medicare billing for DME quadrupled from 2002 to 2006 to $1.7 billion.
	
	Investigators found much of that increase was due to fraud. In 2006, federal inspectors revoked the licenses of 634 DME suppliers in South Florida, nearly half the DME dealers in the region. </p></blockquote><blockquote><p>Later the same year, raids in Southern California yielded similar results: The feds shut down 95 DME suppliers.
	
	Many of the DME suppliers shut down around Los Angeles were run by immigrants from the former Soviet Union. It’s probably no coincidence that when the feds raided Los Angeles DME suppliers, some Angelenos fled to cities where there was less scrutiny—such as Portland.</p></blockquote>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 06:09:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dme suppliers simply">dme suppliers simply</category>
      <category domain="http://securityratty.com/tag/dme suppliers">dme suppliers</category>
      <category domain="http://securityratty.com/tag/dme fraud">dme fraud</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/dme">dme</category>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/medical identity theft">medical identity theft</category>
      <category domain="http://securityratty.com/tag/dme dealers">dme dealers</category>
      <category domain="http://securityratty.com/tag/dme supplier">dme supplier</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/cbac-medical-identity-theft.html">CBAC &amp; Medical Identity Theft</source>
    </item>
    <item>
      <title><![CDATA[A Blast from the Past: Processing Patterns for Predictive Business, March 2006]]></title>
      <link>http://securityratty.com/article/82a7aa9e17030f2308e03502a40f3bef</link>
      <guid>http://securityratty.com/article/82a7aa9e17030f2308e03502a40f3bef</guid>
      <description><![CDATA[Forreaders interested in complex event processing and a few of the challenges the industry faces, here is a presentation from 28 months back called Processing Patterns for Predictive Business . This...]]></description>
      <content:encoded><![CDATA[<p>For readers interested in complex event processing and a few of the challenges the industry faces, here is a presentation from 28 months back called <a href="http://http://www.complexevents.com/slides/TIBCO_MARCH_2006.ppt" target="_blank">Processing Patterns for Predictive Business</a>.   This presentation was delivered at the first <a title="Workshop on Event Processing - Presentations" rel="bookmark" href="http://complexevents.com/?page_id=87">Workshop on Event Processing - Presentations</a> at IBM Research Labs, Yorktown Heights, March 14-16th 2006.</p>
<p>The same key points of that presentation are still relevant today:</p>
<p><strong><em>1. Event-Decision Processing is Computationally Intensive</em></strong></p>
<p><em><strong>2. CEP requires a Number of Technologies</strong></em>:</p>
<ul>
<li>Distributed Computing, Publish/Subscribe and SOA</li>
<li>Hierarchical, Cooperative Inference Processing</li>
<li>High Speed, Real Time Processing with State Management</li>
<li>Event-Decision Architecture for Complex Situations and Events</li>
<li>There is no single “CEP Solution” or “CEP Product” <em>(in the market place then, and today)</em></li>
</ul>
<p><em><strong>3. CEP needs a Common Vocabulary and Functional Architecture based on Mature, Industry-Standard Inference Models</strong></em></p>
<p><em><strong>4. Processing and Integration Patterns for CEP need to be Developed and Formalized</strong></em></p>
<p>Since March of 2006 a number of other challenges has surfaced.  I will elaborate on this challenges in a future post.</p>
]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 03:22:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event-decision architecture">event-decision architecture</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/event-decision">event-decision</category>
      <category domain="http://securityratty.com/tag/cep requires">cep requires</category>
      <category domain="http://securityratty.com/tag/cep product">cep product</category>
      <category domain="http://securityratty.com/tag/patterns">patterns</category>
      <category domain="http://securityratty.com/tag/march">march</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <source url="http://www.thecepblog.com/2008/07/09/a-blast-from-the-past-processing-patterns-for-predictive-business-march-2006/">A Blast from the Past: Processing Patterns for Predictive Business, March 2006</source>
    </item>
    <item>
      <title><![CDATA[A Blast from the Past: CEP at Stanford,1998-2003]]></title>
      <link>http://securityratty.com/article/ecd27eebd62b2df7d9e99b1fcf7ac96f</link>
      <guid>http://securityratty.com/article/ecd27eebd62b2df7d9e99b1fcf7ac96f</guid>
      <description><![CDATA[Courtesy of Complex Event Processing at Stanford
Complex event processing (CEP) is a new technology. It can be applied to extracting and analyzing information from any kind of distributed...]]></description>
      <content:encoded><![CDATA[<p>Courtesy of <a href="http://pavg.stanford.edu/cep/" target="_blank">Complex Event Processing at Stanford</a></p>
<p>Complex event processing (CEP) is a new technology. It can be applied to extracting and analyzing information from any kind of distributed message-based system. It is developed from the Rapide concepts of (1) causal event modeling, (2) event patterns and pattern matching, and (3) event pattern maps and constraints. Complex event processing can be applied to a wide variety of Enterprise monitoring and management problems, from low level network management to high level enterprise intelligence gathering.</p>
<h2>Applications of Complex Event Processing:</h2>
<ul>
<li><strong><a href="http://pavg.stanford.edu/cep/enterprise-viewing.html">Instant Insight</a></strong>  - hierarchical event viewing applied to the Enterprise IT layer. (coming soon)
<ul>
<li><a href="http://pavg.stanford.edu/cep/instantinsightpaper.pdf">Analysing business processes</a> (paper in pdf format)</li>
</ul>
</li>
<li><a href="http://pavg.stanford.edu/cep/netviewer-presentation.ppt">Network Level Monitoring and Management (Powerpoint presentation)</a></li>
<li><a href="http://pavg.stanford.edu/ID/">Cyber Security: Network Intrusion Detection</a></li>
<li>Enterprise Monitoring and Management (coming soon)</li>
<li><a href="http://pavg.stanford.edu/cep/final-version-131102.pdf">Modeling and Simulation of Collaborative Business Processes </a></li>
<li>Business Policy Monitoring. (coming soon)</li>
<li>Analysis and Debugging of Distributed Systems (coming soon)</li>
</ul>
<h2>Presentations:</h2>
<ul>
<li><a href="http://pavg.stanford.edu/cep/ee380abstract.html">&#8220;Complex Event Processing: An Essential Technology for Instant Insight into the Operation of Enterprise Information Systems,&#8221; </a>lecture at the Stanford University Computer Systems Laborary EE380 Colloquium series. <a href="http://stanford-online.stanford.edu/courses/ee380/030115-ee380-100.asx">Video of the lecture (duration: 60 minutes). </a></li>
</ul>
<h2>Publications:</h2>
<ul>
<li><em><a href="http://pavg.stanford.edu/cep/fabline.ps">Complex Event Processing in Distributed Systems.</a></em> David C. Luckham and Brian Frasca, Stanford University Technical Report CSL-TR-98-754, March 1998, 28 pages.<em>Abstract:</em> Complex event processing is a new technology for extracting information from distributed message-based systems. This technology allows users of a system to specify the information that is of interest to them. It can be low level network processing data or high level enterprise management intelligence, depending upon the role and viewpoint of individual users. And it can be changed from moment to moment while the target system is in operation. This paper presents an overview of Complex Event Processing applied to a particular example of a distributed message-based system, a fabrication process management system. The concepts of causal event histories, event patterns, event filtering, and event aggregation are introduced and their application to the process management system is illustrated by simple examples. This paper gives the reader an overview of Complex Event Processing concepts and illustrates how they can be applied using the Rapide toolset to one specific kind of system.<br />
 </li>
<li><em><a href="http://pavg.stanford.edu/cep/99pakdd.ps">Event Mining with Event Processing Networks.</a></em> Louis Perrochon and Walter Mann and Stephane Kasriel and David C. Luckham, The Third Pacific-Asia Conference on Knowledge Discovery and Data Mining. April 26-28, 1999. Beijing, China, 5 pages.<em>Abstract:</em> Event Mining discovers and delivers information and knowledge in a real-time stream of data, or events. We show that the process of delivering knowledge by searching patterns in data and subsequent abstraction of found patterns can be applied in real-time to a complex, asynchronous system. Our event processing engine consists of a network of event processing agents (EPAs) running in parallel that interact using a dedicated event processing infrastructure. The agents can be configured at run-time using a formal pattern language. The underlying infrastructure (1) provides an abstract communication mechanism and thus allows dynamic reconfiguration of the communication topology between agents at run-time and (2) provides transparent, location-independent access to all data. These features allow dynamic allocation of EPAs to different threads and processes on different machines at run time.<br />
 </li>
<li><em><a href="http://pavg.stanford.edu/people/santoro/distrib/ejava.ps">eJava - Extending Java with Causality</a></em>. Alexandre Santoro and Walter Mann and Neel Madhav and David Luckham, Proceedings of the 10th International Conference on Software Engineering and Knowledge Engineering, June 1998, 10 pages.<em>Abstract:</em> Programming languages like Java provide designers with a variety of classes that simplify the process of program development. Some of these classes allow one to easily build multithreaded programs. Though useful, especially in the creation of reactive systems, multithreaded programs present challenging problems such as race conditions and synchronization issues. Validating these programs against a specification is not trivial since Java does not clearly indicate thread interaction. These problems can be solved by modifying Java so that it produces computations, collections of events with both causal and temporal ordering relations defined for them. Specifically, the causal ordering is ideal for identifying thread interaction. This paper presents eJava, an extension to Java that is both event based and causally aware, and shows how it simplifies the process of understanding and debugging multithreaded programs.<br />
 </li>
<li><a href="http://pavg.stanford.edu/cep/99wicsa1.ps.gz">Event-Based Execution Architectures for Dynamic Software Systems</a>. James Vera, Louis Perrochon, David C. Luckham.<br />
Proceedings of the First Working IFIP Conf. on Software Architecture. 1999. San Antonio, Texas.<em>Abstract:</em> Distributed systems&#8217; runtime behavior can be difficult to understand. Concurrent, distributed activity make notions of global state difficult to grasp. We focus on the runtime structure of a system, its execution architecture, and propose representing its evolution as a partially ordered set of predefined architectural event types. This representation allows a system&#8217;s topology to be visualized, analyzed and con-strained. The use of a predefined event types allows the execution architectures of different systems to be readily compared.<br />
 </li>
<li><em><a href="http://pavg.stanford.edu/cep/cidf.ps.gz">Using Context-Based Correlation in Network Operations and Management</a></em>. Louis Perrochon (work in progress, mail author for newest version)<em>Abstract:</em> Network operation consists to a large degree of reaction to activities happening in the network. Better knowledge of the network at any time allows more appropriate reactions. On the example of intrusion detection, we show how context-based correlation of such activities can provide a more detailed view of the network in shorter time. We first present how we model context and then describe the architecture of the Stanford University CEP context-based correlator. Correlation is specified as event patterns in a declarative language that allows us to specify what needs to be detected, instead of specifying how it should be detected. CEP introduces the concept of causal context to intrusion detection. The correlator is able to process events on-line, as they are generated and it can be reconfigured at dynamically. We then show how it increases detection rate, reduce false alarms, and detect large-scale attack patterns at an early stage.</li>
</ul>
]]></content:encoded>
      <pubDate>Mon, 07 Jul 2008 15:20:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/architectural event types">architectural event types</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/event pattern maps">event pattern maps</category>
      <category domain="http://securityratty.com/tag/event types">event types</category>
      <category domain="http://securityratty.com/tag/event aggregation">event aggregation</category>
      <category domain="http://securityratty.com/tag/event patterns">event patterns</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/event based">event based</category>
      <category domain="http://securityratty.com/tag/hierarchical event">hierarchical event</category>
      <source url="http://www.thecepblog.com/2008/07/07/a-blast-from-the-past-cep-at-stanford1998-2003/">A Blast from the Past: CEP at Stanford,1998-2003</source>
    </item>
  </channel>
</rss>
