<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: packet]]></title>
    <link>http://securityratty.com/tag/packet</link>
    <description></description>
    <pubDate>Mon, 30 Jun 2008 00:01:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[EstDomains & Intercage: A Perfect Couple in Crime]]></title>
      <link>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</link>
      <guid>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</guid>
      <description><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's take on the...]]></description>
      <content:encoded><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's <a href="http://www.google.com/search?hl=en&q=site%3Asunbeltblog.blogspot.com+estdomains+atrivo+intercage&btnG=Search" target="_blank">take</a> on the topic, or <a href="http://www.emergingthreats.net/index.php?searchword=intercage&option=com_search&Itemid=5" target="_blank">search</a> Emergingthreats to come up to speed.<br />Yesterday, EstDomains posted the most inept, ridiculous <a href="http://www.domainnews.com/en/general/estdomains-denies-links-to-malware-distribution.html" target="_blank">response</a> ever issued to the endless and worthy criticism, largely <a href="http://technewsreview.com.au/article.php?article=5882" target="_blank">leveled</a> by Brian Krebs at the Washington Post. <br />Not only can't these morons from EstDomains write, they're either so deeply clueless or flagrantly malicious (likely both), it's beyond laughable. This section sums it up best:<br /><span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality. But the outstanding performance of hosting services is not the sole reason why EstDomains, Inc appreciates this partnership so greatly. Intercage, Inc generously provides EstDomains, Inc specialists with reports regarding discovered malware vehicles. As the main database for additional domain name management services is located in Intercage Data Center, EstDomains, Inc has the perfect opportunity to get notifications of the slightest mark of malware presence in the shortest time and take measures in advance."</span><br /><span style="font-weight:bold;">What? Really?</span> <br />Again, aside from the absolute butchery of the language, did they just say <span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality."</span>? SIGH...yes, they did.<br /><br />Allow me to exemplify just how ridiculous a claim that is.<br />Following is content from a packet capture I took during a recent Storm worm analysis.<br /><br />Using the ip2asn module included in <a href="http://writequit.org/projects/nsm-console/" target="_blank">NSM-console</a> availabe in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we find:<br />27595   | 216.255.189.211  | INTERCAGE - InterCage, Inc.<br /><br />Using Etherape, also included in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s1600-h/etherape_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s320/etherape_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246478966559532178" /></a><br /><br />Using <a href="http://networkminer.wiki.sourceforge.net/NetworkMiner" target="_blank">Eric Hjelmvik's</a> <a href="http://holisticinfosec.org/toolsmith/docs/august2008.pdf" target="_blank">NetworkMiner</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s1600-h/NetworMiner_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s320/NetworMiner_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246480419744190626" /></a><br /><br />See the recurring theme? Intercage, EstDomain's <span style="font-style:italic;">"reliable ally in its battle against malware"</span>.<br />Nice work, guys...keep it up.<br /><br />I'm submitting this to <a href="http://thedailywtf.com/" target="blank">The Daily WTF</a> as we speak.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html&title=EstDomains%20&%20Intercage:%20A%20Perfect%20Couple%20in%20Crime " title="EstDomains & Intercage: A Perfect Couple in Crime ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html" title="EstDomains & Intercage: A Perfect Couple in Crime ">digg</a>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 17:32:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/intercage">intercage</category>
      <category domain="http://securityratty.com/tag/estdomains">estdomains</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware presence">malware presence</category>
      <category domain="http://securityratty.com/tag/intercage data center">intercage data center</category>
      <category domain="http://securityratty.com/tag/track malware issues">track malware issues</category>
      <category domain="http://securityratty.com/tag/reliable ally">reliable ally</category>
      <category domain="http://securityratty.com/tag/management services">management services</category>
      <category domain="http://securityratty.com/tag/malware vehicles">malware vehicles</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html">EstDomains &amp; Intercage: A Perfect Couple in Crime</source>
    </item>
    <item>
      <title><![CDATA[Berkeley Packet Filters - The Basics]]></title>
      <link>http://securityratty.com/article/31f2e882cc533292f03b0fe98ceb4c67</link>
      <guid>http://securityratty.com/article/31f2e882cc533292f03b0fe98ceb4c67</guid>
      <description><![CDATA[Jeff Stebelton submits this paper on BPF's and a detailed outline of what they are and what they...]]></description>
      <content:encoded><![CDATA[Jeff Stebelton submits this paper on BPF's and a detailed outline of what they are and what they do.]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/jeff stebelton submits">jeff stebelton submits</category>
      <category domain="http://securityratty.com/tag/bpf">bpf</category>
      <category domain="http://securityratty.com/tag/outline">outline</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <source url="http://www.infosecwriters.com/texts.php?op=display&amp;id=631">Berkeley Packet Filters - The Basics</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.1.08]]></title>
      <link>http://securityratty.com/article/bbf15fbdceab01591b641bee93ce7efb</link>
      <guid>http://securityratty.com/article/bbf15fbdceab01591b641bee93ce7efb</guid>
      <description><![CDATA[The Yankee Group had this not-so-urgent advice for IPv6 visibility . It may be time to ask your network monitoring and management software vendors about their plans for IPv6 visibility. Although were...]]></description>
      <content:encoded><![CDATA[<p>The Yankee Group had this not-so-urgent advice for <a href="http://searchnetworking.techtarget.com/news/article/0,289142,sid7_gci1323274,00.html" target="_blank">IPv6 visibility</a>. “It may be time to ask your network monitoring and management software vendors about their plans for IPv6 visibility.” Although we’re still a few years away from broad adoption of IPv6 in the US, experts have been urging enterprises to pave the way for a smooth migration now by having IPv6-ready infrastructure in place…
<p>I’ll take your 6 centers of excellence and uh, raise you 2 data centers. Following up on the HP announcement that they’ve partnered with Yahoo and Intel to create <a href="http://www.techcrunch.com/2008/07/29/hp-yahoo-intel-announce-cloud-computing-research-initiative/" target="_blank">cloud computing Centers of Excellence</a> this week, IBM said they were building out <a href="http://online.wsj.com/article/BT-CO-20080801-700024.html?mod=djempersonal" target="_blank">2 data centers</a> to accommodate the coming cloud computing resources need. I should say that <a href="http://blogs.zdnet.com/BTL/?p=8694" target="_blank">IBM</a> had already announced their “partnership” with Google to provide services for the cloud back in May. Who’s left to partner with on cloud computing? <a href="http://arstechnica.com/news.ars/post/20080729-microsoft-bets-on-cloud-computing-as-amazon-suffers-outage.html" target="_blank">Microsoft and Amazon</a>?
<p>Packet Trap Networks recently conducted a survey of network engineers and <a href="http://www.packettrap.com/blog/index.php/network-management-systems-market/#comment-568" target="_blank">IT professionals who perform network management duties inside companies with more than 100 employees</a>. Out of the 800 engineers surveyed, 49 percent stated that they did not have a comprehensive network management system in place – showing a need for solutions focused on the mid-market – i.e., the right features at reasonable prices. If you remember, <a href="http://www.networkworld.com/community/node/28639" target="_blank">Sevcik and Wetzel</a> (not a vendor!) conducted their own survey on application performance management and had similar findings but a rather different answer… (hint – starts with “E” and ends in “7”)
<p><a href="http://news.cnet.com/8301-12640_3-9999878-91.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" target="_blank">Is open-source software more secure</a>? After all thousands of eyes are better than a handful, right? Well, according to a report sponsored by <a href="http://www.fortify.com/news-events/releases/2008/2008-07-21.jsp" target="_blank">Fortify Software</a>, that’s just not the case. <a href="http://blogs.zdnet.com/security/?p=1623" target="_blank">Roger Thornton, founder and CTO of Fortify Software</a>, adds that the underlying problem is “a lack of understanding and collaboration between developers and security experts – today each are talking past each other when it comes to security.”
<p>For all you aspiring CIOs out there, WSJ has provided a <a href="http://blogs.wsj.com/biztech/2008/07/31/a-reading-list-for-tech-leaders/?mod=djemTECH" target="_blank">must-read list</a>. Uh oh– the first on the list is “How to Read a Book”. Please, any negative comments directly on the Journal site…and any “good” ones here!</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Links+List+8.1.08&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Flinks-list-8108%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 17:37:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/management software vendors">management software vendors</category>
      <category domain="http://securityratty.com/tag/ipv6 visibility">ipv6 visibility</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/data centers">data centers</category>
      <category domain="http://securityratty.com/tag/centers">centers</category>
      <category domain="http://securityratty.com/tag/network engineers">network engineers</category>
      <category domain="http://securityratty.com/tag/open-source software">open-source software</category>
      <source url="http://blog.sciencelogic.com/links-list-8108/08/2008">Links List 8.1.08</source>
    </item>
    <item>
      <title><![CDATA[Security Through Visibility - Montego, Lancope and NetFlow]]></title>
      <link>http://securityratty.com/article/03c1f11d6787944e11b9ab1baec0352e</link>
      <guid>http://securityratty.com/article/03c1f11d6787944e11b9ab1baec0352e</guid>
      <description><![CDATA[We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments. This is because it is extremely challenging to see...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments.&nbsp; This is because it is extremely challenging to see what is going on at a micro vs. macro level within a virtual environments network.&nbsp; The virtualization vendors such as VMWare and Citrix have provided embedded tools into their management consoles that show a macro level of visibility but its not enough to identify security events in the environment.&nbsp; Take a look at the attached picture.&nbsp; It simply shows VMWare's ability to monitor virtual network performance statistics from a bits per second perspective.</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/performancescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Performancescreen" title="Performancescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/performancescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
<br />&lt;-Click To Enlarge</p>

<p>With only this level of detail how can one determine which network applications are causing spikes.&nbsp; Is it FTP traffic that is occuring at a high volume at an unuseal time of day?&nbsp; If that were occuring, could that be indicative of either a breach or some sort of problem? What if FTP isn't even an authorized service in the virtual environment but there is a high volume of it?&nbsp; Did someone install a rouge FTP service so they could steal information from the server at will? </p>

<p>These types of questions can't really be answered without a micro level of detail into the packets flowing in, out and within the virtual environment.&nbsp; Now, what I am highlighting is not security in the traditional sense of prevention but using visibility as a means to first identify, then pin point the source of an issue so that it can properly be mitigated.&nbsp; Having constant visibility can also ensure that other security products in the environment are performing as expected.&nbsp; What if a Montego HyperSwitch with firewalling enabled is configured with many policies but someone forgot to create an FTP block policy.&nbsp; One could think they are protected from rouge FTP services transmiting data out of the network, but without constant visibility monitoring, can you be certain?</p>

<p>Some vendors, namely Reflex Security will get you to believe that their IPS / IDS solution that is inline and running in the virtual environment is the right and only approach.&nbsp; Or they will tell you to hang a virtual IDS off a span port in the virtual environment and you will at least have visibility into the attacks that are taking place.&nbsp; Well, sure... You now have attack visibility but at the performance cost of your virtual environment.&nbsp; Signature matching technologies are great, I'm a huge believer; however they don't scale very well in shared computing environments such as virtual ones.&nbsp; IDS systems also don't typically track protocol and network service (FTP, HTTP, etc.) utilizations; which is another important part of visibility.</p>

<p>So, what do we do to gain visibility without the performance headache?&nbsp; Well, for starters its probably best to put your IDS/IPS solutions in the physical environment where performance will be less of a concern.&nbsp; In fact, you can span a virtual switch's traffic out to a physical NIC as easy as you can to a virtual one.&nbsp; So why do it virtual and have to pay a 60% CPU utilization tax?&nbsp; Another solution is to IDS inspect only the things you care about.&nbsp; Why IDS inspect SSL traffic if you know your solution can't unencrypt SSL.&nbsp; Its just a waste of compute cycles isnt it?&nbsp; Policy based switching helps you with directing only the things you care about to an IDS (attack visualization product).&nbsp; Montego's HyperSwitch also can help you with the traffic redirection of only the things you care about. </p>

<p>Another method of visibility which I tend to be a fan of is one of packet analysis (aka NetFlow).&nbsp; NetFlow was invented by Cisco some time ago and has gained popularity in the physical world and definately has a use in the virtual world.&nbsp; NetFlow is lightweight.&nbsp; Let me say that again, its light weight!&nbsp; It only sends a summation of packet detail to an analytical engine which can do some number crunching, packet comparison, etc. etc. to make some sense out of whats going on.&nbsp; <a href="http://www.lancope.com">Lancope</a>, an Atlanta based visibility company that provides Network Visibility, Security Visibility and User Visibility has this tool on their website that is a Netflow Bandwidth calculator.&nbsp; You'll see from playing with this ( <a href="http://www.lancope.com/netflowcalculator.aspx">http://www.lancope.com/netflowcalculator.aspx</a> ) calculator that it doesn't consume a lot of network bandwidth to transmit these network accounting records.&nbsp; It also doesn't cause a lot of CPU overhead to send these records to an analytical engine sitting somewhere in the network.</p>

<p>Lancope's analytical engines have the ability to do the following for you within your virtual environment:</p><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta name="ProgId" content="PowerPoint.Slide" /><meta name="Generator" content="Microsoft PowerPoint 11" /><title><p>&lt;p&gt;Slide 3&lt;/p&gt;</p></title><meta name="Description" content="7/30/2008" /><style>
.O
	{color:black;
	font-size:149%;}
a:link
	{color:#CC9900 !important;}
a:active
	{color:#9B2D1F !important;}
a:visited
	{color:#96A9A9 !important;}
</style><style media="print">
&amp;lt;!--.sld
	{left:0px !important;
	width:6.0in !important;
	height:4.5in !important;
	font-size:103% !important;}
--&amp;gt;
</style><o:shapelayout v:ext="edit"></o:shapelayout><o:idmap v:ext="edit" data="1"></o:idmap><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9">&nbsp;</p:colorscheme><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9"><div v:shape="_x0000_s1026" class="O">

<ol><li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert network behavior of VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Track Vmotion movement of VMs accross physical servers</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert on communication between VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify users accessing VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify unauthorized or rouge VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert when VM’s go online or offline
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify network services running on VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor Network / Application performance of VMs<br />Display active hosts accessing VMs</span></li></ol>















<div></div>

</div>

</p:colorscheme><p>...and probably a slew of other things I'm not aware of.&nbsp; A screen shot of their product is bellow:</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/lancopescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Lancopescreen" title="Lancopescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/lancopescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a> &lt;- Click to enlarge</p>

<p>You'll notice from the screenshot that you are able to visualize who is talking to who, how much traffic they have sent and received and something called a concern index (not seen on this screenshot).</p>

<p>Now, a concern index is a number that increases as Lancopes analytical engines monitor suspicious activity on a session.&nbsp; A high counter can be indicative of a security problem.&nbsp; Its another way of identifying (visualizing) compromised hosts (virtual machines) without having to do signature matching like a heavy weight IPS engine.&nbsp; Example:&nbsp; Lets say you have a VM that has a BOT on it and is &quot;owned&quot;.&nbsp; The Lancope product is monitoring this long life session.&nbsp; Let's say that session is established for several hours or maybe even days or months.&nbsp; Lets also say that the conversation appears to be mostly unidirectional from a public ip address not belonging to your enterprise.&nbsp; Lancope would increase a the concern index on this since this server hasn't typically had this type of behavior.&nbsp; Once the concern index reached a certain level it could then fire off an email, send you a text message or something saying:&nbsp; <strong>Warning, Warning, Danger, Danger Will Robinson!!! You're virtual server may be infected with a BOT, please investigate immediately!!!</strong></p>

<p>This example is VISIBILITY which helps you with SECURITY.&nbsp; There are a number of other things you can do with NetFlow and Lancope products that have less to do with security and more to do with operational efficiencies.&nbsp; Things like, helping you answer questions of:&nbsp; How do I know what network applications are taking up the most bandwidth?&nbsp; When should I move those applications over to a server with more horsepower?&nbsp; When did these VM's vmotion over here and was there a traffic condition / CPU condition that caused that to occur?&nbsp; I could go on and on but thats a topic for another blog entry.</p>

<p>So, my suggestion is to take a look at what NetFlow has to offer.&nbsp; Montego Networks supports NetFlow transmission and Lancope supports NetFlow analytics and with both you can regain what was lost visibility.</p>

<p>I hope this was helpful to you all!</p>

<p>-John Peterson</p></div>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 17:57:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network visibility">network visibility</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/environments">environments</category>
      <category domain="http://securityratty.com/tag/virtual environments network">virtual environments network</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/network bandwidth">network bandwidth</category>
      <category domain="http://securityratty.com/tag/bandwidth">bandwidth</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/350982407/security-throug.html">Security Through Visibility - Montego, Lancope and NetFlow</source>
    </item>
    <item>
      <title><![CDATA[Security Through Visibility - Montego, Lancope and NetFlow]]></title>
      <link>http://securityratty.com/article/5b6ed1101dc183f8ebcfa1e481566982</link>
      <guid>http://securityratty.com/article/5b6ed1101dc183f8ebcfa1e481566982</guid>
      <description><![CDATA[We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments. This is because it is extremely challenging to see...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments.&nbsp; This is because it is extremely challenging to see what is going on at a micro vs. macro level within a virtual environments network.&nbsp; The virtualization vendors such as VMWare and Citrix have provided embedded tools into their management consoles that show a macro level of visibility but its not enough to identify security events in the environment.&nbsp; Take a look at the attached picture.&nbsp; It simply shows VMWare's ability to monitor virtual network performance statistics from a bits per second perspective.</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/performancescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Performancescreen" title="Performancescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/performancescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
<br />&lt;-Click To Enlarge</p>

<p>With only this level of detail how can one determine which network applications are causing spikes.&nbsp; Is it FTP traffic that is occuring at a high volume at an unuseal time of day?&nbsp; If that were occuring, could that be indicative of either a breach or some sort of problem? What if FTP isn't even an authorized service in the virtual environment but there is a high volume of it?&nbsp; Did someone install a rouge FTP service so they could steal information from the server at will? </p>

<p>These types of questions can't really be answered without a micro level of detail into the packets flowing in, out and within the virtual environment.&nbsp; Now, what I am highlighting is not security in the traditional sense of prevention but using visibility as a means to first identify, then pin point the source of an issue so that it can properly be mitigated.&nbsp; Having constant visibility can also ensure that other security products in the environment are performing as expected.&nbsp; What if a Montego HyperSwitch with firewalling enabled is configured with many policies but someone forgot to create an FTP block policy.&nbsp; One could think they are protected from rouge FTP services transmiting data out of the network, but without constant visibility monitoring, can you be certain?</p>

<p>Some vendors, namely Reflex Security will get you to believe that their IPS / IDS solution that is inline and running in the virtual environment is the right and only approach.&nbsp; Or they will tell you to hang a virtual IDS off a span port in the virtual environment and you will at least have visibility into the attacks that are taking place.&nbsp; Well, sure... You now have attack visibility but at the performance cost of your virtual environment.&nbsp; Signature matching technologies are great, I'm a huge believer; however they don't scale very well in shared computing environments such as virtual ones.&nbsp; IDS systems also don't typically track protocol and network service (FTP, HTTP, etc.) utilizations; which is another important part of visibility.</p>

<p>So, what do we do to gain visibility without the performance headache?&nbsp; Well, for starters its probably best to put your IDS/IPS solutions in the physical environment where performance will be less of a concern.&nbsp; In fact, you can span a virtual switch's traffic out to a physical NIC as easy as you can to a virtual one.&nbsp; So why do it virtual and have to pay a 60% CPU utilization tax?&nbsp; Another solution is to IDS inspect only the things you care about.&nbsp; Why IDS inspect SSL traffic if you know your solution can't unencrypt SSL.&nbsp; Its just a waste of compute cycles isnt it?&nbsp; Policy based switching helps you with directing only the things you care about to an IDS (attack visualization product).&nbsp; Montego's HyperSwitch also can help you with the traffic redirection of only the things you care about. </p>

<p>Another method of visibility which I tend to be a fan of is one of packet analysis (aka NetFlow).&nbsp; NetFlow was invented by Cisco some time ago and has gained popularity in the physical world and definately has a use in the virtual world.&nbsp; NetFlow is lightweight.&nbsp; Let me say that again, its light weight!&nbsp; It only sends a summation of packet detail to an analytical engine which can do some number crunching, packet comparison, etc. etc. to make some sense out of whats going on.&nbsp; <a href="http://www.lancope.com">Lancope</a>, an Atlanta based visibility company that provides Network Visibility, Security Visibility and User Visibility has this tool on their website that is a Netflow Bandwidth calculator.&nbsp; You'll see from playing with this ( <a href="http://www.lancope.com/netflowcalculator.aspx">http://www.lancope.com/netflowcalculator.aspx</a> ) calculator that it doesn't consume a lot of network bandwidth to transmit these network accounting records.&nbsp; It also doesn't cause a lot of CPU overhead to send these records to an analytical engine sitting somewhere in the network.</p>

<p>Lancope's analytical engines have the ability to do the following for you within your virtual environment:</p><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta name="ProgId" content="PowerPoint.Slide" /><meta name="Generator" content="Microsoft PowerPoint 11" /><title><p>&lt;p&gt;Slide 3&lt;/p&gt;</p></title><meta name="Description" content="7/30/2008" /><style>
.O
	{color:black;
	font-size:149%;}
a:link
	{color:#CC9900 !important;}
a:active
	{color:#9B2D1F !important;}
a:visited
	{color:#96A9A9 !important;}
</style><style media="print">
&amp;lt;!--.sld
	{left:0px !important;
	width:6.0in !important;
	height:4.5in !important;
	font-size:103% !important;}
--&amp;gt;
</style><o:shapelayout v:ext="edit"></o:shapelayout><o:idmap v:ext="edit" data="1"></o:idmap><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9">&nbsp;</p:colorscheme><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9"><div v:shape="_x0000_s1026" class="O">

<ol><li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert network behavior of VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Track Vmotion movement of VMs accross physical servers</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert on communication between VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify users accessing VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify unauthorized or rouge VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert when VM???s go online or offline
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify network services running on VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor Network / Application performance of VMs<br />Display active hosts accessing VMs</span></li></ol>















<div></div>

</div>

</p:colorscheme><p>...and probably a slew of other things I'm not aware of.&nbsp; A screen shot of their product is bellow:</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/lancopescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Lancopescreen" title="Lancopescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/lancopescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a> &lt;- Click to enlarge</p>

<p>You'll notice from the screenshot that you are able to visualize who is talking to who, how much traffic they have sent and received and something called a concern index (not seen on this screenshot).</p>

<p>Now, a concern index is a number that increases as Lancopes analytical engines monitor suspicious activity on a session.&nbsp; A high counter can be indicative of a security problem.&nbsp; Its another way of identifying (visualizing) compromised hosts (virtual machines) without having to do signature matching like a heavy weight IPS engine.&nbsp; Example:&nbsp; Lets say you have a VM that has a BOT on it and is &quot;owned&quot;.&nbsp; The Lancope product is monitoring this long life session.&nbsp; Let's say that session is established for several hours or maybe even days or months.&nbsp; Lets also say that the conversation appears to be mostly unidirectional from a public ip address not belonging to your enterprise.&nbsp; Lancope would increase a the concern index on this since this server hasn't typically had this type of behavior.&nbsp; Once the concern index reached a certain level it could then fire off an email, send you a text message or something saying:&nbsp; <strong>Warning, Warning, Danger, Danger Will Robinson!!! You're virtual server may be infected with a BOT, please investigate immediately!!!</strong></p>

<p>This example is VISIBILITY which helps you with SECURITY.&nbsp; There are a number of other things you can do with NetFlow and Lancope products that have less to do with security and more to do with operational efficiencies.&nbsp; Things like, helping you answer questions of:&nbsp; How do I know what network applications are taking up the most bandwidth?&nbsp; When should I move those applications over to a server with more horsepower?&nbsp; When did these VM's vmotion over here and was there a traffic condition / CPU condition that caused that to occur?&nbsp; I could go on and on but thats a topic for another blog entry.</p>

<p>So, my suggestion is to take a look at what NetFlow has to offer.&nbsp; Montego Networks supports NetFlow transmission and Lancope supports NetFlow analytics and with both you can regain what was lost visibility.</p>

<p>I hope this was helpful to you all!</p>

<p>-John Peterson</p></div>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 17:57:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network visibility">network visibility</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/environments">environments</category>
      <category domain="http://securityratty.com/tag/virtual environments network">virtual environments network</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/network bandwidth">network bandwidth</category>
      <category domain="http://securityratty.com/tag/bandwidth">bandwidth</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <source url="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/07/security-throug.html">Security Through Visibility - Montego, Lancope and NetFlow</source>
    </item>
    <item>
      <title><![CDATA[(Not Really) Stateful IT-GRC Inspecting Threat Management At Gigabit Speeds]]></title>
      <link>http://securityratty.com/article/886052f98b89f3f82c4e060e06cc7f73</link>
      <guid>http://securityratty.com/article/886052f98b89f3f82c4e060e06cc7f73</guid>
      <description><![CDATA[A friend of the blog recently pointed me to an article that used the term
PCI Risk Management
Now usually when I see a term like this, I can only imagine that such things are the byproduct of rapidly...]]></description>
      <content:encoded><![CDATA[<p>A friend of the blog recently pointed me to an article that used the term:</p>
<p style="text-align: center;"><em><strong>&#8220;PCI Risk Management&#8221;</strong></em></p>
<p>Now usually when I see a term like this, I can only imagine that such things are the byproduct of rapidly decaying brain cells.  In my mind I imagine there&#8217;s a conference room somewhere with some marketing types all hopped up on the vapors from industrial solvents spewing terms like &#8220;protectivity&#8221; or &#8220;advanced adaptive deep packet inspection&#8221; into the ether with all the acumen of an intoxicated long-horned bovine.</p>
<p><em><strong>BUT</strong></em></p>
<p>I thought about this, and it&#8217;s really not a bad idea - depending on how you define it.  Now I just couldn&#8217;t make the effort to read how the author used the term (I have a short pain threshold), but here&#8217;s my thoughts on what PCI Risk Management should be.  If we define Risk as the probable frequency and probable magnitude of future loss.</p>
<p>Then managing the risk inherent in PCI DSS compliance could mean:</p>
<p><span style="color: #008000;"><strong>1.)  The expected frequency of being out of compliance and how much that will cost us.</strong></span></p>
<p>Because let&#8217;s face it - being in or out of PCI compliance is still a subjective judgment.  First, we have what our ever-qualified assessor says.  But in the case of an incident, it&#8217;s really someone else who has the final say in whether or not we were &#8220;compliant&#8221; at the time of incident.  So we can only know for certain if we&#8217;re in compliance after the fact - i.e. after there&#8217;s an incident.  So if we cannot really &#8220;know&#8221; if we&#8217;re compliant - we have a probability problem to solve!  Sounds like &#8220;risk&#8221; or &#8220;secure&#8221; doesn&#8217;t it?</p>
<p>So we could view the PCI as a threat community to deal with.  This gives us the first angle of what we could call PCIRM (this sort of term begs to be it&#8217;s own acronym, doesn&#8217;t it?) - the simple creation of a probability statement that says there is some belief that we could be found out of compliance - regardless of our efforts - and the calculation of what the impact would be to our organization (like defending frivolous 90 bajillion $ law suits from tiny financial institutions whose lawyers smell blood in the water).  Note that you may or may not want to add the value of the money and time spent on PCI compliance into your loss magnitude calculations.  It&#8217;s a sunk cost at that point.</p>
<p>However, there&#8217;s another side of the coin.  We can find out the risk of being out of compliance, but is there risk in being *in* compliance?  I think there is.  So our second aspect of PCI Risk Management might be:</p>
<p><span style="color: #008000;"><strong>2.)  The expected frequency of being in compliance and how much that will cost us.</strong></span></p>
<p>An alternate view of how we could view the Payment Card Industry as a threat community would involve trying to figure out the probable frequency with which they will make onerous demands of our security budget, and the impact of those demands.</p>
<p>Now note that we would have a &#8220;secondary risk&#8221; to measure here.  I&#8217;m thinking that it&#8217;s not improbable that our PCI efforts may not be the most efficient use of or time and money.  So if we&#8217;re spending money on what PCI says we must, and neglecting areas of our IRM landscape that would actually reduce organizational risk more than those PCI efforts - then PCI compliance is costing us some real value by reducing our capability to manage real risk.  <strong>However</strong>,  and it&#8217;s quite a long tail event but, imagine that we&#8217;re unlucky and an incident happens!  This incident may become, in no small probability, the byproduct of PCI requirements.  Being diligent in risk management, we might want to study this likelihood, too.</p>
<p>So there you have it.  In both cases PCI Risk Management involves looking at the Payment Card Industry as a threat community, and determining the probable impact of having to deal with PCI DSS.</p>
<p>Now if you&#8217;ll excuse me, I have a white paper to write and I&#8217;m fresh out of acetone-based paint remover.</p>
<p><strong>POST SCRIPT</strong></p>
<p>I should make it clear that Risk Management should (and is) obviously being performed by those with PCI concerns.  PCI, if you will, is simply a sort of ISMS.  And the development of an ISMS can assist IT management with the process of developing metrics and analysis concerning the organizations capability to manage risk.  <em>There&#8217;s nothing wrong with PCI in this regard.</em></p>
<p>But I figured I should make the effort to read what the author was advocating, and the document this &#8220;PCI Risk Management&#8221; term was drawn from was really a set of &#8220;best practices&#8221; for PCI and &#8220;best practices&#8221; above and beyond what PCI requires.  <strong>This is not risk management</strong> (and no, adding &#8220;risk assessment&#8221; - in quotes because the author is really referring to vulnerability management - to the list of best practices doesn&#8217;t make it risk management, either).  It is more witch-doctory.</p>
]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 10:41:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci risk management">pci risk management</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/pci dss compliance">pci dss compliance</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk inherent">risk inherent</category>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci concerns">pci concerns</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=373">(Not Really) Stateful IT-GRC Inspecting Threat Management At Gigabit Speeds</source>
    </item>
    <item>
      <title><![CDATA[AEP left high and dry moves to ID access control]]></title>
      <link>http://securityratty.com/article/64af30b899f6aeae68a02006bebc700d</link>
      <guid>http://securityratty.com/article/64af30b899f6aeae68a02006bebc700d</guid>
      <description><![CDATA[AEP had been a victim of the NAC fallout. They made a bad bet on an OEM partner to provide them with NAC technology. When that NAC vendor went belly up, so did AEPs NAC product as a result. Now Tim...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>AEP had been a victim of the NAC fallout.&nbsp; They made a bad bet on an OEM partner to provide them with NAC technology.&nbsp; When that NAC vendor went belly up, so did AEPs NAC product as a result.&nbsp; Now <a href="http://www.networkworld.com/newsletters/vpn/2008/071408nac1.html?nlhtnac=ts_071508&amp;nladname=071508security:networkaccesscontrolal">Tim Greene reports</a> that AEP has come out with a new device that while not strictly a NAC product, does more identity access control and does not seem to do any admission control.</p>

<p>AEP which makes a SSL VPN type of appliance has a new appliance that delivers an agent to an endpoint and authenticates the user.&nbsp; It than according to the article inserts an identifier in the payload of every packet that shows where and who that packet is from which then allows it to either pass or not pass through, only to its allowed base.&nbsp; I don’t know that seems a bit of a chokepoint/bottleneck to me, but I don’t know enough about it, only what I read in the article. </p>

<p>The appliance is not cheap with a price tag of over 50k for just 99 users.&nbsp; It seems like an awful lot of money for what it does.&nbsp; An important lesson I think on picking the right OEM partner.&nbsp; Pick the wrong one and your product goes down as collateral damage to the OEM partners demise.</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=c63vEW"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=c63vEW" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=PSf9bJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=PSf9bJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=1EcEOJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=1EcEOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=CHCPnJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=CHCPnJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=DDgJbJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=DDgJbJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=yfFqLj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=yfFqLj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=a6KoIj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=a6KoIj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/336274533" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 08:33:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/aeps nac product">aeps nac product</category>
      <category domain="http://securityratty.com/tag/product">product</category>
      <category domain="http://securityratty.com/tag/nac product">nac product</category>
      <category domain="http://securityratty.com/tag/aep">aep</category>
      <category domain="http://securityratty.com/tag/oem partner">oem partner</category>
      <category domain="http://securityratty.com/tag/ssl vpn type">ssl vpn type</category>
      <category domain="http://securityratty.com/tag/appliance">appliance</category>
      <category domain="http://securityratty.com/tag/oem partners demise">oem partners demise</category>
      <category domain="http://securityratty.com/tag/article">article</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/336274533/aep-left-high-a.html">AEP left high and dry moves to ID access control</source>
    </item>
    <item>
      <title><![CDATA[Pirate Bay Wants Total Network Encryption, But Who Else?]]></title>
      <link>http://securityratty.com/article/cbaaa7bfa360660249982af62c597e59</link>
      <guid>http://securityratty.com/article/cbaaa7bfa360660249982af62c597e59</guid>
      <description><![CDATA[The Pirate Bay has ambitious plans to bring end-to-end encryption to all network activity, essentially blacking out a user's traffic from deep packet inspection gear and other prying eyes. Interesting...]]></description>
      <content:encoded><![CDATA[The Pirate Bay has ambitious plans to bring end-to-end encryption to all network activity, essentially blacking out a user's traffic from deep packet inspection gear and other prying eyes. Interesting project, sure, and definitely ambitious, but will it work? We doubt it, at least in the near term, and here's why. ]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 07:20:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ambitious">ambitious</category>
      <category domain="http://securityratty.com/tag/ambitious plans">ambitious plans</category>
      <category domain="http://securityratty.com/tag/bay">bay</category>
      <category domain="http://securityratty.com/tag/end-to-end encryption">end-to-end encryption</category>
      <category domain="http://securityratty.com/tag/network activity">network activity</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/project">project</category>
      <category domain="http://securityratty.com/tag/doubt">doubt</category>
      <category domain="http://securityratty.com/tag/term">term</category>
      <source url="http://digg.com/security/Pirate_Bay_Wants_Total_Network_Encryption_But_Who_Else">Pirate Bay Wants Total Network Encryption, But Who Else?</source>
    </item>
    <item>
      <title><![CDATA[Snort Security Platform 3.0 Beta Released]]></title>
      <link>http://securityratty.com/article/1f4e2b6789774132eea1a5417ead2a1e</link>
      <guid>http://securityratty.com/article/1f4e2b6789774132eea1a5417ead2a1e</guid>
      <description><![CDATA[Marty Roesch and company have just announced the release of Snort 3.0 beta
From Snort.org
Were pleased to introduce our first beta release built on the new Snort 3.0 architecture. The Snort 3.0...]]></description>
      <content:encoded><![CDATA[<p>Marty Roesch and company have just announced the release of Snort 3.0 beta. </p>
<p>From Snort.org:</p>
<blockquote><p>We’re pleased to introduce our first beta release built on the new Snort 3.0 architecture. The Snort 3.0 architecture consists of two primary components: a software platform called the Snort Security Platform (SnortSP) 3.0, which is shipping in beta form in this release, and traffic analysis engine modules that plug into SnortSP. This beta test release contains one engine module which contains the Snort 2.8.2 detection engine implemented as a SnortSP engine module. SnortSP is an open-source platform for running packet-based network security applications. It provides many of the common functions required by programs that deal with packet processing such as configuration loading, event generation and traffic logging, data acquisition, protocol decoding and validation, flow management, and more.</p></blockquote>
<p>They provide you an opportunity to provide feedback on the beta release as well &#8220;sspneta SHIFT 2 sourcefire D0T com&#8221;.</p>
<p>Downloading my copy now.</p>
<p><a href="http://www.snort.org/dl/snortsp/">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=LTShft"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=LTShft" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=YgoefI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=YgoefI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=PrSy0i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=PrSy0i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=2fImNi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=2fImNi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=KgMMQi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=KgMMQi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=HZ0Mni"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=HZ0Mni" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/323662680" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 21:11:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/beta">beta</category>
      <category domain="http://securityratty.com/tag/release">release</category>
      <category domain="http://securityratty.com/tag/beta release">beta release</category>
      <category domain="http://securityratty.com/tag/snort security platform">snort security platform</category>
      <category domain="http://securityratty.com/tag/snort">snort</category>
      <category domain="http://securityratty.com/tag/engine module">engine module</category>
      <category domain="http://securityratty.com/tag/snortsp engine module">snortsp engine module</category>
      <category domain="http://securityratty.com/tag/beta test release">beta test release</category>
      <category domain="http://securityratty.com/tag/snortsp">snortsp</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/323662680/">Snort Security Platform 3.0 Beta Released</source>
    </item>
    <item>
      <title><![CDATA[Feature Request #1: Stable Code]]></title>
      <link>http://securityratty.com/article/8ccf3e65d2b1b8b72fdbe0860c092c80</link>
      <guid>http://securityratty.com/article/8ccf3e65d2b1b8b72fdbe0860c092c80</guid>
      <description><![CDATA[I have a note to all network hardware vendors
Dear network vendor
As someone that is forced to configure and implement security on your hardware, I would greatly appreciate stable code and properly...]]></description>
      <content:encoded><![CDATA[<p><em>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; I have a note to all network hardware vendors&#8230;</em></p><p>Dear network vendor,</p><p>As someone that is forced to configure and implement security on your hardware, I would greatly appreciate stable code and properly functioning features. Unfortunately, I cannot always choose the hardware my customers are using in their infrastructure. However, if you would like for me to recommend they continue purchasing and using it, then the product must demonstrate to me that it is: capable, reliable, predictable and well-documented. If your product is not meeting these requirements, I&#8217;m forced to recommend other solutions to your (current) customer. </p><p><u>Stable Code</u>. If I have to spend 2-6 hours per implementation working through your product&#8217;s bugs, and then must either spend time on a support call or spend time getting packet captures to prove to you it&#8217;s not working, I am not a happy camper because you&#8217;re slowing down my progress. Your customer is not happy because they&#8217;re paying for that time and I&#8217;m not cheap. </p><p><u>Features</u>. Don&#8217;t publish in technical documentation that your product, or code can do something, only for me to find out later that it cannot. On-site in the middle of an implementation is not the time to architect Plan B. Let me know before, either through technical docs, white papers, best practices or release notes. I do read those. If you want to bend the truth, do it the marketing fluff, not my technical documents. </p><p><u>Documentation</u>. If your product <em>does</em> do what you say it does, then please do document and explain the concepts and procedures. Examples are good, but explanations are mandatory. A correct CLI reference is always lovely as well. If there are got&#8217;chas or tricks, please also document those. Again, white papers or release notes are fine. Having to track down the one security engineer from your company that holds the magic key is not practical, nor scalable. Plus, he may be on vacation during my install, which would make me irate. </p><p><u>Support</u>. If your product is not functioning or performing as expected, do NOT expect your customers to have a current maintenance contract to address a known issue or bug (or an un-known issue or bug for that matter). If they found a bug for you, you should probably <em>give</em> them a maintenance contract for a year&#8230; or two. If you don&#8217;t let us call support, I will find one of your pre-sales engineers and we will use him or her for post-sales support, which is not what you want them to do. But that&#8217;s your problem, not mine.</p><p>I believe that sums up the major issues. Specifically, I am interested in security, RADIUS, SSH, SNMP, DHCP&nbsp;and 802.1X functions. Before you add another bell or tweak another whistle, please make what you have works&#8230; consistently. That should be first, so it&#8217;s my Feature Request #1. </p><p>Respectfully,</p><p>jj</p><p># # #</p>
]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 00:01:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/stable code">stable code</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/post-sales support">post-sales support</category>
      <category domain="http://securityratty.com/tag/current maintenance contract">current maintenance contract</category>
      <category domain="http://securityratty.com/tag/current">current</category>
      <category domain="http://securityratty.com/tag/maintenance contract">maintenance contract</category>
      <category domain="http://securityratty.com/tag/security engineer">security engineer</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/6/30/feature-request-1-stable-code.html">Feature Request #1: Stable Code</source>
    </item>
  </channel>
</rss>
