<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: paradigm]]></title>
    <link>http://securityratty.com/tag/paradigm</link>
    <description></description>
    <pubDate>Fri, 20 Jun 2008 17:26:55 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Microsoft combats cybercrime in Nigeria]]></title>
      <link>http://securityratty.com/article/a3b5858d4e5896b5bf8a8b5384aaaee3</link>
      <guid>http://securityratty.com/article/a3b5858d4e5896b5bf8a8b5384aaaee3</guid>
      <description><![CDATA[Paradigm Initiative Nigeria (PIN) and Microsoft have partnered to educate the country's youth on cybercrime and to provide opportunities for them to use their computer skills...]]></description>
      <content:encoded><![CDATA[Paradigm Initiative Nigeria (PIN) and Microsoft have partnered to educate the country's youth on cybercrime and to provide opportunities for them to use their computer skills positively.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=80050?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=80050?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer skills positively">computer skills positively</category>
      <category domain="http://securityratty.com/tag/paradigm initiative nigeria">paradigm initiative nigeria</category>
      <category domain="http://securityratty.com/tag/provide opportunities">provide opportunities</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/pin">pin</category>
      <category domain="http://securityratty.com/tag/youth">youth</category>
      <source url="http://www.networkworld.com/news/2008/102208-microsoft-combats-cybercrime-in.html?fsrc=rss-security">Microsoft combats cybercrime in Nigeria</source>
    </item>
    <item>
      <title><![CDATA[Network World Coverage of ScienceLogic at Interop]]></title>
      <link>http://securityratty.com/article/27b0a46be99117829b3a5801b8947a5d</link>
      <guid>http://securityratty.com/article/27b0a46be99117829b3a5801b8947a5d</guid>
      <description><![CDATA[We were all really excited to have the opportunity to illuminate Sevick and Wetzel about ScienceLogics value proposition at Interop
Yesterday, they posted a terrific blog post about what they saw at...]]></description>
      <content:encoded><![CDATA[<p>We were all really excited to have the opportunity to illuminate Sevick and Wetzel about ScienceLogic’s value proposition at Interop.
<p>Yesterday, they <a href="http://www.networkworld.com/community/node/33059" target="_blank">posted a terrific blog post</a> about what they saw at Interop. Fortunately, ScienceLogic was one of the technologies that they highlighted from the show. I have written earlier posts about <a href="http://blog.sciencelogic.com/whats-up-with-the-washington-posts-biz-section-coverage-of-local-business/05/2008" target="_blank">how difficult it has been</a> to gain smart, insightful coverage for our solutions with technology media.
<p>I have to say that they really got it! And it feels so good. We know that we have a bit of a hidden gem of a product here at ScienceLogic and will be working overtime in the coming months to take our business and products to a “Blue Ocean” environment that will shock and surprise many others in the media. However Sevick and Wetzel will be amongst the first to get a close-up on why and how we will deliver a new paradigm to this marketplace in 2009!
<p>A few excerpts from their post:<br />
<blockquote>
<p>“We noticed yet more specialty network management vendors, leading us to wonder how the market can support such a plethora of them, and we felt empathy for IT teams that have to master yet more interfaces.”
<p>“Application performance management and application acceleration vendors were well represented. Such products play well in today’s climate because they allow enterprises to get the most out of existing IT investments instead of buying more “stuff”. One particularly interesting vendor we talked to was <a href="http://www.sciencelogic.com/">ScienceLogic</a>. They are integrating IT infrastructure and application monitoring into a single, not-very-expensive platform that will serve mainstream business well. This is smart, and we predict they will give the CA’s, BMC’s, HP’s and IBM’s of the world a run for their money.”</p>
</blockquote>
<p>&nbsp;
<p>Check out the <a href="http://www.networkworld.com/community/node/33059" target="_blank">blog post here</a> and keep <a href="http://www.networkworld.com/community/appview" target="_blank">App Performance View</a> on your radar..<a href="http://www.networkworld.com/community/node/33059"></a></p>
]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 11:36:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/terrific blog post">terrific blog post</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/application acceleration vendors">application acceleration vendors</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/sciencelogic">sciencelogic</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/application performance management">application performance management</category>
      <source url="http://blog.sciencelogic.com/network-world-coverage-of-sciencelogic-at-interop/09/2008">Network World Coverage of ScienceLogic at Interop</source>
    </item>
    <item>
      <title><![CDATA[Complex Event Processing An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control]]></title>
      <link>http://securityratty.com/article/85dd8ffe0f10a11626880b7de9e30386</link>
      <guid>http://securityratty.com/article/85dd8ffe0f10a11626880b7de9e30386</guid>
      <description><![CDATA[The following quote is from Complex Event Processing An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control by Evo Eftimov, iSec Consulting Ltd
Complex Event Processing...]]></description>
      <content:encoded><![CDATA[<p>The following quote is from <a href="http://www.top-consultant.com/articles/CEP.pdf" target="_blank">Complex Event Processing – An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control</a> by Evo Eftimov, <a href="http://www.isecc.com" target="_blank">iSec Consulting Ltd</a></p>
<blockquote><p>&#8220;Complex Event Processing (CEP) is a technology which has been used for many years in the Aerospace and Defence Industry for Situational Awareness and Data Fusion modules in Command, Control, Communications, Computing and Intelligence Systems (aka C4I).</p>
<p>Currently CEP is being rediscovered as a foundation for new class of extremely effective Business Intelligence, Security and System/Network/SCADA Monitoring solutions in industries like Financial Services, Telecommunications, Oil and Gas, Manufacturing, Logistics etc. The increasing connectivity and processing power of the modern IT and Telecom technologies lead to increasing speed and volume of the dataflow available to the organisations. By using CEP solutions companies can gain competitive advantage by achieving real-time situational awareness and tapping the information value that is hidden within the streams of real-time event data that are coming from a variety of sources such as enterprise applications, financial transactions, sensor networks and supply chains.&#8221;</p></blockquote>
<p style="text-align: left;">Unfortunately, the author does not cite references in the paper.</p>
]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 01:59:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/cep solutions companies">cep solutions companies</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/situational awareness">situational awareness</category>
      <category domain="http://securityratty.com/tag/real-time situational awareness">real-time situational awareness</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/solutions">solutions</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <category domain="http://securityratty.com/tag/business intelligence">business intelligence</category>
      <source url="http://www.thecepblog.com/2008/09/21/complex-event-processing-%e2%80%93-an-emerging-paradigm-in-business-intelligence-security-and-monitoring-and-control/">Complex Event Processing An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control</source>
    </item>
    <item>
      <title><![CDATA[Interop NY Keynotes: IBM]]></title>
      <link>http://securityratty.com/article/44ba0e9ad08b54462e9c92a6c54837a5</link>
      <guid>http://securityratty.com/article/44ba0e9ad08b54462e9c92a6c54837a5</guid>
      <description><![CDATA[Day one of Interop NY began with an introduction from Interop Manager Lenny Heymann, then Bob Picciano, General manager Lotus software and WebSpehere Portal IBM took the stage
IBMs presentation was...]]></description>
      <content:encoded><![CDATA[<p>Day one of Interop NY began with an introduction from Interop Manager Lenny Heymann, then Bob Picciano, General manager Lotus software and WebSpehere Portal IBM took the stage.</p>
<p>IBM&#8217;s presentation was cleverly titled <strong>2mor0@Wrk</strong> - Tomororow work and Web 2.0.</p>
<p><strong>Overview</strong></p>
<p>Web 2.0 is delivering a whole different paradigm of communication. The slide is Lotus Symphony - NOT PPT. Over 2 million downloads.</p>
<p>There is an information overload that impacts individual productivity in the workplace. It has a profound effect on organizational productivity. A more complex organization entity provides more pressure and more inefficiencies in workplace. Up to 70% of time can be used looking for the WRONG information.</p>
<p>Collaboration mitigates information overload. It allows you to identify experts and opinions.</p>
<p>The collaboration agenda. Enterprises are at the onset of exploring these features. Web 2.0 is giving us the capacity to do more. Collaboration optimizes business outcomes - global, secure and dynamic.The most progressive companies are looking at UNIFIED COMMUNICATIONS. Making sure that directories and profiles are fully mobile.</p>
<p>Collaboration should be a contextual part of the workflow, going directly into applications.</p>
<p>IBM&#8217;s collaboration strategy is to deliver these services through online or offline services.</p>
<p><strong>Demonstration</strong></p>
<p>Executive IT architect Ron Sebastian provided a demonstration of IBM&#8217;s collaboration strategy. IBM&#8217;s Web 2.0 solutions span delivery platforms:</p>
<ul>
<li>Platform - web as&nbsp; platform</li>
<li>Application - development</li>
<li>People - social computing</li>
</ul>
<p><a href="http://www-01.ibm.com/software/lotus/products/connections/" target="_blank">Lotus Connections</a> - a family of social computing software that provides profile lookup and community capabilities. Think of Facebook, Yahoo Groups, and delicious combined in one portal.</p>
<p>Ron demonstrated these social services embedded into a healthcare provider application. Semantic tagging is available, contact information and commenting. Not only are we providing service to customers, you can integrate sync capability to directly call the person you want.</p>
<p>The biggest aspect of Lotus Connection? It&#8217;s all integrated.</p>
<p>A new service - <a href="https://www.bluehouse.lotus.com/" target="_blank">Project Bluehouse</a>. This is a SaaS delivery of these collaborated capabilities. The store and share can manage and share documents within and outside the company. Access control is no longer an issue.</p>
<p>Collaborative Web 2.0 services available as standalone products that also work in a mobile environment.</p>
<p><strong>Case Study: Natural Disaster Management Mashup</strong></p>
<p>Boeing came up with twenty different scenarios that they could handle through their systems. The problem was the one they didn&#8217;t count on. One example was Katrina - how to deliver supplies to the area: what airports were open? Where could they land? The problem was they could not find one list of public, private and military airports, nor what was open. The mashup took different feeds to allow the deacon maker to make a more rapid and intelligent decision based on information on where they could fly in the appropriate supplies. From open information sites like <a href="http://www.airnav.com/" target="_blank">AirNav.com</a> and personal contacts, users were able to mashup the information to make better decisions.</p>
<p><strong>Conclusion</strong></p>
<p><a href="http://www.eweek.com/c/a/Messaging-and-Collaboration/IBM-to-Unveil-Social-Software-Center-at-Interop/" target="_blank">IBM announced the IBM Center for Social Software</a>, proving their commitment to connect, collaborate, and innovate. Users and academics can work together to how these innovations can be applied to businesses and provide value to the market.</p>
<p>There has been <a href="http://teblog.typepad.com/david_tebbutt/2008/04/ibms-bluehouse.html" target="_blank">some question</a> of whether or not IBM can pull this off and move into the collaborative Web 2.0 market. Despite <a href="http://www.theappgap.com/ibm-bluehouse-organizes-online-meetings-and-the-before-and-after.html" target="_blank">some criticism</a>, it looks like IBM has really taken a step forward in advancing their products and services to meet market needs.</p>
<p>People drive better business outcomes. Connecting, collaboration, and innovation is key. Having the right tools and information to do that eases pressure that many organizations feel and brings Web 2.0 technologies to the heart of businesses.</p>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 09:39:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ibm">ibm</category>
      <category domain="http://securityratty.com/tag/information sites">information sites</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/collaboration">collaboration</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/ibms collaboration strategy">ibms collaboration strategy</category>
      <category domain="http://securityratty.com/tag/social services">social services</category>
      <category domain="http://securityratty.com/tag/collaborative web">collaborative web</category>
      <source url="http://blog.sciencelogic.com/interop-ny-keynotes-ibm/09/2008">Interop NY Keynotes: IBM</source>
    </item>
    <item>
      <title><![CDATA[Biotech Platforms]]></title>
      <link>http://securityratty.com/article/45651b9a0decddecc758c652995e074f</link>
      <guid>http://securityratty.com/article/45651b9a0decddecc758c652995e074f</guid>
      <description><![CDATA[It is interesting to see the notion of tech platforms play out in other fields. Specifically, the biotech field is all abuzz on platforms. For example Exelixis' oncology platform built on kinase...]]></description>
      <content:encoded><![CDATA[<p>It is interesting to see the notion of tech platforms play out in other fields. Specifically, the biotech field is <a href="http://www.hammerstockblog.com/genentech’s-new-shiny-platform/">all </a><a href="http://www.hammerstockblog.com/exelixis-as-a-platform-company/">abuzz</a> on platforms. For example Exelixis&#39; oncology platform built on kinase inhibitors.</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal; ">Having a validated drug discovery platform is the first and most important criterion for defining a good platform company. The platform is typically comprised of a combination of technology, experienced personnel and intellectual property that can generate a stream of drug candidates. Most importantly, investing should be done only after a product of the platform&#160;<span>demonstrates</span>&#160;activity&#160;<span>in clinical trials.&#160;</span>Having a clinically validated product is not a guarantee for future success of the platform nor does it mean that the specific agent will reach the market, but it does imply that one or more of the platform’s products stand a reasonable chance of becoming a commercial drug. A validated platform may increase overall success rates, yet the odds of a particular drug candidate to make it all the way to approval are still low.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Exelixis is active in the ever growing market of kinase inhibitors (KIs) for the treatment of cancer, that is, drugs that block the activity of kinases in cancer cells. Cancer cells are often described as cells that are out of control: They proliferate quickly, ignore death signals, invade nearby tissues and eventually metastasize to distant organs. These disease onset and advancement are associated with processes such as cell growth, motility and blood-vessel formation, which are governed by a complex network made of kinases. Thus, blocking these processes by inhibiting the relevant kinases has emerged as one of the most attractive approaches to fighting cancer.<br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Together with monoclonal antibodies, kinase inhibitors represent a paradigm shift in cancer treatment from cytotoxic agents to targeted therapies, a trend that is constantly growing. Like antibodies for cancer, kinase inhibitors target tumors while sparing healthy cells and consequently lead to better activity with fewer side effects. Kinase inhibitors, however, possess several advantages over antibodies. The most evident advantage is that KIs can hit targets inside the cell while antibodies can only bind targets presented on the cell surface, so internal targets are approachable only by KIs. Another advantage is the fact that KIs can be given orally, which is a major factor in terms of patient convenience, especially given the typical long treatment duration associated with targeted therapies. Another advantage, which will be later discussed in the article, is the ability to produce KIs that hit several targets at once.<br /></span></p></blockquote><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Read the whole thing </span><a href="http://www.hammerstockblog.com/exelixis-as-a-platform-company/">here</a><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">.&#160;</span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Speaking a software guy, the thing that is interesting to me here is that the platform approach allows a biotech to aggregate a large database of tests and test results to refine products across a range of targets and delivery mechanisms. Its just data. Cancer versus Moore&#39;s law? Puh-leeze.</span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></div>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 06:08:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/drug">drug</category>
      <category domain="http://securityratty.com/tag/treatment">treatment</category>
      <category domain="http://securityratty.com/tag/cancer treatment">cancer treatment</category>
      <category domain="http://securityratty.com/tag/commercial drug">commercial drug</category>
      <category domain="http://securityratty.com/tag/platforms">platforms</category>
      <category domain="http://securityratty.com/tag/drug discovery platform">drug discovery platform</category>
      <category domain="http://securityratty.com/tag/platform">platform</category>
      <category domain="http://securityratty.com/tag/cells">cells</category>
      <category domain="http://securityratty.com/tag/cancer cells">cancer cells</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/biotech-platforms.html">Biotech Platforms</source>
    </item>
    <item>
      <title><![CDATA[Virtualization and information-centric security]]></title>
      <link>http://securityratty.com/article/ff2a437ce08ea0458e81253a590d4c9d</link>
      <guid>http://securityratty.com/article/ff2a437ce08ea0458e81253a590d4c9d</guid>
      <description><![CDATA[Many more of the customers I talk to are focused on virtualization as a core infrastructure strategy. They obviously want to know more about how this will affect how they look at security. While I am...]]></description>
      <content:encoded><![CDATA[Many more of the customers I talk to are focused on virtualization as a core infrastructure strategy. They obviously want to know more about how this will affect how they look at security. While I am not the expert on anti-virus/malware, NAC, intrusion prevention etc, one area that I get excited about is the data protection implications of this trend...<br /><br />As devices get abstracted and pushed to the background, it appears we are left, at the core, with applications and data. The interactions between the two dictate productivity, security et al. In this context, an information-centric security paradigm becomes even more important.<br /><br />There are no devices to lock down (these will be virtual - appearing and dissapearing as required). Much of the data will be accessed from virtual containers. Therefore, protecting the data itself, regardless of the applications, the devices, the networks will become crucial in this evolving landscape...<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=m0SW5J"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=m0SW5J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=KSbNxj"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=KSbNxj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=JnpzqJ"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=JnpzqJ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/341722561" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 12:33:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data protection implications">data protection implications</category>
      <category domain="http://securityratty.com/tag/core">core</category>
      <category domain="http://securityratty.com/tag/security paradigm">security paradigm</category>
      <category domain="http://securityratty.com/tag/core infrastructure strategy">core infrastructure strategy</category>
      <category domain="http://securityratty.com/tag/virtual containers">virtual containers</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/341722561/virtualization-and-information-centric.html">Virtualization and information-centric security</source>
    </item>
    <item>
      <title><![CDATA[Assessing the Security Benefits of Cloud Computing]]></title>
      <link>http://securityratty.com/article/1e09e5c89f15d3a4df4ea921f9230c2d</link>
      <guid>http://securityratty.com/article/1e09e5c89f15d3a4df4ea921f9230c2d</guid>
      <description><![CDATA[With all this talk and reporting about security concerns, lets change the channel for a moment and assess the potential security benefits of Cloud Computing
In my view, there are some strong technical...]]></description>
      <content:encoded><![CDATA[<p><a title="Is the glass half empty or half full?" href="http://www.flickr.com/photos/94094843@N00/2292559560/" target="_blank"><img class="alignright" style="border: 0; float: right; margin: 3px;" src="http://farm4.static.flickr.com/3004/2292559560_378f226531_m.jpg" border="0" alt="Is the glass half empty or half full?" /></a></p>
<p>With all this <a href="http://cloudsecurity.org">talk</a> and <a href="http://www.gartner.com/DisplayDocument?id=685308">reporting</a> about security concerns, lets change the channel for a moment and assess the <strong>potential security benefits</strong> of Cloud Computing.</p>
<p>In my view, there are some strong technical security arguments in favour of Cloud Computing - assuming we can find ways to manage the risks.</p>
<p>With this new paradigm come challenges <strong>and </strong>opportunities.  The challenges are getting plenty of attention - I&#8217;m regularly afforded the opportunity to <a href="http://www.gridtoday.com/grid/2422309.html">comment</a> on them, plus obviously I cover them on this blog.  However, lets not lose sight of the potential upside.</p>
<p>In this post, I walk through seven technical security benefits.  Some are immediate, others may arise over time and have conditions attached (some unstated for the sake of brevity).  However, I&#8217;m including the longer-range benefits now to raise awareness.  Some of the outcomes listed are available today without the Cloud, but they are either complex and slow to implement (and thus less likely to happen) or prohibitive for capital cost reasons.  I don&#8217;t claim this is a definitive list - it reflects where my thinking is today.</p>
<p>Some benefits depend on the Cloud service used and therefore do not apply across the board.  For example; I see no solid forensic benefits with SaaS.  Also, for space reasons, I&#8217;m purposely not including the &#8216;flip side&#8217; to these benefits, however if you read this blog regularly you should <a href="http://cloudsecurity.org/2008/04/24/cloud-stacks-please-mind-the-gap/">recognise some</a>.</p>
<p>On a sidenote, I believe the Cloud offers Small and Medium Businesses major potential security benefits.  Frequently SMBs struggle with limited or non-existent in-house INFOSEC resources and budgets.  The caveat is that the Cloud market is still very new - security offerings are somewhat foggy - making selection tricky.  Clearly, not all Cloud providers will offer the same security.</p>
<h4>Seven Technical Security Benefits of the Cloud</h4>
<h4>1. Centralised Data</h4>
<ul>
<li><strong>Reduced Data Leakage</strong>: this is the benefit I hear most from Cloud providers - and in my view they are right.  How many laptops do we need to lose before we get this?  How many backup tapes?  The data &#8220;landmines&#8221; of today could be greatly reduced by the Cloud as thin client technology becomes prevalent.  Small, temporary caches on handheld devices or Netbook computers pose less risk than transporting data buckets in the form of laptops.  Ask the CISO of any large company if all laptops have company &#8216;mandated&#8217; controls consistently applied; e.g. full disk encryption.  You&#8217;ll see the answer by looking at the whites of their eyes.  Despite best efforts around asset management and endpoint security we continue to see embarrassing and disturbing misses.  And what about SMBs?  How many use encryption for sensitive data, or even have a data classification policy in place?</li>
<li><strong>Monitoring benefits</strong>: central storage is easier to control and monitor.  The flipside is the nightmare scenario of <a href="http://www.gnucitizen.org/blog/most-attractive-targets-saas/">comprehensive data theft</a>.  However, I would rather spend my time as a security professional figuring out smart ways to protect and monitor access to data stored in one place (with the benefit of situational advantage) than trying to figure out all the places where the company data resides across a myriad of thick clients!  You can get the benefits of Thin Clients today but Cloud Storage provides a way to centralise the data faster and potentially cheaper.  The logistical challenge today is getting Terabytes of data to the Cloud in the first place.</li>
</ul>
<h4>2. Incident Response / Forensics</h4>
<ul>
<li><strong>Forensic readiness</strong>: with Infrastructure as a Service (IaaS) providers, I can build a dedicated forensic server in the same Cloud as my company and place it offline, ready for use when needed.  I would only need pay for storage until an incident happens and I need to bring it online.  I don&#8217;t need to call someone to bring it online or install some kind of remote boot software - I just click a button in the Cloud Providers web interface.  If I have multiple incident responders, I can give them a copy of the VM so we can distribute the forensic workload based on the job at hand or as new sources of evidence arise and need analysis.  To fully realise this benefit, commercial forensic software vendors would need to move away from archaic, physical dongle based licensing schemes to a network licensing model.</li>
<li><strong>Decrease evidence acquisition time</strong>: if a server in the Cloud gets compromised (i.e. broken into), I can now clone that server at the click of a mouse and make the cloned disks instantly available to my Cloud Forensics server.  I didn&#8217;t need to &#8220;find&#8221; storage or have it &#8220;ready, waiting and unused&#8221; - its just there.</li>
<li><strong>Eliminate or reduce service downtime</strong>: Note that in the above scenario I didn&#8217;t have to go tell the COO that the system needs to be taken offline for hours whilst I dig around in the RAID Array hoping that my physical acqusition toolkit is compatible (and that the version of RAID firmware isn&#8217;t supported by my forensic software).  Abstracting the hardware removes a barrier to even doing forensics in some situations.</li>
<li><strong>Decrease evidence transfer time</strong>: In the same Cloud, bit fot bit copies are super fast - made faster by that replicated, distributed filesystem my Cloud provider engineered for me.  From a network traffic perspective, it may even be free to make the copy in the same Cloud.  Without the Cloud, <strong>I </strong>would have to a lot of time consuming and expensive provisioning of physical devices.  I only pay for the storage as long as I need the evidence.</li>
<li><strong>Eliminate forensic image verification time</strong>: Some Cloud Storage implementations expose a cryptographic checksum or hash.  For example, Amazon S3 generates an MD5 hash <a href="http://docs.amazonwebservices.com/AmazonS3/2006-03-01/index.html?RESTObjectPUT.html">automagically</a> when you store an object.  In theory you no longer need to generate time-consuming MD5 checksums using external tools - its already there.</li>
<li><strong>Decrease time to access protected documents</strong>: Immense CPU power opens some doors.  Did the suspect password protect a document that is relevant to the investigation?  You can now test a wider range of candidate passwords in less time to speed investigations.</li>
</ul>
<h4>3. Password assurance testing (aka cracking)</h4>
<ul>
<li><strong>Decrease password cracking time</strong>: if your organisation regularly tests password strength by running password crackers you can use Cloud Compute to decrease crack time and you only pay for what you use.  Ironically, your cracking costs go up as people choose better passwords ;-).</li>
<li><strong>Keep cracking activities to dedicated machines</strong>: if today you use a distributed password cracker to spread the load across non-production machines, you can now put those agents in dedicated Compute instances - and thus stop mixing sensitive credentials with other workloads.</li>
</ul>
<h4>4. Logging</h4>
<ul>
<li><strong>&#8220;Unlimited&#8221;, pay per drink storage</strong>: logging is often an afterthought, consequently insufficient disk space is allocated and logging is either non-existant or minimal.  Cloud Storage changes all this - no more &#8216;guessing&#8217; how much storage you need for standard logs.</li>
<li><strong>Improve log indexing and search</strong>: with your logs in the Cloud you can leverage Cloud Compute to index those logs in real-time and get the benefit of <a href="http://blogs.splunk.com/thewilde/2008/06/24/splunk-ninja-inside-the-cloud/">instant search results.</a> What is different here?  The Compute instances can be plumbed in and scale as needed based on the logging load - meaning a true real-time view.</li>
<li><strong>Getting compliant with Extended logging</strong>: most modern operating systems offer extended logging in the form of a C2 audit trail.  This is rarely enabled for fear of performance degradation and log size.  Now you can &#8216;opt-in&#8217; easily - if you are willing to pay for the enhanced logging, you can do so.  Granular logging makes compliance and investigations easier.</li>
</ul>
<h4>5. Improve the state of security software (performance)</h4>
<ul>
<li><strong>Drive vendors to create more efficient security software</strong>: Billable CPU cycles get noticed.  More attention will be paid to inefficient processes; e.g. poorly tuned security agents.  Process accounting will make a comeback as customers target &#8216;expensive&#8217; processes.  Security vendors that understand how to squeeze the most performance from their software will win.</li>
</ul>
<h4>6. Secure builds</h4>
<ul>
<li><strong>Pre-hardened, change control builds</strong>: this is primarily a benefit of virtualization based Cloud Computing.  Now you get a chance to start &#8217;secure&#8217; (by your own definition) - you create your Gold Image VM and clone away.  There are ways to do this today with bare-metal OS installs but frequently these require additional 3rd party tools, are time consuming to clone or add yet another agent to each endpoint.</li>
<li><strong>Reduce exposure through patching offline</strong>: Gold images can be kept up securely kept up to date.  Offline VMs can be conveniently patched &#8220;off&#8221; the network.</li>
<li><strong>Easier to test impact of security changes</strong>: this is a big one.  Spin up a copy of your production environment, implement a security change and test the impact at low cost, with minimal startup time.  This is a big deal and removes a major barrier to &#8216;doing&#8217; security in production environments.</li>
</ul>
<h4>7. Security Testing</h4>
<ul>
<li><strong>Reduce cost of testing security: </strong>a SaaS provider only passes on a portion of their security testing costs.  By sharing the same application as a service, you don&#8217;t foot the expensive security code review and/or penetration test.  Even with Platform as a Service (PaaS) where your developers get to write code, there are potential cost economies of scale (particularly around use of code scanning tools that sweep source code for security weaknesses).</li>
</ul>
<h4>Your Thoughts?</h4>
<p>What benefits do you see that I haven&#8217;t included in the above list?  Where do you agree/disagree and importantly, why?</p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/341289594" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 03:00:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/benefits">benefits</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/technical security benefits">technical security benefits</category>
      <category domain="http://securityratty.com/tag/based">based</category>
      <category domain="http://securityratty.com/tag/virtualization based cloud">virtualization based cloud</category>
      <category domain="http://securityratty.com/tag/efficient security software">efficient security software</category>
      <category domain="http://securityratty.com/tag/security software">security software</category>
      <category domain="http://securityratty.com/tag/cloud market">cloud market</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/341289594/">Assessing the Security Benefits of Cloud Computing</source>
    </item>
    <item>
      <title><![CDATA[OWASP Talk Q&A Notes]]></title>
      <link>http://securityratty.com/article/81fb1dfdb408580202cb30b424d72c9c</link>
      <guid>http://securityratty.com/article/81fb1dfdb408580202cb30b424d72c9c</guid>
      <description><![CDATA[On Monday I did a talk on Web Services security at the MSP OWASP. The talk was ok, but not as good as at RSA because I Brian Chess did a better job with some of the stories than me. What was really...]]></description>
      <content:encoded><![CDATA[<p>On Monday I did a talk on Web Services security at the MSP OWASP. The talk was ok, but not as good as at RSA because I Brian Chess did a better job with some of the stories than me. What was really good though was a number of questions and answers afterwards.</p><div><br><div>One person asked the old chestnut - "do we need to care about web services security if we are inside the firewall?" Now, I have heard this question many, many times in different ways, and this time my brain just shorted out, I basically said that I am not sure what difference it really makes. You don't get security from a firewall, you may get the ability to fire someone if they do something bad, but in most companies there is no "wall" and there sure isn't any "fire", at most they are speed bumps. I am *not* saying to remove them, they are part and parcel of how you operate a network but they are not really providing any additional security. Network firewalls are thought of as a security tools because they began as a security innovation and they are paid for out of the security budget.</div><br>

<p><br>
<a href="http://1raindrop.typepad.com/photos/uncategorized/2008/05/19/innovatecompare_2.png"><img  alt="Innovatecompare_2" title="Innovatecompare_2" src="http://1raindrop.typepad.com/1_raindrop/images/2008/05/19/innovatecompare_2.png" width="300" height="167" border="0"></a></p>
<div><a href="http://1raindrop.typepad.com/1_raindrop/2007/02/thinking_about_.html">Robert Garigue</a> said several years ago that network firewalls are part of network hygiene like brushing your teeth. Information security should not have to help people brush their teeth, and instead should operate like a dentist helping groups work more complex and risky issues. I have advised CISOs at several companies to off load the network firewall jockeys out of infosec and into network groups. Sometimes they listen. If so, the infosec group can focus on other issues instead of managing a Visio-driven "security" device. </div><br><div>Why Visio? Well, the main security property from a firewall is the scary flames and brick wall on Visio. And how do you know whether or not to open up a port? You just open the org chart (in Visio) and find the level of the person who is requesting the port be opened. If VP Then Yes. Is this security? Hardly.</div><br><div>So one last time - Web Services are used to provide access to your main systems (which live on mainframes, big RDBMS, SAP, ERP, CRM, and so on) these are the keys to the kingdom, and lots of apps need them. The whole point of Web Services is to make it easier to talk to them. So "inside" or "outside" the firewall, do you need to care about authentication, authorization, and auditing on the systems that run your entire business???</div><br><div>Another interesting question from the Q &amp; A from <a href="http://hursk.com/">Jon Passki</a> was on XML Security Gateways. We talked a fair bit about their utility in solving the aforementioned authentication, authorization, and auditing problems. I pulled up <a href="http://www.vordel.com/products/vx_gateway/">Vordel's gateway</a> and showed how to build security workflows to deploy security as a service. Jon asked could I ever imagine a Web services security architecture without a gateway? I said I think that they are not always the starting point but mid to long term they are definitely in basically any effective security architecture I can think of. Having a place to deploy, manage, and enforce policy that is separate the code solves a lot of real world problems. People are hung up on thinking about Web services programming like it has to be Web app programming (this happens in REST a lot), but there is another school of successful web apps, arguably the most successful, and its called email. </div><br><div>Email app architecture looks nothing like web app design. You wouldn't read every email sent to your address would you? Of course not, it goes through spam filters, virus checkers and so on. Further its a message oriented paradigm, and you know that unless its signed/encrypted with PGP/GPG security is suspect at best. So yeah, I think gateways are an hugely important part of a Web Services security architecture.</div><br><div>Finally, I can also not imagine going live when you are supporting multiple protocols and token types without a good testing strategy. Mark O'Neill recently <a href="http://radio.weblogs.com/0111797/2008/07/07.html#a115">blogged</a> something I recommend to all my clients - namely make sure you have security specific test cases, test harnesses and testing tools, like for example <a href="http://www.vordel.com/products/soapbox/">Vordel's Soapbox</a>.</div><br></div>]]></content:encoded>
      <pubDate>Fri, 11 Jul 2008 11:36:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/additional security">additional security</category>
      <category domain="http://securityratty.com/tag/security workflows">security workflows</category>
      <category domain="http://securityratty.com/tag/security innovation">security innovation</category>
      <category domain="http://securityratty.com/tag/effective security architecture">effective security architecture</category>
      <category domain="http://securityratty.com/tag/web services">web services</category>
      <category domain="http://securityratty.com/tag/gateways">gateways</category>
      <category domain="http://securityratty.com/tag/web services security">web services security</category>
      <category domain="http://securityratty.com/tag/xml security gateways">xml security gateways</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/owasp-talk-qa-notes.html">OWASP Talk Q&amp;A Notes</source>
    </item>
    <item>
      <title><![CDATA[Will Idiocy Ever End?]]></title>
      <link>http://securityratty.com/article/7a7383b72d02885cfc7f7edc37372687</link>
      <guid>http://securityratty.com/article/7a7383b72d02885cfc7f7edc37372687</guid>
      <description><![CDATA[So, I just came back from FIRST2008 and a typical conference discussion over beer has turned - again! - to academic security research

I lamented and ranted and rambled about it ( here , here , here...]]></description>
      <content:encoded><![CDATA[So, I just came back from <a href="http://www.first.org/conference/2008/program/#p864">FIRST2008</a> and a typical conference discussion over beer has turned - again! - to  academic security research.<br /><br />I lamented and ranted and rambled about it (<a href="http://chuvakin.blogspot.com/2007/12/spaf-on-academic-security-research.html">here</a>, <a href="http://chuvakin.blogspot.com/2007/09/once-more-on-failure-of-academic.html">here</a>, <a href="http://chuvakin.blogspot.com/2008/05/fun-security-reading-3.html">here</a>), but I am still shocked. I come from academic background myself and it is unthinkable to me that a research physicist today will write a thesis on 2nd Law of Newton or will set to prove that objects tend to fall down while dropped. Or that they, in fact, "fall up."<br /><br />However, that is the type of stuff I see in academic security papers that I occasionally get to review. Based on our FIRST conversation, other people who happen to retain ties to academia are reporting the same: research work that confuses "phishing" with "fast flux networks" (thanks Jose), inventing a new intrusion detection "paradigm, "  and all sorts of other bizarre crap continues to be cooked and  submitted to publications.<br /><br />When will this end? Why can't you people tackle REAL problems? Or at least useful and hard classic problems? Or, at the very least, learn  WTF is going on the real world of operational security before you do ANYTHING? The maybe you stop saying things like "in general, IDS is considered to be a security tool" as if it was some kind of Zen wisdom (a quote from a pathetic excuse for a paper that I reviewed recently...)<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=RlxgsI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=RlxgsI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=GLg27I"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=GLg27I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0keoFI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0keoFI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/319714659" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 02:15:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/academic security research">academic security research</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/people tackle real">people tackle real</category>
      <category domain="http://securityratty.com/tag/bizarre crap continues">bizarre crap continues</category>
      <category domain="http://securityratty.com/tag/typical conference discussion">typical conference discussion</category>
      <category domain="http://securityratty.com/tag/research physicist">research physicist</category>
      <category domain="http://securityratty.com/tag/academic security papers">academic security papers</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/319714659/will-idiocy-ever-end.html">Will Idiocy Ever End?</source>
    </item>
    <item>
      <title><![CDATA[Links List 6.20.08]]></title>
      <link>http://securityratty.com/article/f63a51e258d42ece74939596e871ddcf</link>
      <guid>http://securityratty.com/article/f63a51e258d42ece74939596e871ddcf</guid>
      <description><![CDATA[Dana Gardner discusses the recently announced partnership of VMWare and HP . They seek to offer enterprises and service providers a single management and control approach to both physical and virtual...]]></description>
      <content:encoded><![CDATA[<p>Dana Gardner discusses the <a href="http://briefingsdirectblog.blogspot.com/2008/06/vmware-and-hp-align-products-to-bring.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/briefingsdirectblog.blogspot.com');" target="_blank">recently announced partnership of VMWare and HP</a>. They seek to offer enterprises and service providers a single management and control approach to both physical and virtual software infrastructure stacks. A fun little game: count the number of HP modules you have to buy for a “complete” virtualization management solution.
<p>John Willis talks about customers that use a hybrid approach of priority and <a href="http://www.johnmwillis.com/opensource/the-art-of-war/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.johnmwillis.com');" target="_blank">open source monitoring</a> tools depending on how important what’s being monitored actually is to the business. He says,”a running joke that was going around in the early 2000’s is that BMC and Tivoli created Mercury (now HP) Sitescope because they, BMC and Tivoli, would not budge on their per server pricing. In fact many of the enterprise proprietary monitoring vendors still don’t deal with the not-so-important-server issue.”
<p>One of our favorite writers, <a href="http://blogs.eweek.com/masked_intentions/content/systems_management/virtualization_management_war_begins_in_earnest.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/blogs.eweek.com');" target="_blank">Michael Vizard, examines the virtualization market</a> and more at Masked Intentions. He says that, “Virtualization continues to evolve, and companies such as IBM, CA, <a href="http://www.eweek.com/c/a/Virtualization/Making-Virtualization-Work-for-You/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.eweek.com');" target="_blank">BladeLogic</a> and <a href="http://www.eweek.com/c/a/Infrastructure/Making-the-Most-Out-of-IT-Automation/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.eweek.com');" target="_blank">Hewlett-Packard</a> have all made specific commitments to extend their tools for managing physical servers to virtual machine environments.” We would add ScienceLogic to that list of course. But what’s more interesting is the statement that newbies focused on point solutions around virtualization management are saying that virtual machines represent a paradigm shift that will make existing management tools obsolete. Am I missing something here? All management vendors need to keep up with technology changes – hence the move to support virtualization. The market needs change; the management tools change, hopefully apace.
<p><a href="http://www.packettrap.com/blog/index.php/june-16th-2008-commercial-open-source-debate/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.packettrap.com');" target="_blank">PacketTrap thinks that commercial open source is dying</a>. So does that mean they think only commercial open source is their competitor and not just open source monitoring software?
<p>So their value proposition is not that their feature set and value are better, but that they’ll probably be around longer than any open source products dabbling in trying to drum up revenue.
<p>Want to work inside the Interop NOC? We’re <a href="http://www.interop.com/blog/?p=408" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.interop.com');" target="_blank">looking for some great people to join the volunteer team at Interop</a>.
<p>And finally, snicker, snicker. Here’s a truly funny post on the <a href="http://weblog.infoworld.com/openresource/archives/2008/06/memo_to_broadco.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/weblog.infoworld.com');" target="_blank">Broadcom debacle</a>. </p>
<p><a href="http://sharethis.com/item?&wp=2.5.1&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Links+List+6.20.08&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Flinks-list-62008%2F06%2F2008" onclick="javascript:pageTracker._trackPageview('/outbound/article/sharethis.com');">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 20 Jun 2008 17:26:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/management tools change">management tools change</category>
      <category domain="http://securityratty.com/tag/source products">source products</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/management tools obsolete">management tools obsolete</category>
      <category domain="http://securityratty.com/tag/change">change</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/virtualization market">virtualization market</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <source url="http://blog.sciencelogic.com/links-list-62008/06/2008">Links List 6.20.08</source>
    </item>
  </channel>
</rss>
