<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: possibly]]></title>
    <link>http://securityratty.com/tag/possibly</link>
    <description></description>
    <pubDate>Thu, 25 Sep 2008 02:32:08 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Symantec's vision...]]></title>
      <link>http://securityratty.com/article/0a12c35a88cbf21c5df24b956fdc875d</link>
      <guid>http://securityratty.com/article/0a12c35a88cbf21c5df24b956fdc875d</guid>
      <description><![CDATA[And so it begins

Symantec bought out MessageLabs and is (in their own words) &quot;combining MessageLabs deep expertise in the SaaS market with Symantecs rich portfolio of technologies

The interesting...]]></description>
      <content:encoded><![CDATA[And so it begins...<br /><br /><a href="http://www.symantec.com/about/news/release/article.jsp?prid=20081008_02">Symantec bought out MessageLabs</a> and is (in their own words) "combining MessageLabs’ deep expertise in the SaaS market with Symantec’s rich  portfolio of technologies".<br /><br />The interesting thing is that Symantec does not really lead in the anti-virus market (in terms of quality, not market share. All antivirus products are about the same) or antispam (MessageLabs is excellent here).<br /><br />So, what could they possibly bring to the party that MessageLabs doesn't already have?<br /><br />DLP.<br /><br />MessageLabs has DLP but it is very simple and not really worth very much. The framework is certainly there though. Add some good DLP and voila - you have a product that is worth something.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/416721491" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 07:24:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/messagelabs">messagelabs</category>
      <category domain="http://securityratty.com/tag/messagelabs deep expertise">messagelabs deep expertise</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/dlp">dlp</category>
      <category domain="http://securityratty.com/tag/symantecs rich portfolio">symantecs rich portfolio</category>
      <category domain="http://securityratty.com/tag/saas market">saas market</category>
      <category domain="http://securityratty.com/tag/worth">worth</category>
      <category domain="http://securityratty.com/tag/anti-virus market">anti-virus market</category>
      <category domain="http://securityratty.com/tag/market share">market share</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/416721491/symantecs-vision.html">Symantec's vision...</source>
    </item>
    <item>
      <title><![CDATA[More on "Helping With Compliance" vs "Selling Using Compliance"]]></title>
      <link>http://securityratty.com/article/ba4460a1ff35b322ba94b7532397d8da</link>
      <guid>http://securityratty.com/article/ba4460a1ff35b322ba94b7532397d8da</guid>
      <description><![CDATA[So, here is a perfect example showing the idea I shared in my post &quot; Just A Thought on Compliance &quot;: the exact quote is &quot;its a vendors responsibility to make bearing the costs of PCI manageable

Did...]]></description>
      <content:encoded><![CDATA[So, <a href="http://www.infosecurity-magazine.com/news/081006_VendorsToSoftenBlowOfPCI.html">here</a> is a perfect example showing the idea I shared in my post "<a href="http://chuvakin.blogspot.com/2008/10/just-thought-on-compliance.html">Just A Thought on Compliance</a>":  the exact quote is "it’s a vendor’s responsibility to make bearing the  costs of PCI manageable."<br /><br />Did he say "it is vendor's role to 'sell stuff' using PCI." <span style="font-weight: bold;">God no!</span> He said that vendors will make PCI "bearable" for end-users. A big difference ...<br /><br />Yes, PCI DSS  is "a driver" for vendors to sell security tools AND "a sledgehammer" for end-users to "motivate" their bosses into releasing budget, but the reality is that PCI DSS compliance is a non-trivial challenge for many organizations, and that they need <span style="font-weight: bold;">HELP </span>more than they need "being sold to."<br /><br /><span style="font-style: italic;">And help is on its way...</span><br /><br /><span style="font-weight: bold;">Possibly related posts:</span><br /><ul><li>"<a href="http://chuvakin.blogspot.com/2008/10/just-thought-on-compliance.html">Just A Thought on Compliance</a>"</li></ul><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=gO5wM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=gO5wM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=TvrIM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=TvrIM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=hkemM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=hkemM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/415146058" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 09:37:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/pci dss compliance">pci dss compliance</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/vendors responsibility">vendors responsibility</category>
      <category domain="http://securityratty.com/tag/pci manageable">pci manageable</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/end-users">end-users</category>
      <category domain="http://securityratty.com/tag/exact quote">exact quote</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/415146058/more-on-helping-with-compliance-vs.html">More on "Helping With Compliance" vs "Selling Using Compliance"</source>
    </item>
    <item>
      <title><![CDATA[Mac security focus: Privacy]]></title>
      <link>http://securityratty.com/article/470cacce3a18698005889bf47ab1cad8</link>
      <guid>http://securityratty.com/article/470cacce3a18698005889bf47ab1cad8</guid>
      <description><![CDATA[At the very least, losing your wallet to a thief is a major pain in the neck: you lose your cash and (possibly) some precious mementos, and you have to cancel your credit cards and replace your...]]></description>
      <content:encoded><![CDATA[At the very least, losing your wallet to a thief is a major pain in the neck: you lose your cash and (possibly) some precious mementos, and you have to cancel your credit cards and replace your driver's license. More seriously, the thief could steal your identity, using your personal information to make purchases, get loans, or cause you all kinds of grief by pretending to be you.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=35950?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=35950?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/precious mementos">precious mementos</category>
      <category domain="http://securityratty.com/tag/credit cards">credit cards</category>
      <category domain="http://securityratty.com/tag/thief">thief</category>
      <category domain="http://securityratty.com/tag/major pain">major pain</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/purchases">purchases</category>
      <category domain="http://securityratty.com/tag/neck">neck</category>
      <category domain="http://securityratty.com/tag/possibly">possibly</category>
      <category domain="http://securityratty.com/tag/grief">grief</category>
      <source url="http://www.networkworld.com/news/2008/100808-mac-security-focus.html?fsrc=rss-security">Mac security focus: Privacy</source>
    </item>
    <item>
      <title><![CDATA[Presentation from SANS 2008 Lunch and Learn in Las Vegas]]></title>
      <link>http://securityratty.com/article/9e013f4069a35954694c89f4bb3e700d</link>
      <guid>http://securityratty.com/article/9e013f4069a35954694c89f4bb3e700d</guid>
      <description><![CDATA[As promised , here is my infamous presentation on &quot;Log management 'Worst Practices'&quot; that I gave at SANS Network Security 2008 yesterday

This presentation can also be considered a sequel to my...]]></description>
      <content:encoded><![CDATA[As <a href="http://chuvakin.blogspot.com/2008/10/my-lunch-presentation-at-sans-network.html">promised</a>, <a href="http://www.slideshare.net/anton_chuvakin/antons-log-management-worst-practices-presentation">here </a>is my infamous presentation on "Log management 'Worst Practices'" that I gave at SANS Network Security 2008 yesterday.<br /><br />This presentation can also be considered a sequel to my <a href="http://www.slideshare.net/anton_chuvakin/choosing-your-log-management-approach-buy-build-or-outsource">"Choosing a Log Management Approach" presentation</a>, which was my previous SANS Lunch and Learn preso.<br /><br />If you are involved / about to be involved with logging, read both (<a href="http://www.slideshare.net/anton_chuvakin/choosing-your-log-management-approach-buy-build-or-outsource">first</a>, <a href="http://www.slideshare.net/anton_chuvakin/antons-log-management-worst-practices-presentation">second</a>)!<br /><br />It is also embedded below:<br /><br /><div style="width: 425px; text-align: left;" id="__ss_635093"><a style="margin: 12px 0pt 3px; font-family: Helvetica,Arial,Sans-serif; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; display: block; text-decoration: underline;" href="http://www.slideshare.net/anton_chuvakin/antons-log-management-worst-practices-presentation?type=powerpoint" title="Anton's Log Management 'Worst Practices'">Anton's Log Management 'Worst Practices'</a><object style="margin: 0px;" width="425" height="355"><param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=sanslmworstpracticesd6oct2008-1223079958645247-8&amp;stripped_title=antons-log-management-worst-practices-presentation"><param name="allowFullScreen" value="true"><param name="allowScriptAccess" value="always"><embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=sanslmworstpracticesd6oct2008-1223079958645247-8&amp;stripped_title=antons-log-management-worst-practices-presentation" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View SlideShare <a style="text-decoration: underline;" href="http://www.slideshare.net/anton_chuvakin/antons-log-management-worst-practices-presentation?type=powerpoint" title="View Anton's Log Management 'Worst Practices' on SlideShare">presentation</a> or <a style="text-decoration: underline;" href="http://www.slideshare.net/upload?type=powerpoint">Upload</a> your own. (tags: <a style="text-decoration: underline;" href="http://slideshare.net/tag/chuvakin">chuvakin</a> <a style="text-decoration: underline;" href="http://slideshare.net/tag/logging">logging</a>)</div></div><br /><br /><br /><span style="font-weight: bold;">Possibly related material:</span><br /><ul><li>All my presentation on Slideshare.<br /></li></ul><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Ch9yM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Ch9yM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=27R3M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=27R3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0cfCM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0cfCM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/411284395" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 04 Oct 2008 07:11:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/view slideshare presentation">view slideshare presentation</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/log management approach">log management approach</category>
      <category domain="http://securityratty.com/tag/infamous presentation">infamous presentation</category>
      <category domain="http://securityratty.com/tag/slideshare">slideshare</category>
      <category domain="http://securityratty.com/tag/worst practices">worst practices</category>
      <category domain="http://securityratty.com/tag/previous sans lunch">previous sans lunch</category>
      <category domain="http://securityratty.com/tag/sans network security">sans network security</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/411284395/presentation-from-sans-2008-lunch-and.html">Presentation from SANS 2008 Lunch and Learn in Las Vegas</source>
    </item>
    <item>
      <title><![CDATA[Ifoothills.org Registrants Personal data and credit card numbers possibly stolen in Foothills Park & Recreation facilities Breach]]></title>
      <link>http://securityratty.com/article/04d4867c3a3abee4dcf6b258cb0a9664</link>
      <guid>http://securityratty.com/article/04d4867c3a3abee4dcf6b258cb0a9664</guid>
      <description><![CDATA[Foothills Park &amp; Recreation District in South Jefferson County is working with the Jefferson County Sheriffs Office in the investigation of a theft of personal information from the districts computer...]]></description>
      <content:encoded><![CDATA[Foothills Park &#38; Recreation District in South Jefferson County is working with the Jefferson County Sheriff’s Office in the investigation of a theft of personal information from the district’s computer network. The information have been accessed through an illegal hacking and could contain credit card information and other personal information that could be used to [...]]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 16:51:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/foothills park">foothills park</category>
      <category domain="http://securityratty.com/tag/credit card information">credit card information</category>
      <category domain="http://securityratty.com/tag/districts computer network">districts computer network</category>
      <category domain="http://securityratty.com/tag/south jefferson county">south jefferson county</category>
      <category domain="http://securityratty.com/tag/recreation district">recreation district</category>
      <category domain="http://securityratty.com/tag/illegal">illegal</category>
      <category domain="http://securityratty.com/tag/theft">theft</category>
      <source url="http://cyberinsecure.com/ifoothillsorg-registrants-personal-data-possibly-stolen-in-foothills-park-and-recreation-facilities-breach/">Ifoothills.org Registrants Personal data and credit card numbers possibly stolen in Foothills Park &amp; Recreation facilities Breach</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - September 2008]]></title>
      <link>http://securityratty.com/article/7bcc00d7fa1280bf6a276c7c821e4445</link>
      <guid>http://securityratty.com/article/7bcc00d7fa1280bf6a276c7c821e4445</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAIN</a> this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my poll</a>).&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a>. </li>    <li><a href="http://chuvakin.blogspot.com/search/label/ROI">Security ROI</a> - and its parent topic &quot;security metrics&quot;/&quot;measuring security&quot; - is definitely an ongoing <strong>HOT</strong> debate. Indeed, the old post <a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">&quot;</a><a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">Security ROI Pile-Up!</a><a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">&quot;</a> takes the #2 spot this month, possibly propelled by a more recent post &quot;<a href="http://chuvakin.blogspot.com/2008/09/second-roi-war.html">Second ROI War</a>.&quot;</li>    <li>Some say that &quot;short blog posts rule&quot;, but, in reality, good, fun content is the best. Here is an example:&#160; &quot;<a href="http://chuvakin.blogspot.com/2008/09/dumb-luck-is-strategy.html">Dumb Luck IS a Strategy!</a>&quot; post makes the top list. In it, I try to explore why people still ignore security concerns even if stare people in the face...</li>    <li>Discussion on what you can do to soften the impact of &quot;getting 0wned&quot; ( &quot;<a href="http://chuvakin.blogspot.com/2008/09/what-can-you-do.html">What CAN You Do?</a>&quot;) made the top list. Good!</li>    <li>As before, my post &quot;<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a>&quot;. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>) </li>    <li>Still burning hot is a post with my irreverent comments on a Terry Childs saga. Namely, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">On Doomsaying (Terry Childs case)</a>&quot;, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">So ... Am I? Maybe I Am!</a>&quot; and &quot;<a href="http://chuvakin.blogspot.com/2008/07/admins-good-guys-or-am-not-idiot.html">Admins , Good Guys or &quot;I am NOT an Idiot!&quot;</a>&quot; </li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in October.</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160;</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=IIM1M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=IIM1M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bxJsM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bxJsM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=fBKoM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=fBKoM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/408700309" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 12:19:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/security roi pile-up">security roi pile-up</category>
      <category domain="http://securityratty.com/tag/security roi">security roi</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/ignore security concerns">ignore security concerns</category>
      <category domain="http://securityratty.com/tag/security metrics">security metrics</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/408700309/monthly-blog-round-up-september-2008.html">Monthly Blog Round-Up - September 2008</source>
    </item>
    <item>
      <title><![CDATA[My Lunch Presentation at SANS Network Security 2008]]></title>
      <link>http://securityratty.com/article/3e189d6db26932e799c2dbea2b5e3bf5</link>
      <guid>http://securityratty.com/article/3e189d6db26932e799c2dbea2b5e3bf5</guid>
      <description><![CDATA[If you are at SANS Network Security 2008 in Vegas, come see me speak about &quot; 'Worst Practices' of Log Management .&quot; It is a fun presentation - and we ( LogLogic ) will feed you lunch. For those of you...]]></description>
      <content:encoded><![CDATA[If you are at SANS Network Security 2008 in Vegas, come see me speak <a href="http://www.sans.org/ns2008/vendor.php">about "<strong>'Worst Practices' of Log Management</strong>."</a> It is a fun presentation - and we (<a href="http://www.loglogic.com/">LogLogic</a>) will feed you lunch. For those of you who cannot make it,  I will release the slide deck here after I present it this last time...<br /><br />Here is the announcement:<br /><h5>LogLogic Lunch and Learn Presentation</h5><strong>'Worst Practices' of Log Management<br />Speaker:  Dr. Anton Chuvakin, GCIH, GCFA<br />Friday, October 3rd, 2008 * 12:30pm - 1:15 pm</strong><br /><br />BTW, I am arriving Thursday night, so if anybody wants to meet and "talk logs," please drop me an email.<br /><br /><span style="font-weight: bold;">Possibly relates posts:</span>s<br /><ul><li> <a href="http://www.slideshare.net/anton_chuvakin/slideshows">My other presentations on Slideshare</a></li></ul><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=CwOfM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=CwOfM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0QRQM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0QRQM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=9VNZM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=9VNZM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/408505537" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 07:19:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lunch">lunch</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/sans network security">sans network security</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/worst practices">worst practices</category>
      <category domain="http://securityratty.com/tag/loglogic lunch">loglogic lunch</category>
      <category domain="http://securityratty.com/tag/loglogic">loglogic</category>
      <category domain="http://securityratty.com/tag/anton chuvakin">anton chuvakin</category>
      <category domain="http://securityratty.com/tag/fun presentation">fun presentation</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/408505537/my-lunch-presentation-at-sans-network.html">My Lunch Presentation at SANS Network Security 2008</source>
    </item>
    <item>
      <title><![CDATA[Fun Presentation from Recent ISSA e-Conference]]></title>
      <link>http://securityratty.com/article/729255ecd910e8e121a27073e3b64f2f</link>
      <guid>http://securityratty.com/article/729255ecd910e8e121a27073e3b64f2f</guid>
      <description><![CDATA[Again, while I am not blogging like mad, here is another presentation on logging. This baby is a big philosophical and mildly inspired by Dan Geer and it looks into connections between logging and...]]></description>
      <content:encoded><![CDATA[Again, while I am not blogging like mad, here is another presentation on logging.  <a href="http://www.slideshare.net/anton_chuvakin/logs-accountability-presentation">This baby</a> is a big philosophical  and mildly inspired by Dan Geer and it looks into connections between logging and broader concept of "accountability," as it is defined in IT and even beyond. I also explore the ideas that "controls don't scale, while monitoring/logging does."<br /><br />The presentation is also embedded below:<br /><br /><div style="width:425px;text-align:left" id="__ss_620729"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin/logs-accountability-presentation?type=powerpoint" title="Logs = Accountability">Logs = Accountability</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=isc2logsaccountabilityjul2008rel-1222464889669894-9&stripped_title=logs-accountability-presentation" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=isc2logsaccountabilityjul2008rel-1222464889669894-9&stripped_title=logs-accountability-presentation" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View SlideShare <a style="text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin/logs-accountability-presentation?type=powerpoint" title="View Logs = Accountability on SlideShare">presentation</a> or <a style="text-decoration:underline;" href="http://www.slideshare.net/upload?type=powerpoint">Upload</a> your own. (tags: <a style="text-decoration:underline;" href="http://slideshare.net/tag/logs">logs</a> <a style="text-decoration:underline;" href="http://slideshare.net/tag/chuvakin">chuvakin</a>)</div></div><br /><br />Enjoy!<br /><br /><span style="font-weight: bold;">Possibly related posts:</span><ul><li><h3 class="post-title"><a href="http://chuvakin.blogspot.com/2008/01/logs-accountability.html">Logs = Accountability!</a></h3></li></ul><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=A39AL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=A39AL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=gWcgL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=gWcgL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=19vlL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=19vlL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/406929430" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 14:13:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/logs chuvakin">logs chuvakin</category>
      <category domain="http://securityratty.com/tag/chuvakin">chuvakin</category>
      <category domain="http://securityratty.com/tag/view slideshare presentation">view slideshare presentation</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/accountability">accountability</category>
      <category domain="http://securityratty.com/tag/dan geer">dan geer</category>
      <category domain="http://securityratty.com/tag/broader concept">broader concept</category>
      <category domain="http://securityratty.com/tag/connections">connections</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/406929430/fun-presentation-from-recent-issa-e.html">Fun Presentation from Recent ISSA e-Conference</source>
    </item>
    <item>
      <title><![CDATA[Presentation from GOVCERT.NL 2008: Log Forensics]]></title>
      <link>http://securityratty.com/article/1090cdb96e29f72b502edcce4e86634c</link>
      <guid>http://securityratty.com/article/1090cdb96e29f72b502edcce4e86634c</guid>
      <description><![CDATA[While I am too busy too blog [I will explain why soon!], I wanted to give my readers some fun logging and security stuff to read

So, I am releasing one of my favorite presentations, the one on log...]]></description>
      <content:encoded><![CDATA[While I am too busy too blog [I will explain why soon!], I wanted to give my readers some fun logging and security stuff to read.<br /><br />So, I am releasing one of my favorite presentations, the one on log forensics, in its newest expanded form: "<a href="http://www.slideshare.net/anton_chuvakin/logs-for-incident-response-and-forensics-key-issues-for-govcertnl-2008-presentation-620704">Logs for Incident Response and Forensics: Key Issues for GOVCERT.NL 2008</a>"<br /><br />Here it is also embedded below:<br /><br /><div style="width:425px;text-align:left" id="__ss_620704"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin/logs-for-incident-response-and-forensics-key-issues-for-govcertnl-2008-presentation-620704?type=powerpoint" title="Logs for Incident Response and Forensics: Key Issues for GOVCERT.NL 2008">Logs for Incident Response and Forensics: Key Issues for GOVCERT.NL 2008</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=logsincidentforensicsgovcert08rel-1222463958016243-9&stripped_title=logs-for-incident-response-and-forensics-key-issues-for-govcertnl-2008-presentation-620704" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=logsincidentforensicsgovcert08rel-1222463958016243-9&stripped_title=logs-for-incident-response-and-forensics-key-issues-for-govcertnl-2008-presentation-620704" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View SlideShare <a style="text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin/logs-for-incident-response-and-forensics-key-issues-for-govcertnl-2008-presentation-620704?type=powerpoint" title="View Logs for Incident Response and Forensics: Key Issues for GOVCERT.NL 2008 on SlideShare">presentation</a> or <a style="text-decoration:underline;" href="http://www.slideshare.net/upload?type=powerpoint">Upload</a> your own. (tags: <a style="text-decoration:underline;" href="http://slideshare.net/tag/chuvakin">chuvakin</a> <a style="text-decoration:underline;" href="http://slideshare.net/tag/response">response</a>)</div></div><br /><br />Enjoy!<br /><br /><span style="font-weight: bold;">Possibly related:</span><br /><ul><li><a href="http://www.slideshare.net/anton_chuvakin/slideshows">All my presentations on slideshare</a></li><li><a href="http://www.chuvakin.org/secpublic.html">My speaking ops (past and future)</a><br /></li></ul><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=gNGSL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=gNGSL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=DexnL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=DexnL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mBV0L"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mBV0L" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/404193461" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 11:24:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log forensics">log forensics</category>
      <category domain="http://securityratty.com/tag/forensics">forensics</category>
      <category domain="http://securityratty.com/tag/slideshare">slideshare</category>
      <category domain="http://securityratty.com/tag/govcert">govcert</category>
      <category domain="http://securityratty.com/tag/incident response">incident response</category>
      <category domain="http://securityratty.com/tag/view slideshare presentation">view slideshare presentation</category>
      <category domain="http://securityratty.com/tag/key issues">key issues</category>
      <category domain="http://securityratty.com/tag/favorite presentations">favorite presentations</category>
      <category domain="http://securityratty.com/tag/chuvakin">chuvakin</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/404193461/presentation-from-govcertnl-2008-log.html">Presentation from GOVCERT.NL 2008: Log Forensics</source>
    </item>
    <item>
      <title><![CDATA[$20M Cameras at New York's Freedom Tower are Pretty Sophisticated]]></title>
      <link>http://securityratty.com/article/1854e20c6c17653e3ad8d28eb7bdb765</link>
      <guid>http://securityratty.com/article/1854e20c6c17653e3ad8d28eb7bdb765</guid>
      <description><![CDATA[They're trying to detect anomalies : If you have ever wondered how security guards can possibly keep an unfailingly vigilant watch on every single one of dozens of television monitors, each depicting...]]></description>
      <content:encoded><![CDATA[<p>They're trying to <a href="http://cityroom.blogs.nytimes.com/2008/09/24/unblinking-eyes-for-20-million-at-freedom-tower/">detect anomalies</a>:</p>

<blockquote>If you have ever wondered how security guards can possibly keep an unfailingly vigilant watch on every single one of dozens of television monitors, each depicting a different scene, the answer seems to be (as you suspected): they can't.

<p>Instead, they can now rely on computers to constantly analyze the patterns, sizes, speeds, angles and motion picked up by the camera and determine -- based on how they have been programmed -- whether this constitutes a possible threat. In which case, the computer alerts the security guard whose own eyes may have been momentarily diverted. Or shut.</p>

<p>An alarm can be raised, for instance, if the computer discerns a vehicle that has been standing still for too long (say, a van in the drop-off lane of an airport terminal) or a person who is loitering while everyone else is in motion. By the same token, it will spot the individual who is moving rapidly while everyone else is shuffling along. It can spot a package that has been left behind and identify which figure in the crowd abandoned it. Or pinpoint the individual who is moving the wrong way down a one-way corridor.</p>

<p>Because one person's "abnormal situation" is another person's "hot dog vendor attracting a small crowd," the computers can be programmed to discern between times of the day and days of the week.</blockquote></p>

<p>Certainly interesting.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=y6WlL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=y6WlL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=IzyVL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=IzyVL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 02:32:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/person">person</category>
      <category domain="http://securityratty.com/tag/hot dog vendor">hot dog vendor</category>
      <category domain="http://securityratty.com/tag/security guards">security guards</category>
      <category domain="http://securityratty.com/tag/individual">individual</category>
      <category domain="http://securityratty.com/tag/unfailingly vigilant">unfailingly vigilant</category>
      <category domain="http://securityratty.com/tag/constantly analyze">constantly analyze</category>
      <category domain="http://securityratty.com/tag/security guard">security guard</category>
      <category domain="http://securityratty.com/tag/detect anomalies">detect anomalies</category>
      <category domain="http://securityratty.com/tag/television monitors">television monitors</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/20m_cameras_at.html">$20M Cameras at New York's Freedom Tower are Pretty Sophisticated</source>
    </item>
  </channel>
</rss>
