<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: queries]]></title>
    <link>http://securityratty.com/tag/queries</link>
    <description></description>
    <pubDate>Fri, 05 Sep 2008 10:25:35 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Google Trends Labs Abused By Cybercriminals To Spread Malware]]></title>
      <link>http://securityratty.com/article/4ea1cd9db70bcac5a0266b22111315ab</link>
      <guid>http://securityratty.com/article/4ea1cd9db70bcac5a0266b22111315ab</guid>
      <description><![CDATA[According to a recent advisory issued by Webroot, cybecriminals are exploiting the search engines by monitoring the peak traffic for popular search queries using Googles Trend Labs and syndicating the...]]></description>
      <content:encoded><![CDATA[According to a recent advisory issued by Webroot, cybecriminals are exploiting the search engines by monitoring the peak traffic for popular search queries using Google’s Trend Labs and syndicating the keywords in order to acquire the traffic and direct it to malware serving blogs primarily hosted at Windows Live’s Spaces.
For the first time, hackers are [...]]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 17:59:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows lives spaces">windows lives spaces</category>
      <category domain="http://securityratty.com/tag/googles trend labs">googles trend labs</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/peak traffic">peak traffic</category>
      <category domain="http://securityratty.com/tag/blogs primarily">blogs primarily</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/recent advisory">recent advisory</category>
      <category domain="http://securityratty.com/tag/engines">engines</category>
      <category domain="http://securityratty.com/tag/direct">direct</category>
      <source url="http://cyberinsecure.com/google-trends-labs-abused-by-cybercriminals-to-spread-malware/">Google Trends Labs Abused By Cybercriminals To Spread Malware</source>
    </item>
    <item>
      <title><![CDATA[Syndicating Google Trends Keywords for Blackhat SEO]]></title>
      <link>http://securityratty.com/article/c56eb4f87e14b19e95246ca1bd8a55dd</link>
      <guid>http://securityratty.com/article/c56eb4f87e14b19e95246ca1bd8a55dd</guid>
      <description><![CDATA[Several hundred Windows Live Spaces and AOL Journals , are currently syndicating the most popular keywords provided by Google Trends, and are consequently hijacking the top search queries exposing...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOXPRRoj3fI/AAAAAAAACPQ/DGGVEuUQaUc/s1600-h/bogus_blogs_google_trends_malware.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOXPRRoj3fI/AAAAAAAACPQ/fIYx1pvZfIM/s200-R/bogus_blogs_google_trends_malware.JPG" /></a>Several hundred <a href="http://blogs.zdnet.com/security/?p=1995">Windows Live Spaces and AOL Journals</a>, are currently syndicating the most popular keywords provided by Google Trends, and are consequently <a href="http://www.webroot.com/En_US/about-press-room-press-releases-hackers-using-real-headlines.html">hijacking the top search queries</a> exposing users to Zlob codecs.<br />
<br />
Here are some same bogus blogs used in the campaign, naturally pre-registered long before they executed it :<br />
<br />
<b>vinniedigg18 .spaces.live.com</b><br />
<b>journals.aol .com/iolatour16</b><br />
<b>fredabreak02 .spaces.live.com</b><br />
<b>thedaalerts01 .spaces.live.com</b><br />
<b>allisonpolls08 .spaces.live.com</b><br />
<b>rheabreak18 .spaces.live.com</b><br />
<b>racquellog17 .spaces.live.com</b><br />
<b>monikavideo11 .spaces.live.com</b><br />
<b>journals.aol .com/shelvakill27</b><br />
<b>tomekadigg26 .spaces.live.com</b><br />
<b>ivahnet19 .spaces.live.com</b><br />
<b>journals.aol .com/louisathere13</b><br />
<b>allisonpolls08 .spaces.live.com</b><br />
<b>valericatch03 .spaces.live.com</b><br />
<b>journals.aol .com/iolatour16</b><br />
<b>hadleycue01 .spaces.live.com</b><br />
<b>journals.aol .com/staceyliving01</b><br />
<b>collettebreak17 .spaces.live.com</b><br />
<b>journals.aol .com/nataliablog16</b><br />
<b>natalymore26 .spaces.live.com<br />
</b><br />
<br />
<a href="http://www.filefactory.com/file/4faafd/n/rogue_blogs_google_trends_txt">A comprehensive listing of the blogs involved can be downloaded here</a>. <br />
<br />
<div class="separator" style="clear: both; text-align: center;"><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOXYvtGnGWI/AAAAAAAACPY/7WDPIuBn5Eg/s1600-h/google_trends_blackhat_SEO.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOXYvtGnGWI/AAAAAAAACPY/3Ph-I65avew/s200-R/google_trends_blackhat_SEO.png" /></a></div>What do all of these bogus blogs have in common? The fact that they are all being abused by a single malware campaign, and the Keep it Simple Stupid mentality only a lazy malware campaigner can take advantage of. All of the blogs as using a central redirection domain, shutting it down or blocking it renders the number of bogus blogs is circulation irrelevant. In this case, the domain in question is <b>video.xmancer.org</b> (216.195.59.75).<br />
<br />
Here are the the rest of the domains participating in the campaign, as well as the parked ones at the corresponding IPs :<br />
<br />
<b>video.xmancer .org</b> (216.195.59.75)<br />
<b>buynowbe .com<br />
loveniche .com<br />
antivirus-freecheck .com<br />
jetelephone .cn<br />
reducki .cn<br />
woteenhas .cn<br />
lilaloft .cn</b><br />
<br />
<b>clipztimes .com</b> (78.157.143.235)<br />
<b>imagelized .com<br />
vidzdaily .com</b><br />
<br />
<b>gotmovz .com</b> (78.108.177.91) <br />
<b>dwnld-clips .com</b><br />
<br />
<b>movwmstream .com</b> (77.91.231.183)<br />
<b>newwmpupdate .com<br />
zaeplugin .com<br />
movaccelerator .com<br />
optimwares .com<br />
piterserv .com</b><br />
<br />
<b>moviesportal2008p .com</b> (72.232.183.154)<br />
<b>movieportal2008a .com<br />
funnyportal2008l .com<br />
starsportal2008p .com<br />
softportal2008p .com<br />
movieportal2008q .com</b><br />
<br />
In short, despite that the campaign is poised to attract generic search traffic, it's a self-exposing blackhat SEO campaign since each and every blog participating is also linking to the rest of the ones within the ecosystem.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/blackhat-seo-campaign-at-millennium.html">Blackhat SEO Campaign at The Millennium Challenge Corporation</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">Massive IFRAME SEO Poisoning Attack Continuing</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/massive-blackhat-seo-targeting-blogspot.html">Massive  Blackhat SEO Targeting Blogspot</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/invisible-blackhat-seo-campaign.html">The  Invisible Blackhat SEO Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2007/01/attack-of-seo-bots-on-edu-domain.html">Attack  of the SEO Bots on the .EDU Domain</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/p0rngov-ongoing-blackhat-seo-operation.html">p0rn.gov  - The Ongoing Blackhat SEO Operation</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign.html">The Continuing .Gov Blackat SEO Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign_25.html">The Continuing .Gov Blackhat SEO Campaign - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/compromised-sites-serving-malware-and.html">Compromised Sites Serving Malware and Spam</a><b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uwRsM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uwRsM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LdmhM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LdmhM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eqMbm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eqMbm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=igiam"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=igiam" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iONDM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iONDM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0QewM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0QewM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6xSvm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6xSvm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/410092478" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 00:19:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spaces">spaces</category>
      <category domain="http://securityratty.com/tag/windows live spaces">windows live spaces</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/live">live</category>
      <category domain="http://securityratty.com/tag/single malware campaign">single malware campaign</category>
      <category domain="http://securityratty.com/tag/aol journals">aol journals</category>
      <category domain="http://securityratty.com/tag/journals">journals</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/blackhat seo campaign">blackhat seo campaign</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/410092478/syndicating-google-trends-keywords-for.html">Syndicating Google Trends Keywords for Blackhat SEO</source>
    </item>
    <item>
      <title><![CDATA[IT Security Ask the Experts: Top Queries, September 2008]]></title>
      <link>http://securityratty.com/article/ee48bd16afde490130e4c145de2d914c</link>
      <guid>http://securityratty.com/article/ee48bd16afde490130e4c145de2d914c</guid>
      <description><![CDATA[Our Web site was created to be a clearing house for technical IT security queries, and we are still fielding quite a few of those. But we continue to receive a broad variety of fascinating questions...]]></description>
      <content:encoded><![CDATA[Our Web site was created to be a clearing house for technical IT security queries, and we are still fielding quite a few of those. But we continue to receive a broad variety of fascinating questions e...]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 09:31:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/broad variety">broad variety</category>
      <category domain="http://securityratty.com/tag/security queries">security queries</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/house">house</category>
      <category domain="http://securityratty.com/tag/questions">questions</category>
      <category domain="http://securityratty.com/tag/technical">technical</category>
      <category domain="http://securityratty.com/tag/receive">receive</category>
      <category domain="http://securityratty.com/tag/continue">continue</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/409612019/">IT Security Ask the Experts: Top Queries, September 2008</source>
    </item>
    <item>
      <title><![CDATA[Monetizing Infected Hosts by Hijacking Search Results]]></title>
      <link>http://securityratty.com/article/30b128b9fa2c48983d32dbcc4818d136</link>
      <guid>http://securityratty.com/article/30b128b9fa2c48983d32dbcc4818d136</guid>
      <description><![CDATA[When logs with accounting data are no longer of interest due to low liquidity on the underground market, monetization of the infected hosts comes into play

This web based malware seems like an early...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOPovcbgMHI/AAAAAAAACNY/PtnyHCXQm30/s1600-h/pict1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOPovcbgMHI/AAAAAAAACNY/kLv97AsLUco/s200-R/pict1.jpg" /></a>When logs with accounting data are no longer of interest due to low liquidity on the underground market, monetization of the infected hosts comes into play.<br />
<br />
This web based malware seems like an early BETA aiming to scale, however it's only unique features are its ability to hijack the infected user's searches and server relevant ads courtesy of the affiliate networks the administrator participates in, and also, an integrated DDoS module that the author simply stole from another kit. Strangely, it's 2008 yet the author also included the ability to turn on the telnet service on an infected host. <br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZH-8W6ZI/AAAAAAAACOQ/DVWUfx2tkJg/s1600-h/pict2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZH-8W6ZI/AAAAAAAACOQ/kSX1geifdWA/s200-R/pict2.jpg" /></a>With the search queries feature easy to duplicate by other kits, this web based malware is a great example of how the time-to-market mentality lacking any kind of personal experience -- the malware cannot intercept SSL sessions compared to the majority of crimeware kits that can -- ends up in a weird hybrid of random features.<br />
&nbsp; <br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZQQsgnMI/AAAAAAAACOY/f1UOwGyrhSo/s1600-h/pict3.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZQQsgnMI/AAAAAAAACOY/4K4tbpQnUys/s200-R/pict3.jpg" /></a><a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Customerization</a> will inevitably prevail over the product concept mentality.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dgQOM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dgQOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oQzAM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oQzAM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1wqEm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1wqEm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4U2Mm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4U2Mm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DbC0M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DbC0M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=605TM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=605TM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9wzem"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9wzem" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409220865" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 03:33:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/web based malware">web based malware</category>
      <category domain="http://securityratty.com/tag/kits">kits</category>
      <category domain="http://securityratty.com/tag/author simply">author simply</category>
      <category domain="http://securityratty.com/tag/author">author</category>
      <category domain="http://securityratty.com/tag/crimeware kits">crimeware kits</category>
      <category domain="http://securityratty.com/tag/intercept ssl sessions">intercept ssl sessions</category>
      <category domain="http://securityratty.com/tag/product concept mentality">product concept mentality</category>
      <category domain="http://securityratty.com/tag/queries feature easy">queries feature easy</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409220865/monetizing-infected-hosts-by-hijacking.html">Monetizing Infected Hosts by Hijacking Search Results</source>
    </item>
    <item>
      <title><![CDATA[The Genesis of Complex Event Processing: Asymmetric Capabilities]]></title>
      <link>http://securityratty.com/article/58ed1db82fe051447218ff6d60c32d71</link>
      <guid>http://securityratty.com/article/58ed1db82fe051447218ff6d60c32d71</guid>
      <description><![CDATA[More often than not, folks working in the field of complex event processing do not truly understand CEP. We often see the same folks try to position and mischaracterize CEP as business process...]]></description>
      <content:encoded><![CDATA[<p>More often than not, folks working in the field of complex event processing do not truly understand CEP.   We often see the same folks try to position and mischaracterize CEP as business process orchestration, business process management, event-driven architecture or even an evolution of service-oriented architecture.    Well-intended, this mischaracterization of CEP is often for sales and marketing purposes.  However, sometimes the mischaracterization of CEP is from a lack of understanding of what CEP was designed to accomplish.  These mischaracterizations have very little to do with the original intent of complex event processing.</p>
<p>Originally, researchers in CEP were not trying to solve a problem of streaming data or streaming events.   Often we read this mischaracterization by folks in the database/streaming domain, as they were focused on the low latency processing of streaming events.   A natural extension of this research has been stream processing software (often called &#8220;engines&#8221;) that process streaming data with continuous queries, for example market data feeds for algo-trading or best market order execution.  This mischaracterization is partly responsible for why we see many order processing applications in market data stream processing mislabled as &#8220;complex event processing&#8221; applications.</p>
<p>The genesis of complex event processing was not the stream processing need for &#8220;feeds and speed&#8221; but the processing capability to solve what can be characterized as the &#8220;problem of asymmetric capabilties&#8221;.   The term &#8220;asymmetric&#8221; has been used in the military domain. For example we often hear the term &#8220;<a href="http://en.wikipedia.org/wiki/Asymmetric_warfare" target="_blank">asymmetric warfare</a>.&#8221;  However, in general the concept of &#8220;asymmetrical processing capablities&#8221; is the true genesis for CEP and related processing concepts and domains.   It is this genesis that distinguishes CEP from EDA, SOA, SOR, and so many other technology oriented concepts.</p>
<p>In order to illustrate what I mean by &#8220;asymmetrical processing capablities&#8221; we will take the example of the evolution of rocketry.    In the early days, scientists learned how to make rockets, I assume with gunpowder and similar chemical compounds to launch rockets.   Over many years the application of rocketry advanced much faster than the ability to understand the situations created in the sky.    In other words, folks could fill the skies with rockets long before they had the capability to track and identify (or sense and respond to)  the rockets in real time.</p>
<p>Therefore, the concept of &#8220;asymmetrical processing capablities&#8221; is the situation where there is a capability, such as &#8220;launch a rocket, sense-and-respond,&#8221; that is asymmetric in nature.    In other words, the capability to detect multiple rocket launches creates an asymmetric situation where it is easy to launch rockets, but hard to detect and defend against those launches.</p>
<p>The same concept can be applied to everyday air travel.   If we could only fly airplanes, but did not have the capability to track the planes, understand situations in airspace, and then respond to changing situations, air travel would be quite difficult.   Lucky for us, the global traveller, there is symmetry in the capabilities to build and fly aircraft and the capabilities to detect, track and follow the evolving situations in the sky.</p>
<p>The genesis of CEP was to solve the problem of asymmetry in cyberspace, or if you prefer, distributed data networks.   The folks who identified, early on,  the problems associated with asymmetry in cyberspace were folks working the the field of network and security management.    This is because there has been, and is currently, a great asymmetry between the capablities to &#8220;launch a process or transaction&#8221; in cyberspace and the capabilties to detect and track what is going on in the same domain.</p>
<p>In my next post on this topic, we will go into some details of this asymmetry and review the first CEP projects from Stanford University in the context of asymmetric processing capabilities in cyberspace.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 13:31:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/asymmetric">asymmetric</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/market data stream">market data stream</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/term asymmetric warfare">term asymmetric warfare</category>
      <category domain="http://securityratty.com/tag/term asymmetric">term asymmetric</category>
      <category domain="http://securityratty.com/tag/distinguishes cep">distinguishes cep</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/asymmetric capabilties">asymmetric capabilties</category>
      <source url="http://www.thecepblog.com/2008/09/29/the-genesis-of-complex-event-processing-asymmetric-capabilites/">The Genesis of Complex Event Processing: Asymmetric Capabilities</source>
    </item>
    <item>
      <title><![CDATA[TIBCO BusinessEvents 3.0]]></title>
      <link>http://securityratty.com/article/de1f0c5b81d2a653775eaade21547299</link>
      <guid>http://securityratty.com/article/de1f0c5b81d2a653775eaade21547299</guid>
      <description><![CDATA[I was pleased to read the Paul Vincents post, TIBCO BusinessEvents 3.0 . TIBCO has always had a forward thinking vision for distributed computing and this release of BE 3.0 is another step in the...]]></description>
      <content:encoded><![CDATA[<p>I was pleased to read the Paul Vincent&#8217;s post, <a title="Permalink" href="http://tibcoblogs.com/cep/2008/09/22/tibco-businessevents-30/">TIBCO BusinessEvents 3.0</a>.    TIBCO has always had a forward thinking vision for distributed computing and this release of BE 3.0 is another step in the right direction.  TIBCO now has the only commercial-off-the-shelf (COTS) event processing platform on the market that supports distributed event processing, multi-agent architectures, distributed object caching, extensibility, continuous queries, state management and state-of-the-art rules.</p>
<p>Even thought TIBCO&#8217;s BusinessEvents does not yet support Bayesian Classifiers, Artificial Neural Networks and other advanced decision support algorithms, it is just a matter of time before TIBCO will add these advanced features &#8220;out of the box&#8221;.  On the other hand, the extensible nature of TIBCO&#8217;s BE makes it possible to add probabalistic computing functionality, however this requires quite a lot of programming and integration work.</p>
<p>When I see a great release like this for TIBCO, it makes me a little nostalgic for &#8220;the good old days&#8221; travelling the world in the front of the aircraft for TIBCO.   TIBCO has a rich and diverse customer base.  This customer base includes financial services companies; however, TIBCO is much less dependent on financial services than other event processing companies.   So, with TIBCO you not only get great technology, but rock-solid stability in an unstable and uncertain business world.</p>
<p>As a side note, an S&amp;P analyst recently <a href="http://www.thecepblog.com/2008/09/18/sp-downgrades-tibco-to-sell-on-financial-services-exposure/" target="_blank">downgraded</a> TIBCO&#8217;s stock <a href="http://online.barrons.com/quotes/main.html?symbol=tibx">(TIBX)</a>, primarily due to chao in the financial services sector.    Because of TIBCO&#8217;s global reach and stability, plus forward vision, advanced technologies and many years of commericial success, the S&amp;P downgrade will create a buying opportunity for TIBCO stock.</p>
]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 01:54:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tibco businessevents">tibco businessevents</category>
      <category domain="http://securityratty.com/tag/tibco">tibco</category>
      <category domain="http://securityratty.com/tag/tibco stock">tibco stock</category>
      <category domain="http://securityratty.com/tag/tibcos">tibcos</category>
      <category domain="http://securityratty.com/tag/tibcos businessevents">tibcos businessevents</category>
      <category domain="http://securityratty.com/tag/tibcos global reach">tibcos global reach</category>
      <category domain="http://securityratty.com/tag/financial services">financial services</category>
      <category domain="http://securityratty.com/tag/financial services sector">financial services sector</category>
      <category domain="http://securityratty.com/tag/vision">vision</category>
      <source url="http://www.thecepblog.com/2008/09/24/tibco-businessevents-30/">TIBCO BusinessEvents 3.0</source>
    </item>
    <item>
      <title><![CDATA[Spam Campaign Abusing Yahoo's Services]]></title>
      <link>http://securityratty.com/article/c2626f449f476aba6a0e3171d77be643</link>
      <guid>http://securityratty.com/article/c2626f449f476aba6a0e3171d77be643</guid>
      <description><![CDATA[Think spammers.Yahoo.com trusts Yahoo.com, consequently, a spam campaign that using bogus Yahoo.com email accounts, and spamming only Yahoo users with links to Yahoo's search engine using queries...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SNEJZU3UKFI/AAAAAAAACKk/nL7rnM4boe0/s1600-h/captcha_outsource_bogus_accounts_yahoo1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SNEJZU3UKFI/AAAAAAAACKk/G05GItHoyBs/s200-R/captcha_outsource_bogus_accounts_yahoo1.JPG" /></a>Think spammers.Yahoo.com trusts Yahoo.com, consequently, a spam campaign that using bogus Yahoo.com email accounts, and spamming only Yahoo users with links to Yahoo's search engine using queries leading to the exact spammer's URLs, is almost 100% sure to make it through spam filters. That seems to be case with this spam campaign perfectly fitting into the "spam that made it through" category.<br />
<br />
<b>Sample search queries resulting in a single result with the spammer's URL :</b><br />
- yahoo.com/////////////////////////////search/search;_ylt=?p=())))))))))))))callfold(((((((((((((((()))))))))))((((()))))))5000)))))))))))(((((((<br />
- search.yahoo.com/search?p=(((((())))))))((((((((((((((housetear((((())))))(((((((())))))))(((((((((5000((((((())))))))))))))))))))<br />
- yahoo.com/search/search;_ylt=?p=]]]]]]]]]]]][[[[[[galestay[[]]]]]]][[[[[[[[[[[[[[[[[[[[$229[[[[[[[[[[[[[[[[[[[]]]]<br />
- yahoo.com/search/search;_ylt=?p=(((((())))))))))galestay((((((()((((((((((((((((($229)))))))))))(((()<br />
- yahoo.com/////////////////////////////search/search;_ylt=?p=))))))))))))))(((((richorbit((((((((((((((())))))))))))((((((())))))$229)))))))))))(((((((<br />
- yahoo.com/////////////////////////////search/search;_ylt=?p=))))))(((())))))))))richorbit((((((((((((())))))))((((((((((((((((((((((((((((($229))))))((((())<br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SNEMVvsjNOI/AAAAAAAACKw/8DNIdG5HwUw/s1600-h/captcha_outsource_bogus_accounts_yahoo2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SNEMVvsjNOI/AAAAAAAACKw/L0wwRor-SUQ/s200-R/captcha_outsource_bogus_accounts_yahoo2.JPG" /></a><br />
The search queries lead to<b> galestay.com; housetear.com; callfold.com; richorbit.com</b> with several hundred spam domains participating in the campaign parked at <b>218.61.7.21</b> and <b>220.248.185.64</b>.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SNEOBcMV7WI/AAAAAAAACK4/Agv8JwvW6WY/s1600-h/king_replicas_spam.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="160" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SNEOBcMV7WI/AAAAAAAACK4/OmHHnCUAIHc/s200-R/king_replicas_spam.png" width="200" /></a>With CAPTCHA solving and automatic account registration getting easier to outsource next to the easily obtainable <a href="http://ddanchev.blogspot.com/2008/05/segmenting-and-localizing-spam.html">segmented email databases of a particular ISP or web based email service provider</a>, launching such a campaign requires less efforts than it used to before. Interestingly, the spammed through Yahoo emails never leave Yahoo Mail since it's only spamming Yahoo users according to the extensive number of emails CC-ed.<br />
<br />
What's to come in the long-term? With an entire spamming infrastructure build on the foundation of the hundreds of thousands of bogus accounts at legitimate services, spammers are already starting to embrace the "legitimate sender" mentality and<b> </b>are working on ways to integrate that infrastructure in their spam systems, evidence of which can be seen in several <a href="http://blogs.zdnet.com/security/?p=1899">different managed spamming services</a>.<br />
<br />
<b>Related posts:</b><br />
<a href="http://blogs.zdnet.com/security/?p=1232">Microsoft’s CAPTCHA successfully broken</a><br />
<a href="http://blogs.zdnet.com/security/?p=1418">Gmail, Yahoo and Hotmail’s CAPTCHA broken by spammers</a><br />
<a href="http://blogs.zdnet.com/security/?p=1514">Spam coming from free email providers increasing</a><br />
<a href="http://blogs.zdnet.com/security/?p=1835">Inside India’s CAPTCHA solving economy</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=tyomL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=tyomL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RprrL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RprrL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LDOil"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LDOil" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cIk3l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cIk3l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xSFKL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xSFKL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5sTAL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5sTAL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IVbIl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IVbIl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/395238291" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 05:25:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/yahoo">yahoo</category>
      <category domain="http://securityratty.com/tag/spam campaign perfectly">spam campaign perfectly</category>
      <category domain="http://securityratty.com/tag/spam campaign">spam campaign</category>
      <category domain="http://securityratty.com/tag/yahoo users">yahoo users</category>
      <category domain="http://securityratty.com/tag/spam systems">spam systems</category>
      <category domain="http://securityratty.com/tag/spam domains">spam domains</category>
      <category domain="http://securityratty.com/tag/yahoo emails">yahoo emails</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/395238291/spam-campaign-abusing-yahoos-services.html">Spam Campaign Abusing Yahoo's Services</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Routing Out an Address; Badger-Fi]]></title>
      <link>http://securityratty.com/article/47e82ddcf180a1e8e117a5087166b7f3</link>
      <guid>http://securityratty.com/article/47e82ddcf180a1e8e117a5087166b7f3</guid>
      <description><![CDATA[Slashdot breathlessly posts an item by coderrr that Skyhook Wireless is exposing people's addresses: Yeah, whatever. Skyhook has accidentally offered an API that lets you query their Wi-Fi positioning...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://hardware.slashdot.org/article.pl?sid=08/09/12/1255218"><strong>Slashdot breathlessly posts an item by coderrr that Skyhook Wireless is exposing people's addresses:</strong></a> Yeah, whatever. Skyhook has accidentally offered an API that lets you query their Wi-Fi positioning system for latitude and longitude using a MAC address. Skyhook constantly drives major cities around the world and integrates scans created by users of their systems as well. The poster defines a non-existent problem: first, a scammer needs to get someone's MAC address; then you need to pair a rough lat/long with their street address; then, coderrr says, you'd get a phishing email with your home address. Whatever. If my machine is compromised enough that you can obtain my MAC address and then launch a phishing attack, I have worse problems already than my street address being in the email--which is unlikely given that most Wi-Fi scans will be in urban areas. It's likely Skyhook will modify their systems to prevent submission of such queries, or perhaps open their API further.</p>

<p><a href="http://badgerherald.com/news/2008/09/12/atlanta_firm_buys_ci.php"><strong>Madison Wi-Fi network sold to Atlanta firm:</strong></a> Xiocom purchases Mad City Broadband, a firm that has suffered significant criticism over the performance of its Wi-Fi network in Madison, Wisc. The press release from Xiocom (some quoted in the Badger Herald article) are a bit over the top about a network that reportedly has few users, inconsistent performance, and covers only a fraction of the city.</p>]]></content:encoded>
      <pubDate>Fri, 12 Sep 2008 07:34:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi network">wi-fi network</category>
      <category domain="http://securityratty.com/tag/madison wi-fi network">madison wi-fi network</category>
      <category domain="http://securityratty.com/tag/madison">madison</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/mac address">mac address</category>
      <category domain="http://securityratty.com/tag/skyhook">skyhook</category>
      <category domain="http://securityratty.com/tag/skyhook wireless">skyhook wireless</category>
      <category domain="http://securityratty.com/tag/skyhook constantly">skyhook constantly</category>
      <source url="http://wifinetnews.com/archives/008437.html">Wee-Fi: Routing Out an Address; Badger-Fi</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-10 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/2d1af0f676495f958d061ee0c5c8bf43</link>
      <guid>http://securityratty.com/article/2d1af0f676495f958d061ee0c5c8bf43</guid>
      <description><![CDATA[Paul Melson's Blog: ArcSight User Conference 2008 * Logger 3.0 has adopted a more-ESM-like boolean filter interface. Big improvement over the chained-regex search in 2.5 and earlier. * Demo of Logger...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://pmelson.blogspot.com/2008/09/arcsight-user-conference-2008.html">Paul Melson's Blog: ArcSight User Conference 2008</a><br/>
* Logger 3.0 has adopted a more-ESM-like boolean filter interface. Big improvement over the chained-regex search in 2.5 and earlier.
    * Demo of Logger 3.0 shows that searches of data (no details on data set) are roughly 80x faster than a similar sized search on 2.5. (The claim is 100x faster, but I counted. Still, that&#039;s a significant improvement.)
    * Hugh has hinted that the slick, high-performance append-only storage stuff that Logger has is going to be integrated into ESM is some release beyond 4.5. That could mean the end of the Oracle / PartitionArchiver storage model.</li>
<li><a href="http://vmblog.com/archive/2008/09/09/splunk-tames-the-chaos-brought-on-by-virtualization.aspx">Splunk Tames the Chaos Brought on by Virtualization : VMblog.com - Virtualization Technology News and Information for Everyone</a><br/>
Existing system management tools were not designed to handle the dynamic nature of virtualization.  The Splunk for VMWare Management application includes a VMWare API for data input, over 25 pre-defined searches, alerts, and reports and dashboards specifically designed to monitor key metrics for the VMWare Virtual Infrastructure.</li>
<li><a href="http://eventlogs.blogspot.com/2008/08/why-your-hr-department-will-love.html">Dorian Software BLOG: Why Your HR Department Will Love Windows Vista, Even If Your IT Department Doesn't.</a><br/>
Event ID 4802 tracks whenever the screensaver is invoked after a group policy-determined idle time.

Event ID 4803 tracks whenever the screensaver is dismissed by the logged-on user.</li>
<li><a href="http://www.tditx.com/log-management.asp#hypervisor">Moderately Idiotic Competitor</a><br/>
But the clever inside criminal is taking all the payroll data from the system that is either off the network or is temporarily down. When the machine comes back up, there is no record of the intrusion and the traditional &quot;inside out&quot; log management system tells the user there is no problem.</li>
<li><a href="http://lastinfirstout.blogspot.com/2008/07/presumed-hostile-your-application-is.html">Last In - First Out: Presumed Hostile - Your Application is Out to Get You</a></li>
<li><a href="http://help.eclipse.org/help33/index.jsp?topic=/org.eclipse.tptp.monitoring.doc.user/samples/slog_analyzer.html">Help - Eclipse SDK - Working with the Log4J Logging sample</a></li>
<li><a href="http://www.datagovernance.com/cartoon_2.html">Cartoon 2 from The Data Governance Institute ROI</a></li>
<li><a href="http://gordonewasiuk.com/?p=967">Eccentric Engineer &raquo; Blog Archive &raquo; Conf Call Hem and Haw</a><br/>
It’s just a damned centralized-logging platform.  Unix sysadmins have been doing those for years.  This stuff is about as basic as tying your shoes.  All this fluff seems like overkill…but it’s IT…and we have policies.</li>
<li><a href="http://blog.isc2.org/isc2_blog/2008/08/security-metric.html">(ISC)2 Blog: Security metrics: more is not better</a></li>
<li><a href="http://www.roer.com/node/394">Are you Owned? | Roer.Com Information Security Blog</a><br/>
# list of all your profiles online, with your log in.
# list of all your IM/e-mail and other communication tools, with log in
# list of other sites/tools that requires you to log on.
# The lists above should also include each sites URL or contact information for changing passwords, or in worst case shutting them down.
# a friends-list who you trust, and who are willing to help you get back your own life online. The purpose is to have them help you rebuild your internet presence. Make sure you agree some way for them to be certain that they are communicating with you, and not someone else.</li>
<li><a href="http://www.csoonline.com/article/412163/Industry_View_Web_Application_Security_Today_Are_We_All_Insane_">Industry View: Web Application Security Today - Are We All Insane? - CSO Online - Security and Risk</a><br/>
The problem has gotten so bad that industry sources say most websites hosting malware have been hacked, Google says 1.3 percent of their search queries return malicious content, and Vint Cerf (father of the Internet) approximates that one quarter of all PCs are part of a botnet. Firewalls are not working. Antivirus/spyware is not working, nor are weekly patching, user education, SSL, or &quot;turning off the home computer&quot; as recommended by the FBI cyber-crime website. In what has become an inside joke, every authority says to use these &quot;best-practices&quot; despite their ineffectiveness.</li>
<li><a href="http://taosecurity.blogspot.com/2008/09/schneier-agrees-security-roi-is-mostly.html">TaoSecurity: Schneier Agrees: Security ROI is &quot;Mostly Bunk&quot;</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/389332419" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security blog">information security blog</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/web application security">web application security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/arcsight user conference">arcsight user conference</category>
      <category domain="http://securityratty.com/tag/security roi">security roi</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/389332419/anton18">Links for 2008-09-10 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Streaming SQL Approaches Insist in Ignoring Causality by PatternStorm]]></title>
      <link>http://securityratty.com/article/46fcc325a183e0e5f0b350bcc9aeb6b5</link>
      <guid>http://securityratty.com/article/46fcc325a183e0e5f0b350bcc9aeb6b5</guid>
      <description><![CDATA[The following excellent discussion is reposted from Streaming SQL approaches insist in ignoring causality by PatternStorm
The recent paper Towards a Streaming SQL Standard by Oracle and Streambase...]]></description>
      <content:encoded><![CDATA[<blockquote><p>The following excellent discussion is reposted from <a href="http://www.thecepblog.com/wp-admin/#p452">Streaming SQL approaches insist in ignoring causality</a> by PatternStorm.</p></blockquote>
<p>The recent paper &#8220;<a href="http://www.cs.brown.edu/%7Eugur/streamsql.pdf" target="_blank">Towards a Streaming SQL Standard</a>&#8221; by Oracle and Streambase unifies and generalizes two different execution models of Streaming SQL: Oracle&#8217;s and StreamBase&#8217;s.</p>
<p>While it&#8217;s true that the generalization succeeds in overcoming the unability of both execution models of producing correct results for astonishing simple queries (showing evidence of the actual limitations of these two Streaming SQL languages) it is also true that the generalization is closer to being overly complex than natural and intuitive.</p>
<p>The root cause behind the actual limitations of these two Streaming SQL languages is that their execution models &#8220;hardcode&#8221; the way events can be related to each other: in the Oracle case events are partially ordered by timestamp, in the StreamBase case events are totally ordered by time of arrival. These design decisions (natural in a stream oriented lamguage) have strong implications on what queries can be answered correctly, particularly when these queries involve joins of derived streams.</p>
<p>The generalization, of course, mainly consists in providing a new operator that allows the user to establish custom ordering relationships among the events (the SPREAD operator), which is good news but takes us to the fundamental issue: event processing cannot be reduced to stream processing, that is, to the processing of events that are totally or partially ordered by a pre-defined relationship (as Oracle and StreamBase actual implementations do), on the contrary, no particular ordering can be assumed because the user needs to be able to order the events in different ways in order to solve different problems. This is what event processing is about and the paper provides evidence that Streaming SQL approaches have found the need to move towards that direction and are having trouble in their way.</p>
<p>For instance, one of the queries used in the paper as an example of a query that StreamBase cannot solve (but Oracle can) is the following: correlate the stream that contains the total number of cars on the road for each time interval with the stream that contains the total average speed of the cars on the road for each time interval in order to detect the situation where the avergae speed is below 45 and the total number of cars is two or more. This query can be very easily and more robustly solved if you order the events by causality rather than by time, that is, if you have each position report update the average speed stream and the total number of cars stream and then you causally relate each position report to the new average speed event and the new total number of cars event that it generates; then the query is just a matter of detecting all report speeds that are causally related both to an average speed event below 45 and a total number of cars event of two or more (notice that this approach is more robust than Oracle&#8217;s time-based one because it works without requiring derived streams to be synchronized with the report speed stream)</p>
<p>Conclusions:</p>
<ul>
<li>Event Processing is a generalization of Stream Processing (as the paper shows)</li>
<li>Event Processing requires providing the ability to the user of creating custom relationships among events and then define patterns/queries using those custom relationships.</li>
<li>Causality is more often than not a more robust and easier criteria to order events than time or order of arrival.</li>
<li>Event Processing Languages should support causality.</li>
</ul>
<p>Regards,<br />
PatternStorm</p>
]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 10:25:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/sql approaches insist">sql approaches insist</category>
      <category domain="http://securityratty.com/tag/cars stream">cars stream</category>
      <category domain="http://securityratty.com/tag/stream">stream</category>
      <category domain="http://securityratty.com/tag/average speed event">average speed event</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/sql languages">sql languages</category>
      <category domain="http://securityratty.com/tag/languages">languages</category>
      <category domain="http://securityratty.com/tag/cars event">cars event</category>
      <source url="http://www.thecepblog.com/2008/09/05/streaming-sql-approaches-insist-in-ignoring-causality-by-patternstorm/">Streaming SQL Approaches Insist in Ignoring Causality by PatternStorm</source>
    </item>
  </channel>
</rss>
