<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: raw]]></title>
    <link>http://securityratty.com/tag/raw</link>
    <description></description>
    <pubDate>Fri, 27 Jun 2008 16:02:04 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Wee-Fi: Share Cell Connections over Wi-Fi; Mile High-Fi Salaciousness; Giga-Fi; and More]]></title>
      <link>http://securityratty.com/article/457365225a8b72096232f2b375549cff</link>
      <guid>http://securityratty.com/article/457365225a8b72096232f2b375549cff</guid>
      <description><![CDATA[New version of Windows Mobile software to share cell data connections over Wi-Fi: Morose Media ships version 1.20 of WMWifiRouter, a Windows Mobile 5 and 6 application that routes cellular data...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.wmwifirouter.com/"><strong>New version of Windows Mobile software to share cell data connections over Wi-Fi:</strong></a> Morose Media ships version 1.20 of WMWifiRouter, a Windows Mobile 5 and 6 application that routes cellular data connections over Wi-Fi, turning your phone into a micro-hotspot. The software can also share a cell connection via Bluetooth or USB. The software costs $30 or &euro;20, and requires Internet (Connection) Sharing (ICS), which some providers may have removed from your phone. (The company set the price at US$30 before the euro drop, so is offering a kind of discount over their real &euro;20 price for the moment.)</p>

<p><a href="http://www.nytimes.com/2008/09/11/technology/personaltech/11smart.html?_r=1&8cir&emc=cirb1&oref=slogin"><strong>The New York Times rounds up using cell phones as hotspots:</strong></a> Though the reporter, Bob Tedeschi, mentions the issue of having to have an unlimited data plan to avoid unpleasant charges, and worries about bad drains and malicious users, he doesn't note that many carriers don't allow this kind of sharing or routing without a separate "tethering" plan, that can run $20 or more per month. Also, U.S. carriers have now all imposed a 5 GB per month reasonable use cap; some will cut you off, some charge you more, some cancel your service based on exceeding this use.</p>

<p><a href="http://www.networkworld.com/news/2008/090908-ieee-considers-gigabit.html?hpg1=bn"><strong>Gigabit Wi-Fi? Someday:</strong></a> TechWorld considers the IEEE's Very High Throughput (VHT) study group, which wants to start work on 1 Gbps or faster Wi-Fi standard for completion in 2012. With 802.11n offering raw symbol rates up to 600 Mbps--even though no devices have shipped with the radios and antennas to offer that optional high speed yet--there's interest in other frequencies that would allow faster encodings, as well as aggregating multiple links to achieve high speed rates. My experience in testing and using 2.4 GHz with Draft N would show that wide or aggregated channels doesn't work very well. The article's writer, Peter Judge, notes that ultrawideband had potential (over short distances) to approach the gigabit mark, but that UWB hasn't really reached the market in any substantive way years after it was promised to be a big technology.</p>

<p><a href="http://www.nbc5i.com/news/17435300/detail.html"><strong>Flight attendants express concerns about in-flight broadband porn:</strong></a> When I've spoken to airlines, industry experts, and service providers, I find that they all have stories about how porn is viewed on computers, through DVD players, and in convenient magazine form on planes today. Adding the Internet may provide new salacious imagery, but the problem predates Internet access, and filtering Internet service is never as good a solution as a social one. Someone idiotic enough to view porn on a plane over the Internet is also stupid enough to bring along inappropriate DVDs they watch while seated next to children. Flight attendants already have the power vested in them to take care of this. The flight attendants for American might be expressing this concern as part of a bargaining issue, where their responsibilities but not commensurate pay have increased.</p>

<p><a href="http://www.kxly.com/Global/story.asp?S=8989329"><strong>Spokane ends free Wi-Fi:</strong></a> Remember Vivato? Boy, I sure do. A company with a reach far exceeding its grasp, Vivato initially powered Spokane's downtown network. The network has continued to run on some basis--I'm not sure using what equipment--and now will move from free to fee. OneEighty Networks will charge about $10 per month to cover the costs of the network, for which local businesses at one point chipped in.</p>

<p><a href="http://www.onair.aero/"><strong>Brazilian TAM airline signs up for in-flight calling, messaging:</strong></a> OnAir has signed up the Brazilian carrier TAM, which will deploy the service on its Airbus A320 craft. Brazil hasn't yet provided regulatory approval, so no launch date is noted. TAM is the largest domestic and international carrier for Brazil.</p>]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 07:02:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/faster wi-fi standard">faster wi-fi standard</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/internet access">internet access</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/software costs">software costs</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <source url="http://wifinetnews.com/archives/008436.html">Wee-Fi: Share Cell Connections over Wi-Fi; Mile High-Fi Salaciousness; Giga-Fi; and More</source>
    </item>
    <item>
      <title><![CDATA[It Was Sposed to Be So Eaaasy]]></title>
      <link>http://securityratty.com/article/5714e6ea5723d4a1d18b692711ca3452</link>
      <guid>http://securityratty.com/article/5714e6ea5723d4a1d18b692711ca3452</guid>
      <description><![CDATA[Earlier this year, I gave a talk with on Breaking Web Services with Brian Chess at RSA. We pointed out that adding security into Web services is an exercise left to the implementer, the standards...]]></description>
      <content:encoded><![CDATA[<p>Earlier this year, I gave a <a href="http://1raindrop.typepad.com/1_raindrop/2008/04/rsa-debrief-p-1.html">talk</a> with on Breaking Web Services with Brian Chess at RSA. We pointed out that adding security into Web services is an exercise left to the implementer, the standards bodies and vendors give you some primitives, but it is still up to you to figure out all of the items on the <a href="http://arctecgroup.net/pdf/WebServicesSecurityChecklist.pdf">Web services security checklist</a>&#160;should work together in a cohesive system. Needless to say, there are many ways to shoot yourself in the foot.</p><br /><div>So during our talk, someone from Oracle stands up and says, &quot;hey, you guys are making this stuff sound hard. Its not hard we support WS-Security...&quot; etc. Again, the whole point of our presentation was *not* that there are not very interesting general purpose security capabilities in Web services, our point was that you need to figure out the architecture yourself, and then bend the tools to your will. Oh, and deliver on time.</div><br /><div>So imagine my surprise, when I read this article <a href="http://www.ddj.com/database/209400693">&quot;Digitally Signing and Verifying Messages in Web Services&quot;&#160;</a>which talks about using Oracle&#39;s WSM tools to sign Web service messages and verify signatures in Web service messages, but only addresses integrity - absolutely nowt on authenticity! Integrity is important, but there are lots of times when it is not enough. Many times your service needs to be concerned with replay attacks, authentication policies and so on. To deal with those things, we would typically add policies and capabilities for timestamps, nonces and other primitives into the signature block, but the article is silent on those things. (Rad Mark O&#39;Neill&#39;s <a href="http://xmlnetworking.blogspot.com/2008/08/digitally-signing-and-verifying.html">post</a> on this as well)</div><br /><div>Its not about _can_ the standards do something or other, I mean given the right resources the standards can put a monkey on the moon, its about what use cases have they engineered in and what is supported in the tools today. I firmly believe SAML has such great adoption across the industry because they have a use case centric view and so gave the vendors something to engineer and optimize for. I think we&#39;ll still get there in WS-Security and other areas as well, but the use cases are not built into the spec (as with SAML) and so its taking longer.</div><br /><div>One of our points in the talk was - we want you vendors to do your job better and instead of shipping a box Legos, ship a Lego gas station, a Lego airport, and so on. Connect some dots for your customers.&#160;</div><br /><div>What I see in <a href="http://arctecgroup.net/training.htm">training</a> on this topic, is sort of the following - 1) Do I need Web service security? 2) Oh ok, well can I get by with SSL? 3) Oh wait that doesn&#39;t actually protect my assets, can I just use WS-Security? 4) Oh wait, WS-Security isn&#39;t just a checkbox for security, I need to figure out timestamps, nonces, signatures, encryption policies and so on.&#160;And finally 5) How do I accomplish this?</div><br /><div>Once we get to step 5 then the real work can begin. Its not easy to get a lot of developers through all of this, and again this is before the real work begins. Even once the lead developers and architects figure this out, there is still the little matter of transitioning it to the rest of the team.</div><br /><div>I remember I was working with an enterprise architect several years ago, and he bought a Web service XML gateway like <a href="http://www.vordel.com/">Vordel</a> to add WS-Security support into his Web services apps, but he didn&#39;t even buy it as a runtime tool, he bought it as Security API, the runtime enforcement in his opinion was a bonus! He said in effect, well I know I need to do this, but I can&#39;t expose all these security primitives directly to my developers.</div><br /><div>So yeah, I wish it was easier, but in my experience its not right now. Its not about raw capabilities its about use case realization. I think learning from what has worked well is the way to go. SAML&#39;s use case centric approach is one that has.</div><br />]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 03:12:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ws-security">ws-security</category>
      <category domain="http://securityratty.com/tag/support ws-security">support ws-security</category>
      <category domain="http://securityratty.com/tag/web service security">web service security</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/primitives">primitives</category>
      <category domain="http://securityratty.com/tag/security primitives directly">security primitives directly</category>
      <category domain="http://securityratty.com/tag/ws-security support">ws-security support</category>
      <category domain="http://securityratty.com/tag/security api">security api</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/it-was-sposed-to-be-so-eaaasy.html">It Was Sposed to Be So Eaaasy</source>
    </item>
    <item>
      <title><![CDATA[Supporting CEP with Solace Content Routers]]></title>
      <link>http://securityratty.com/article/8d902f5832f1d3b5efbfc1f409e130b5</link>
      <guid>http://securityratty.com/article/8d902f5832f1d3b5efbfc1f409e130b5</guid>
      <description><![CDATA[Interested in content routing and event preprocessingsupporting futureCEP applications? Check out Solace Systems . You can click on the image below for a better picture of the Solace architecture for...]]></description>
      <content:encoded><![CDATA[<p>Interested in content routing and event preprocessing supporting future CEP applications?  Check out <a href="http://wwww.solacesystems.com" target="_blank">Solace Systems</a>.  You can click on the image below for a better picture of the Solace architecture for event processing.</p>
<p style="text-align: center;"><a href="http://www.solacesystems.com/images/solutions/cep_architecture.gif" target="_blank"><img class="aligncenter" src="http://www.solacesystems.com/images/solutions/cep_architecture.gif" alt="" width="450" height="283" /></a></p>
<p>Solace provides <a href="http://www.solacesystems.com/solutions/fs_event_processing.asp" target="_blank">sophisticated middleware functionality</a> in hardware to monitor, filter, route, transform and secure very large volumes of events in real time and with minimal processing overhead.  Solace uses leading-edge FPGA, ASIC and network processor technology to increase throughput and lower latency of event processing. Applications such as fraud detection, algorithmic trading, compliance, insider trade monitoring, risk management and more can be tackled more effectively by separating the simple monitoring, filtering and normalization of raw events from the complex processing of select events. This event pre-processing takes the burden off CEP engines allowing individual engines to be much more effective. </p>
]]></content:encoded>
      <pubDate>Sat, 06 Sep 2008 07:42:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solace">solace</category>
      <category domain="http://securityratty.com/tag/solace systems">solace systems</category>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/raw events">raw events</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/solace architecture">solace architecture</category>
      <category domain="http://securityratty.com/tag/network processor technology">network processor technology</category>
      <category domain="http://securityratty.com/tag/select events">select events</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <source url="http://www.thecepblog.com/2008/09/06/supporting-cep-with-solace-3230-and-solace-3260-content-routers/">Supporting CEP with Solace Content Routers</source>
    </item>
    <item>
      <title><![CDATA[Richard Veryard on Uncertainty]]></title>
      <link>http://securityratty.com/article/4e12f6a6e0e52148942e0e8935546c7e</link>
      <guid>http://securityratty.com/article/4e12f6a6e0e52148942e0e8935546c7e</guid>
      <description><![CDATA[I enjoy reading Richard Veryards blog posts. Richard does not have an agenda, per se , or at least not one I have identified. Richard is not trying to sell us anything; he seeks facts and truth with...]]></description>
      <content:encoded><![CDATA[<p>I enjoy reading Richard Veryard&#8217;s blog posts.  Richard does not have an agenda, <em>per se</em>, or at least not one I have identified.  Richard is not trying to sell us anything; he seeks facts and truth with an open, Zen mind. </p>
<p>In his second post <a href="http://rvsoapbox.blogspot.com/2008/08/faithful-representation-2.html">Faithful Representation 2</a> and continuation, <a href="http://rvsoapbox.blogspot.com/2008/08/responding-to-uncertainty.html">Responding to Uncertainty</a>, Richard explores models, reality and uncertainty.</p>
<p>I don&#8217;t have time to comment as much as I would like today.  However, I would like to conclude that in the process of raw-event to decision-making, there one of the most important factors is the ability to assign likelihood (or certainty) to any detected situation.</p>
]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 04:31:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/richard">richard</category>
      <category domain="http://securityratty.com/tag/richard explores models">richard explores models</category>
      <category domain="http://securityratty.com/tag/uncertainty">uncertainty</category>
      <category domain="http://securityratty.com/tag/post faithful representation">post faithful representation</category>
      <category domain="http://securityratty.com/tag/assign likelihood">assign likelihood</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/seeks">seeks</category>
      <category domain="http://securityratty.com/tag/factors">factors</category>
      <category domain="http://securityratty.com/tag/ability">ability</category>
      <source url="http://www.thecepblog.com/2008/08/13/richard-veryard-on-uncertainty/">Richard Veryard on Uncertainty</source>
    </item>
    <item>
      <title><![CDATA[76Service - Cybercrime as a Service Going Mainstream]]></title>
      <link>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</link>
      <guid>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</guid>
      <description><![CDATA[Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/vEaSMC2S8nI/s1600-h/76service.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/qhgjQh39ej8/s200-R/76service.JPG" style="border: 0pt none ;" /></a>Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so self-sufficient, that the stereotype of a mysterious 76service server offered for rent could in fact easily cease to exist in an ecosystem so vibrant that literally everyone can partion their botnet and start offering access to it on a multi-user basis. Evil? Obviously. Extending the lifecycle of a proprietary malware tool? Definitely.<br />
<br />
<a href="http://www.youtube.com/watch?v=lw9IeuKkNbc">The infamous 76service</a>, a cybercrime as a service web interface where customers basically collect the final output out of the banking malware botnet during the specific period of time for which they've purchases access to the service, is going mainstream, with 76Service's Spring Edition apparently leaking out, and cybercriminals enjoying its interoperability potential by introducing different banking trojans in their campaigns. <br />
<br />
In this post, I'll discuss the 76service's spring.edition that has been combined with a <a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher banking malware</a>, an a popular <a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">web malware exploitation kit</a>, with two campaigns currently hosting 5.51GB of stolen banking data based on over 1 million compromised hosts 59% of which are based in Russia. Screenshots courtesy of an egocentric underground show-off.<br />
<br />
<a href="http://www.cio.com/article/print/135500">Some general info on the 76service</a> :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/JXHZFuBb6Rs/s1600-h/76service1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/2qZfVy6YfU8/s200-R/76service1.JPG" style="border: 0pt none ;" /></a>"<i>Subscribers could log in with their assigned user name and     password any time during the 30-day project. They’d be     met with a screen that told them which of their bots was     currently active, and a side bar of management options. For     example, they could pull down the latest drops—data     deposits that the Gozi-infected machines they subscribed to     sent to the servers, like the 3.3 GB one Jackson had     found. A project was like an investment portfolio. Individual     Gozi-infected machines were like stocks and subscribers bought     a group of them, betting they could gain enough personal     information from their portfolio of infected machines to make a     profit, mostly by turning around and selling credentials on the     black market. (In some cases, subscribers would use a few of     the credentials themselves). Some machines, like some stocks, would under perform and     provide little private information. But others would land the     subscriber a windfall of private data. The point was to     subscribe to several infected machines to balance that risk,     the way Wall Street fund managers invest in many stocks to     offset losses in one company with gains in another.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/uGe8GuhDvRg/s1600-h/76service2.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/88IxypeBf74/s200-R/76service2.JPG" style="border: 0pt none ;" /></a>The 76service empowers everyone who is either not willing to spend time and resources for building and maintaining a botnet, launching campaigns, and SQL injecting hundreds of thousands of sites in order to take advantage of the long tail of malware infected sites that theoretically can outpace the traffic that could come from a SQL injected high-profile site.<br />
<br />
Next to the spring.edition, <a href="http://secureworks.com/research/threats/gozi/">the winter edition's price starts from $1000 and goes to $2000</a>, which is all a matter of who you're buying it from, unless of course you haven't come across leaked copies :<br />
<br />
"<i>Assuming that the dealer offering what he claimed was the 76service kit was correct, the profit is not only in the kit, but in selling value added services like exploitation, compromised servers/accounts, database configuration, and customization of the interface. Prices start between $1000 to $2000 and go up based on added services. The underground payment methods generally involve hard-to-track virtual currencies, whose central authority is in a jurisdiction where regulation is liberal to non-existent, and feature non-reversible transactions. The individual or group called "76service" was easy to track down on the Web, but not in person.</i>" <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/nl-OA3FHPs0/s1600-h/76service3.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/8zS6gcoEdvk/s200-R/76service3.JPG" style="border: 0pt none ;" /></a>It's interesting to monitor how services aiming to provide specific malicious services are vertically integrating by expanding their portfolio of related services -- taka a spamming vendor that will offer the segmented email databases, the advanced metrics, and the localization of the spam messages to different languages -- or letting the buyer have full control of anything that comes out of a particular botnet for a specific period of time in which he has bought access to it. For instance, DDoS for hire matured into botnet for hire, which evolved into today's "What type of stolen data do you want?" for hire mentality I'm starting to see emerging, next to the usual interest in improving the metrics and thereby the probability for a more succesful campaign. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/4s3Mkgb-NOY/s1600-h/metafisher1_ukstories.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/Bt7wKW7IPcE/s200-R/metafisher1_ukstories.jpg" style="border: 0pt none ;" /></a>Ironically, this cybercrime model is so efficient that the people behind it cannot seem to be able to process all of the stolen data, which like a great deal of underground assets loses its value if not sold as fast as possible. The result of this oversupply of stolen data are the increasing number of services selling raw logs segmented based on a particular country for a specific period of time.<br />
<br />
Time for a remotely exploitable vulnerability in yet another malware kit about to go mainstream? Definitely, unless of course backdooring it and releasing it doesn't achieve the obvious results of controlling someone else's cybercrime ecosystem.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed "Spamming Appliances" - The Future of Spam</a><br />
<br />
<b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NWhwdK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NWhwdK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7zGnyK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7zGnyK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rqgfok"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rqgfok" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zA7GDk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zA7GDk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4r7WMK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4r7WMK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=880FjK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=880FjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3wtOmk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3wtOmk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/363878623" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 04:08:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/76service">76service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/malware botnet">malware botnet</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/mysterious 76service server">mysterious 76service server</category>
      <category domain="http://securityratty.com/tag/web service">web service</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/363878623/76service-cybercrime-as-service-going.html">76Service - Cybercrime as a Service Going Mainstream</source>
    </item>
    <item>
      <title><![CDATA[Vulnerabilities in Antivirus Software - Conflict of Interest]]></title>
      <link>http://securityratty.com/article/99630b84f67151661d9187260dcf552f</link>
      <guid>http://securityratty.com/article/99630b84f67151661d9187260dcf552f</guid>
      <description><![CDATA[Vulnerabilities within security solutions -- antivirus software in this case -- are a natural event, however, the conflict of interests and failure of communication between those finding them and...]]></description>
      <content:encoded><![CDATA[<div class="separator" style="text-align: center; clear: both;"><a href="http://bp3.blogger.com/_wICHhTiQmrA/SIg38-WOQQI/AAAAAAAAB9M/PHaw4e4SYmo/s1600-h/nruns_mcafee_av_vulnerabilities.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SIg38-WOQQI/AAAAAAAAB9M/xp4nOKjGb1Q/s200-R/nruns_mcafee_av_vulnerabilities.JPG" style="border: 0pt none ;" /></a></div>Vulnerabilities within security solutions -- antivirus software in this case -- are a natural event, however, the conflict of interests and failure of communication between those finding them and those failing to acknowledge them as vulnerabilities in general, harms the customer. How they get count, and how is their severity measured in a situation where a vulnerability bypassing the scanning method of an antivirus software allowing malware to sneak in, is less important than a remote code execution through the antivirus software, is a good example of short sightedness. Here's a related development regarding a recent study regarding vulnerabilities in antivirus software - "<a href="http://blogs.zdnet.com/security/?p=1538">McAfee debunks recent vulnerabilities in AV software research, n.runs restates its position</a>" :<br />
<br />
"<i>Several days after blogging about a research conduced by n.runs AG that managed to <a href="http://blogs.zdnet.com/security/?p=1445" title="Approximately 800 vulnerabilities discovered in antivirus products">discover approximately 800 vulnerabilities in antivirus products</a>, McAfee issued a statement basically <a href="http://www.avertlabs.com/research/blog/index.php/2008/07/10/vulnerabilities-in-av-software/" title="Vulnerabilities in AV software">debunking the number of vulnerabilities found</a>, and providing its own account into the number of vulnerabilities affecting its own products :</i><br />
<br />
<i>“A recent <a href="http://blogs.zdnet.com/security/?p=1445">ZDnet blog</a> discusses a large number of vulnerabilities German research team N.Runs says it found in antimalware products from nearly every vendor. The ZDNet posting includes scary graphs to frighten users of security products. We researched the N.Runs claims by analyzing the raw data and found their claims to be somewhat exaggerated. We will discuss our findings (and make available our source data) in the attached <a href="http://vil.nai.com/images/AvertBlog_Vulnerabilities%20in%20AV%20software.pdf">document</a>. We have also provided our <a href="http://vil.nai.com/images/AvertBlog%20-%20800%20vulns.xls">source data</a> for anyone who wishes to examine it.”</i><br />
<br />
<i>Today, n.runs AG has issued <a href="http://www.prweb.com/releases/aps-av/nruns/prweb1134004.htm" title="Over 800 Vulnerabilities in Anti-Virus Software -- Reaction to the McAfee Statement">a response to McAfee’s statement</a>, providing even more <a href="http://www.nruns.com/_downloads/PR-08-02_Reaction_to_McAfee_statement.pdf" title="Response to McAfee Statement">insights into the vulnerabilities they’ve managed to find</a>, how they found them, and why are the affected antivirus vendors questioning the number of flaws in general.</i>"<br />
<br />
Consider going through the <a href="http://blogs.zdnet.com/security/?p=1538">interview with Thierry Zoller</a> as well. <br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2005/12/0bay-how-realistic-is-market-for.html">0bay - how realistic is the market for security vulnerabilities?</a><br />
<a href="http://ddanchev.blogspot.com/2006/01/was-wmf-vulnerability-purchased-for.html">Was the WMF vulnerability purchased for $4000?!</a><br />
<a href="http://ddanchev.blogspot.com/2006/03/wheres-my-0day-please.html">Where's my 0day, please?</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/scientifically-predicting-software.html">Scientifically Predicting Software Vulnerabilities</a><br />
<a href="http://ddanchev.blogspot.com/2006/09/zero-day-initiative-upcoming-zero-day.html">Zero Day Initiative "Upcoming Zero Day Vulnerabilities"</a><br />
<a href="http://ddanchev.blogspot.com/2006/05/delaying-yesterdays-0day-security.html">Delaying Yesterday's "0day" Security Vulnerability</a><br />
<a href="http://ddanchev.blogspot.com/2006/05/shaping-market-for-security.html">Shaping the Market for Security Vulnerabilities Through Exploit Derivatives</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/zero-day-vulnerabilities-market-model.html">Zero Day Vulnerabilities Market Model Gone Wrong</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/zero-day-vulnerabilities-auction.html">Zero Day Vulnerabilities Auction</a><br />
<a href="http://ddanchev.blogspot.com/2007/01/zero-day-vulnerabilities-cash-bubble.html">The Zero Day Vulnerabilities Cash Bubble</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uv22wJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uv22wJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=tablsJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=tablsJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vwps8j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vwps8j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5n0xGj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5n0xGj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JzfTJJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JzfTJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iUBJIJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iUBJIJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MwfvGj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MwfvGj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/344429091" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 00:38:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/day vulnerabilities">day vulnerabilities</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/antivirus software">antivirus software</category>
      <category domain="http://securityratty.com/tag/day vulnerabilities auction">day vulnerabilities auction</category>
      <category domain="http://securityratty.com/tag/software vulnerabilities">software vulnerabilities</category>
      <category domain="http://securityratty.com/tag/products">products</category>
      <category domain="http://securityratty.com/tag/runs claims">runs claims</category>
      <category domain="http://securityratty.com/tag/security products">security products</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/344429091/vulnerabilities-in-antivirus-software.html">Vulnerabilities in Antivirus Software - Conflict of Interest</source>
    </item>
    <item>
      <title><![CDATA[Interview with Paul Cannon, Mozy Software Engineer]]></title>
      <link>http://securityratty.com/article/0cc76ea91cbf8ad59a01671da9da1295</link>
      <guid>http://securityratty.com/article/0cc76ea91cbf8ad59a01671da9da1295</guid>
      <description><![CDATA[Mozy Awesome Process
Sometimes people come up to me and say, Paul, how is it that Mozy has created such an unrelenting output of Awesome
Today I have been authorized to share with you some of the...]]></description>
      <content:encoded><![CDATA[<p><span style="font-size: small;"><span style="font-weight: bold;">Mozy Awesome Process</span></span><br />
Sometimes people come up to me and say, &#8220;Paul, how is it that Mozy has created such an unrelenting output of Awesome?&#8221;</p>
<p>Today I have been authorized to share with you some of the unique facets of the Mozy Awesome Process that until now have been tightly controlled trade secrets of Mozy, Inc. It all starts with giant robots (virtually perpetual sources of raw Awesome). We attach them to special Awesome Siphons of our own design and pipe the yield directly into our engineers&#8217; development workstations. Further, peripheral Awesome needs are farmed from old He-Man reruns, a roomful of ninjas wailing on electric guitars, and our captive Happy Fun Ball.</p>
<p>The crude Awesome is skillfully transformed by Mozy engineers into powerful software and hardware configurations, then carefully inspected and regulated according to a host of eldritch acronyms: SWAGs, PMQs, PRDs, and the ever-inspiring CFRRCs. Once a successful creation is stamped with the Seal of Acronymic Approval for Mozy (SAAM), it is subjected to final endorsement by the mystical, revered Mozy Leprecorn*. Finally, a highly trained team of Box Monks put the new Awesomery into place in the Mozy systems, where it becomes available to you, the user.</p>
<p>Our rigorous Awesome Enforcement Policies and Magical Oversight have brought us to what we believe is the most Awesome-efficient development process in the world of backup software.</p>
<p>Be safe,<br />
Paul Cannon<br />
Mozy Software Engineer</p>
<p>*Leprecorn (noun): a rare but phenomenal creature; half Unicorn, half Leprechaun, and all magical.</p>
<p><a title="Mozy" href="http://www.mozy.com/?ref=3f9a896b&amp;kbid=38419&amp;m=4&amp;i=77" target="_blank">Visit Mozy now for a great reliable online backup service, I use it myself.</a></p>
<p><img src="file:///C:/Users/SPYWAR~1/AppData/Local/Temp/moz-screenshot.jpg" alt="" /></p>
<p><img src="file:///C:/Users/SPYWAR~1/AppData/Local/Temp/moz-screenshot-1.jpg" alt="" /></p>
<p><img src="file:///C:/Users/SPYWAR~1/AppData/Local/Temp/moz-screenshot-2.jpg" alt="" /></p>
<p><span style="font-size: small;"><span style="font-weight: bold;">Vote for Mozy</span></span><br />
Lifehacker is currently holding an online backup showdown. Show your love for Mozy. <a title="Vote for Mozy on Lifehacker.com" href="http://click.news.mozy.com/?ju=fe3415747265057c761075&amp;ls=fdf011757767027476137173&amp;m=fef012747c6103&amp;l=fe881576736c01787d&amp;s=fe601679776d007d7014&amp;jb=ffcf14&amp;t=">Vote now</a>.</p>
]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 11:00:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mozy">mozy</category>
      <category domain="http://securityratty.com/tag/mozy systems">mozy systems</category>
      <category domain="http://securityratty.com/tag/visit mozy">visit mozy</category>
      <category domain="http://securityratty.com/tag/mozy awesome process">mozy awesome process</category>
      <category domain="http://securityratty.com/tag/mozy software engineer">mozy software engineer</category>
      <category domain="http://securityratty.com/tag/awesome">awesome</category>
      <category domain="http://securityratty.com/tag/special awesome siphons">special awesome siphons</category>
      <category domain="http://securityratty.com/tag/mozy leprecorn">mozy leprecorn</category>
      <category domain="http://securityratty.com/tag/raw awesome">raw awesome</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=504">Interview with Paul Cannon, Mozy Software Engineer</source>
    </item>
    <item>
      <title><![CDATA[Are Stolen Credit Card Details Getting Cheaper?]]></title>
      <link>http://securityratty.com/article/a67e13e215d163e122340bffab059502</link>
      <guid>http://securityratty.com/article/a67e13e215d163e122340bffab059502</guid>
      <description><![CDATA[What is shaping the prices of stolen credit card details? The investments the cybercriminals or real life scammers ( through credit card cloning or ATM skimming ) put into the process of obtaining the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SHzyYjwnXTI/AAAAAAAAB6c/9rHV8A0Ggz4/s1600-h/ccz.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SHzyYjwnXTI/AAAAAAAAB6c/WQG5_Cal0xY/s200-R/ccz.JPG" style="border: 0pt none ;" /></a>What is shaping the prices of stolen credit card details? The investments the cybercriminals or real life scammers ( through <a href="http://ddanchev.blogspot.com/2007/02/credit-card-data-cloning-tactic.html">credit card cloning</a> or <a href="http://www.snopes.com/fraud/atm/atmcamera.asp">ATM skimming</a>) put into the process of obtaining the details, or can we even talk about investments being made where an experienced scammer has just purchased 1GB of raw credit cards data from a novice botnet master who isn't really aware of the actual value of his "botnet output"?<br />
<br />
Depends on which economic theory you believe in, or whether or not you'll take the "bottom-up approach" or the "top-down" one. And since I'm not aware of the existence of "the invisible hand of the underground market" and centralized power to increase the supply or decrease it to boost prices for the stolen credit card details, also indicating the existence of underground cartels putting everyone in a "price taker" position.<br />
<br />
The basics of demand and supply for anything underground will always apply unless of course, The more they want, the cheaper it gets, the less they want, the higher the price on per credit card basis gets, since the investment on behalf of the malicious party that originally stolen them is virtually the same, and he can theoretically break-even in every single case since the credit card details were obtained efficiently. It's up to the seller to follow or entirely ignore economic behavior, and do what they feel like doing with this good which must on the other hand reach its market liquidity as soon as possible, else it becomes obsolete. The current market model can be further explained as a good example of competitive equilibrium :<br />
<br />
"<i>Competitive market equilibrium is the traditional concept of economic equilibrium, appropriate for the analysis of commodity markets with flexible prices and many traders, and serving as the benchmark of efficiency in economic analysis. <b>It relies crucially on the assumption of a competitive environment where each trader decides upon a quantity that is so small compared to the total quantity traded in the market that their individual transactions have no influence on the prices.</b></i>"<br />
<br />
This can be easily explained in a single sentence - it's a mess and every participant is doing whatever they want to, so generalizing on the prices charged for stolen credit card numbers would be unrealistic, since it's the price a single seller with no real impact on the "average" market price for the same good. As for the average market price itself, it would be hard to measure it depending on the quality of the sample you want to rely on, since this is a type of market where sellers don't have to report price changes in their goods for the purpose of statistical research.<br />
<br />
<a href="http://www.finjan.com/Content.aspx?id=827#SecurityTrendsReport">A recently released report by Finjan</a>, with whom I've been on the same page of several high profile incidents so far, <a href="http://news.yahoo.com/s/nm/20080715/wr_nm/cybercrime_finjan_dc">touches this very same topic</a> :<br />
<br />
"<i>Prices charged by cybercriminals selling hacked bank and credit card details have fallen sharply as the volume of data on offer has soared, forcing them to look elsewhere to boost profit margins, a new report says. Researchers for Finjan, a Web security firm, said the high volumes traded had led to bank and credit card information becoming "commoditized" - account details with PIN codes that once fetched $100 or more each might now go for $10 or $20. In its latest quarterly survey of Web trends, the California-based company said cybercrime had evolved into "a major shadow economy ruled by business rules and logic that closely mimics the legitimate business world.</i>"<br />
<br />
Excluding the presence of <a href="http://ddanchev.blogspot.com/2008/06/price-discrimination-in-market-for.html">price discrimination</a> for a while, as well as open topic offers in the lines of "how much for X amount of Y?" answered as "how much are you willing to pay?", it's all a matter of the seller in a particular situation.<br />
<br />
Furthermore, in real-life market there's always the scarcity problem, however, in the underground market there's no shortage of resources despite the ever growing wants of the buyers. Generalizing even more, take for instance the butterfly effect of a price change in petrol, and result of which is inevitable increase of prices in every single aspect of your life, but in the underground market mostly due to the malicious economies of scale achieved, a price increase in renting a botnet would have no effect in the prices charged for the stolen credit card details obtained through the infected hosts. How come? Basically, the price and resources for malware infection are prone to decrease, if we take a malware infected host as a static foundation for the basis of any upcoming cybercrime activities using it.<br />
<br />
Perhaps the most disturbing part is that the market for stolen credit card details is so mature, and its entry barriers so low these days, that the confidential data that cannot be efficiently obtained through real-life means like credit card cloning or ATM skimming on a large scale, is now purchased online for the purpose of abusing it in real-life by<a href="http://blog.wired.com/27bstroke6/2008/06/citibank-atm-se.html"> embedding the valid information into plastic cards</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=c5gmVJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=c5gmVJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yABcqJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yABcqJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iuXpaj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iuXpaj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Ctkd2j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Ctkd2j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KJLEOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KJLEOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6teEcJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6teEcJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XpeGzj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XpeGzj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/336435935" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 11:36:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/price">price</category>
      <category domain="http://securityratty.com/tag/average market price">average market price</category>
      <category domain="http://securityratty.com/tag/market price">market price</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/competitive market equilibrium">competitive market equilibrium</category>
      <category domain="http://securityratty.com/tag/credit card basis">credit card basis</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/336435935/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</source>
    </item>
    <item>
      <title><![CDATA[Messaging and Event Processing]]></title>
      <link>http://securityratty.com/article/fd1957191d920d6269f4de936020f086</link>
      <guid>http://securityratty.com/article/fd1957191d920d6269f4de936020f086</guid>
      <description><![CDATA[In On Messaging and Events Opher asks, Is event processing just fancy name to message processing
Most event processing systems would be incomplete without the ability to process events in the form of...]]></description>
      <content:encoded><![CDATA[<p>In <a href="http://http://epthinking.blogspot.com/2008/07/on-messages-and-events.html" target="_blank">On Messaging and Events</a> Opher asks, <em>&#8220;Is event processing just fancy name to message processing ?&#8221;</em></p>
<p>Most event processing systems would be incomplete without the ability to process events in the form of messages.   Messages can be delivered in either a connection-oriented protocol or a connectionless protocol.   Most enterprise-class messaging systems have both.   Many messaging systems have features like guarenteed delivery, which are important to many applications.</p>
<p>On the other hand, you do not have to work with a messaging system or enterprise service bus (ESB) to process events, because the transport layer is independent from the event processing layer, theoretically.  Most enterprise-class event processing system architectures will use a combination of both asynchronous and synchronous messaging. </p>
<p>To understand event processing I recommend you turn to network management and the practical use of Simple Network Management Protocol (SMNP) for a basic undertanding of event processing.   SNMP uses both synchronous event-based messaging, called polling, and asynchronous messaging, called traps.   Network management systems engineers use a combination of both polling and trapping in all enterprise-class operational NMS.  Optimizing polling and trapping is one of the tasks good NMS engineers do well. The same holds true in most distributed event processing architectures.  </p>
<p>For example, look at the <a href="http://www.thecepblog.com/what-is-complex-event-processing/" target="_blank">CEP/EP reference architecture</a> on this site.  You will notice that the mechanism for event transport is generic, represented as an event bus, but it does not specify the transport protocol.  If you are receiving raw events and comparing correlated results against a signature in a database, you are using both asynchronous and synchronous messaging.    In theory, you could build an event processing system with only connection-oriented protocols, but this would be an exeception, not the rule.</p>
<p>Event processing is generally associated with messaging because we generally represent event-objects as electronic messages.   In theory, we could call these cyber event-objects anything we want; for example, we could call them &#8220;packets.&#8221; However, packets are generally associated with the underlying Internet Protocol (IP) layer by network engineers.  </p>
<p>Moving up the stack, we think in terms of a complete message-object, which we generally call &#8220;a message.&#8221;  This message could be an SNMP event-object, an SMTP event-object (an email message), or an HTML request to a web server, to only name a few.    In fact, the basic unit of work at the application level of a distributed network application is what we call &#8220;a message.&#8221;  </p>
<p>So, in <a href="http://http://epthinking.blogspot.com/2008/07/on-messages-and-events.html" target="_blank">On Messaging and Events</a> Opher asks, <em>&#8220;Is event processing just fancy name to message processing ?&#8221;</em></p>
<p>Events are generally represented in some electronic format.  The event-object must be transported electronically in cyberspace, and the way that it is transported is in what network engineers generally call &#8220;a message.&#8221;   It make no difference what we call it, really; because whatever we call it, it is still binary data representing information we are interested in, hopefully in a format we can efficiently process.    Enterprise-class event processing systems are designed to work with myriad formats, protocols and transports.   One size does not fit all.</p>
<p> </p>
<p> </p>
]]></content:encoded>
      <pubDate>Sun, 13 Jul 2008 05:02:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/smtp event-object">smtp event-object</category>
      <category domain="http://securityratty.com/tag/event-object">event-object</category>
      <category domain="http://securityratty.com/tag/cyber event-objects">cyber event-objects</category>
      <category domain="http://securityratty.com/tag/snmp event-object">snmp event-object</category>
      <category domain="http://securityratty.com/tag/snmp">snmp</category>
      <category domain="http://securityratty.com/tag/event bus">event bus</category>
      <category domain="http://securityratty.com/tag/event-objects">event-objects</category>
      <category domain="http://securityratty.com/tag/event transport">event transport</category>
      <source url="http://www.thecepblog.com/2008/07/13/messaging-and-event-processing/">Messaging and Event Processing</source>
    </item>
    <item>
      <title><![CDATA[Links List 6.27.08]]></title>
      <link>http://securityratty.com/article/8d5a94cb377694fae8da52b080f88521</link>
      <guid>http://securityratty.com/article/8d5a94cb377694fae8da52b080f88521</guid>
      <description><![CDATA[Peanut butter and chocolate. Beavis and Butthead. Social networking and CMDB? Heres a great blog post on the recently released myCMDB from Managed Objects . The IT Skeptic is as funny as ever
We heard...]]></description>
      <content:encoded><![CDATA[<p>Peanut butter and chocolate. Beavis and Butthead. Social networking and CMDB? Here’s a great blog post on the recently released <a href="http://www.itskeptic.org/node/644" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.itskeptic.org');" target="_blank">myCMDB from Managed Objects</a>. The IT Skeptic is as funny as ever.
<p>We heard a lot about cloud computing at the Gartner show this week. You can read a bit about their take on it <a href="http://blog.sciencelogic.com/a-hot-cloudless-computing-day-in-florida/06/2008"  target="_blank">here</a>. While we’ve been musing on the different ways we monitor cloud computing resources, <a href="http://www.webware.com/8301-1_109-9975354-2.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.webware.com');" target="_blank">Hyperic is already announcing their solution to monitor Amazon’s cloud computing availability</a>. <a href="http://www.informationweek.com/news/hardware/utility_ondemand/showArticle.jhtml?articleID=208800360" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.informationweek.com');" target="_blank">Hyperic believes</a> that “making use of cloud resources would be more popular if the customers had an independent means to monitor cloud services.” They plan to offer the monitoring service to other cloud companies this year. However, <a href="http://www.johnmwillis.com/amazon/taking-the-hype-out-of-hyperics-new-cloudstatus/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.johnmwillis.com');" target="_blank">John Willis questions the hype of Hyperic</a>.
<p>Here are some interesting <a href="http://networkinstruments.wordpress.com/2008/06/20/most-companies-fail-to-use-netflow/" onclick="javascript:pageTracker._trackPageview('/outbound/article/networkinstruments.wordpress.com');" target="_blank">NetFlow use stats</a> from our friends at Network Instruments. In a survey they did a few months ago, only 23% of respondents used NetFlow to monitor network performance; 60% didn’t use flow tech and 17% weren’t sure they had anything for it. I have to say we are asked at every Interop show we do if we support NetFlow so the numbers are slightly surprising but useful.
<p>Kuala Lumpur is bullish on <a href="http://www.bladewatch.com/2008/06/23/talking-about-sun-and-virtualization/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.bladewatch.com');" target="_blank">Sun’s virtualization strategy</a>.
<p>Just like at the Gartner show, one of the tracks at the Burton Group’s conference this week is on virtualization. This post on the Data Center Strategies blog covers Day 1 with some interesting notes on <a href="http://dcsblog.burtongroup.com/data_center_strategies/2008/06/catalyst-day-1.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/dcsblog.burtongroup.com');" target="_blank">where virtualization needs to go</a>, from clarity around software licensing and support to the use of raw storage (connecting VMs directly to LUNs) to improve VM performance, provide better integration with storage and data management solutions, and prevent vendor lock-in.</p>
<p><a href="http://sharethis.com/item?&wp=2.5.1&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Links+List+6.27.08&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Flinks-list-62708%2F06%2F2008" onclick="javascript:pageTracker._trackPageview('/outbound/article/sharethis.com');">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 16:02:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monitor cloud services">monitor cloud services</category>
      <category domain="http://securityratty.com/tag/monitor cloud">monitor cloud</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/cloud resources">cloud resources</category>
      <category domain="http://securityratty.com/tag/monitor amazons cloud">monitor amazons cloud</category>
      <category domain="http://securityratty.com/tag/cloud companies">cloud companies</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/support netflow">support netflow</category>
      <category domain="http://securityratty.com/tag/suns virtualization strategy">suns virtualization strategy</category>
      <source url="http://blog.sciencelogic.com/links-list-62708/06/2008">Links List 6.27.08</source>
    </item>
  </channel>
</rss>
