<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: represents]]></title>
    <link>http://securityratty.com/tag/represents</link>
    <description></description>
    <pubDate>Mon, 28 Jul 2008 07:07:26 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Commercialization of Anti Debugging Tactics in Malware]]></title>
      <link>http://securityratty.com/article/91955d7bc08228b99c0f5fa478c039b5</link>
      <guid>http://securityratty.com/article/91955d7bc08228b99c0f5fa478c039b5</guid>
      <description><![CDATA[Commoditization or commercialization, Themida or Code Virtualizer, individually crypting or outsourcing to an experienced malware crypting service offering discounts on a volume basis next to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SN0BFks8GsI/AAAAAAAACMQ/J_vLiffz110/s1600-h/figure_multiple.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="128" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SN0BFks8GsI/AAAAAAAACMQ/bz624nz5JbE/s200-R/figure_multiple.jpg" width="200" /></a><a href="http://ddanchev.blogspot.com/2008/09/commoditization-of-anti-debugging.html">Commoditization</a> or commercialization, Themida or Code Virtualizer, individually crypting or outsourcing to an experienced malware crypting service offering discounts on a volume basis next to detection rates of the crypted binary offered by a trusted online scanner that is NOT distributing the samples to the vendors? These are just some of the questions malware authors often ask themselves, while others distribute pirated copies of Code Virtualizer urging everyone to start taking advantage of commercial anti-reverse engineering tools to make their malware harder to analyze. Once again, just like we've seen before, a legitimate commercial application can come handy in the hands of the wrong people :<br />
<br />
"<i>Code Virtualizer will convert your original code (Intel x86 instructions) into Virtual Opcodes that will only be understood by an internal Virtual Machine. Those Virtual Opcodes and the Virtual Machine itself are unique for every protected application, avoiding a general attack over Code Virtualizer. Code Virtualizer can protect your sensitive code areas in any x32 and x64 native PE files (like executable files/EXEs, system services, DLLs , OCXs , ActiveX controls, screen savers and device drivers).</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SN0CPwG9MzI/AAAAAAAACMY/lB8WtKqycj4/s1600-h/cvprotopt.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="149" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SN0CPwG9MzI/AAAAAAAACMY/kgSYpWIHW2E/s200-R/cvprotopt.png" width="200" /></a><i>Code Virtualizer can generate multiple types of virtual machines with a different instruction set for each one. This means that a specific block of Intel x86 instructions can be converted into different instruction set for each machine, preventing an attacker from recognizing any generated virtual opcode after the transformation from x86 instructions. The following picture represents how a block of Intel x86 instructions is converted into different kinds of virtual opcodes, which could be emulated by different virtual machines.</i><br />
<br />
<i>When an attacker tries to decompile a block of code that was protected by Code Virtualizer, he will not find the original x86 instructions. Instead, he will find a completely new instruction set which is not recognized by him or any other special decompiler. This will force the attacker to go through the extremely hard work of identifying how each opcode is executed and how the specific virtual machine works for each protected application. Code Virtualizer totally obfuscates the execution of the virtual opcodes and the study of each unique virtual machine in order to prevent someone from studying how the virtual opcodes are executed.</i>"<br />
<br />
With Cyber-as-a-Service business model becoming increasingly common, the entire <a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">quality assurance model in respect to malware</a> is slowly maturing from individual malware crypting propositions, where the seller of the service is basically taking advantage of a diverse set of public/private tools, into DIY web services offering crypting discounts on a volume basis, and perhaps most importantly - improving the customer's experience by letting him take advantage of the inventory of crypting tools and bypassing verification services. Within the tool's inventory are naturally lots of (pirated) commercial anti-reverse engineering tools.<br />
<br />
As we've seen before, whenever someone starts commercializing what used to be a self-selving process, others will either follow, or disintermediate their services by persistently releasing crypting tools for free in the wild. At the end of the day, it's all a matter of how serious they're about commercializing this market segment, and taking into consideration that a spamming vendor is offering malware crypting services "in between" the rest of the services in their portfolio, this underground cash cow is yet to prove itself in the long term.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wJDSL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wJDSL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QoCNL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QoCNL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e4uxl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e4uxl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sXqbl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sXqbl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=khiOL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=khiOL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2cQ2L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2cQ2L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HiSTl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HiSTl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/406651187" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 12:55:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/machine">machine</category>
      <category domain="http://securityratty.com/tag/specific virtual machine">specific virtual machine</category>
      <category domain="http://securityratty.com/tag/internal virtual machine">internal virtual machine</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/sensitive code">sensitive code</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/unique virtual machine">unique virtual machine</category>
      <category domain="http://securityratty.com/tag/original code">original code</category>
      <category domain="http://securityratty.com/tag/code virtualizer">code virtualizer</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/406651187/commercialization-of-anti-debugging.html">The Commercialization of Anti Debugging Tactics in Malware</source>
    </item>
    <item>
      <title><![CDATA[Online Security Issues in Regulated Industries]]></title>
      <link>http://securityratty.com/article/c0375c78d0a6bb8d65017b5d95e86d90</link>
      <guid>http://securityratty.com/article/c0375c78d0a6bb8d65017b5d95e86d90</guid>
      <description><![CDATA[Source: Webroot Software) In June 2008, Computerworld invited IT and business leaders to participate in a survey on online security initiatives at their organizations. The goal of the survey was to...]]></description>
      <content:encoded><![CDATA[<b>(Source: Webroot Software)</b> In June 2008, Computerworld invited IT and business leaders to participate in a survey on online security initiatives at their organizations. The goal of the survey was to better understand Web and e-mail security issues faced today within the regulated education, financial services, government and health care industries. The following report represents top-line results of that survey.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:9e6ab36d2d97e9ff3c67975e0ba4db66:fwDHjQBn7OTNBw53PSRuEUVlxlUPN0BQvoH%2Fx252%2BEQmFH1pVkZM3vhGFq19rXyik2XbWTRLkgst4oS21kjooVAvjadB5qKNUfxwzzFxWjg%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:60352d29916ff3cd4e6ff8f7860f7407:BXaCzD%2BqyPcvgIZ9h4MaWZftlwY33cC%2BqptF34PoosvNVgbTvi1oGD9tBNDaVzMm%2BExWF43ADBCATbXpH7PmmB7cDtoCMVibeIjDi0KTvvY%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:d4f6c3338881713386df49e23a688bd8:MzU6kNZAkv0wNixQFb7YsGYBKo0HVURvH0AsS5NmNFMFlyU3Ao%2BqPahduuZbicI56in%2F0RZxinYIReLK%2FCVAg1e3f%2BnPF%2Bpehz9ZcBH%2FZe8%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:2496aa082242eac668c02c516052f2a6:MDmNMRwp4zLa5yqKgRU%2FSqNdBX2uNmjsxyMjkdEFRW%2FHMohANuVOtdVncWss4%2BqGA7LS%2BCfsTSvgDuG4wMN5z6KqHFFORJ5rp8nQ32VU9zM%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=d26055f7677a5106a46d0eba24afd604"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=d26055f7677a5106a46d0eba24afd604" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=d26055f7677a5106a46d0eba24afd604" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/health care industries">health care industries</category>
      <category domain="http://securityratty.com/tag/online security initiatives">online security initiatives</category>
      <category domain="http://securityratty.com/tag/survey">survey</category>
      <category domain="http://securityratty.com/tag/financial services">financial services</category>
      <category domain="http://securityratty.com/tag/business leaders">business leaders</category>
      <category domain="http://securityratty.com/tag/webroot software">webroot software</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/education">education</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=d26055f7677a5106a46d0eba24afd604">Online Security Issues in Regulated Industries</source>
    </item>
    <item>
      <title><![CDATA[Employee Fraud Spiralling Out of Control in the UK]]></title>
      <link>http://securityratty.com/article/e73530104c782e83900fa4a31dabab72</link>
      <guid>http://securityratty.com/article/e73530104c782e83900fa4a31dabab72</guid>
      <description><![CDATA[You have read it before on TheBulletProofBlog - the tougher times get, the more likelihood that people will resort to criminal measures


We reported it regarding the theft of copper from Churches,...]]></description>
      <content:encoded><![CDATA[You have read it before on TheBulletProofBlog - the tougher times get, the more likelihood that people will resort to criminal measures.  <br /><br /><span id="fullpost"><br />We reported it regarding the theft of copper from Churches, Hospitals, Schools - even from new homes still under construction.  We brought to your attention the fact that thieves have become bolder, evidenced by the theft of manhole covers in public streets and drilling into fuel tanks on vehicles as petrol and diesel prices rise.<br /></span><br />In "<a href="http://www.personneltoday.com/articles/2008/09/01/47259/employee-fraud-rises-as-credit-crunch-hits.html">Personneltoday</a>", it is reported that employers have been put on "red alert" as the downturn in the economy is prompting employees to make ends meet by dishonest means.  One figure that employers every where are bound to find shocking is the fact that employee fraud has cost UK companies more than 77 Million Pounds Sterling (approx. $150,000,000.00),just in the first half of this year alone.<br /><br />The most disturbing aspect of this figure is the fact that it is up from 10 Million Pounds Sterling (approx. $18,000,000.00)in the same period last year.  This represents more than an 8 fold increase in employee fraud in a 12 month period.<br /><br />The report was conducted by the accountancy firm BDO Stoy Hayward.  Mr. Simon Bevan, the head of fraud services there attributes the escalation in criminal activity amongst employees to; "spiralling personal debt as a result of mortgage,food and fuel price hike".  Sound familiar?<br /><br />The population of the UK is one sixth that of the United States.  It is frightening to imagine what the figures will look like from U.S. businesses at the end of this year and beyond.  In 2002, employee fraud and abuse cost U.S. businesses $6 Billion Dollars (independently reported by the "Association of Certified Fraud Examiners" of which SEXTON is a member).<br /><br />What would be the outcome to U.S, businesses if fraud costs escalated 8 fold to $48 Billion Dollars by year's end?  How many would go under? How much further damage would that inflict on the already struggling economy?  The economic circumstances in the U.S. are certainly similar to those of the UK.  <br /><br />U.S. businesses beware.  Be proactive and fight fraud and abuse before it is too late.  Your very survival just may depend upon it.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 06:08:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/employee fraud">employee fraud</category>
      <category domain="http://securityratty.com/tag/businesses">businesses</category>
      <category domain="http://securityratty.com/tag/businesses beware">businesses beware</category>
      <category domain="http://securityratty.com/tag/million pounds">million pounds</category>
      <category domain="http://securityratty.com/tag/billion dollars">billion dollars</category>
      <category domain="http://securityratty.com/tag/period">period</category>
      <category domain="http://securityratty.com/tag/fold increase">fold increase</category>
      <category domain="http://securityratty.com/tag/fold">fold</category>
      <category domain="http://securityratty.com/tag/fuel price hike">fuel price hike</category>
      <source url="http://www.thebulletproofblog.com/2008/09/employee-fraud-spiralling-out-of.html">Employee Fraud Spiralling Out of Control in the UK</source>
    </item>
    <item>
      <title><![CDATA[A layered approach to data leak prevention]]></title>
      <link>http://securityratty.com/article/67a7b8012b1ff38266ad03979190438f</link>
      <guid>http://securityratty.com/article/67a7b8012b1ff38266ad03979190438f</guid>
      <description><![CDATA[My company is increasingly deploying SSL applications and that traffic already represents 40 percent of my network capacity. With this encrypted traffic on the rise, how can I build an effective...]]></description>
      <content:encoded><![CDATA[My company is increasingly deploying SSL applications and that traffic already represents 40 percent of my network capacity.  With this encrypted traffic on the rise, how can I build an effective protection against the loss of sensitive data?]]></content:encoded>
      <pubDate>Sun, 07 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/ssl applications">ssl applications</category>
      <category domain="http://securityratty.com/tag/sensitive data">sensitive data</category>
      <category domain="http://securityratty.com/tag/network capacity">network capacity</category>
      <category domain="http://securityratty.com/tag/effective protection">effective protection</category>
      <category domain="http://securityratty.com/tag/represents">represents</category>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/increasingly">increasingly</category>
      <category domain="http://securityratty.com/tag/loss">loss</category>
      <source url="http://www.networkworld.com/columnists/2008/090808insider.html?fsrc=rss-security">A layered approach to data leak prevention</source>
    </item>
    <item>
      <title><![CDATA[EPTS: Proposed Event Processing Definitions, September 20, 2006]]></title>
      <link>http://securityratty.com/article/c90d53785950324b36b55747a92766da</link>
      <guid>http://securityratty.com/article/c90d53785950324b36b55747a92766da</guid>
      <description><![CDATA[For interested readers, here are the event processing definitions we provided to the (future) EPTS working group on September 20, 2006, coordinated (edited)by David Luckham and Roy Schulte
adaptive...]]></description>
      <content:encoded><![CDATA[<p>For interested readers, here are the <a href="http://www.thecepblog.com/pdf/EVENT.PROCESSING.DRAFT.GLOSSARY.V4.SEPT.pdf" target="_blank">event processing definitions</a> we provided to the (future) EPTS working group on September 20, 2006, <a href="http://complexevents.com/?p=195" target="_blank">coordinated (edited) by David Luckham and Roy Schulte</a>;</p>
<p><strong>adaptive process management</strong> (n.) an element of resource and business process management, adaptive search and event processing. Sometimes referred to as “Level 4” event processing or process refinement.</p>
<p><strong>application concept</strong> (n.) a definition of a set of properties that represent the data fields of an application entity. An application concept can describe relationships among themselves. For example, an order concept might have a parent/child relationship with an item concept. A department concept might be related to a purchase requisition concept based on the shared property, department_id. Application concepts can include an application state model.</p>
<p><strong>application state modeler</strong> (n.) a UML-compliant application that allows you to model the life cycle of a concept instance — that is, for each instance of a given concept, you can define which states it will pass through and how it will transition from state to state. States have entry actions, exit actions, and conditions, providing precision control over the behavior of an event processing agent. Transitions between states also may have rules. Multiple types of states and transitions maximize the versatility and power of the application state modeler.</p>
<p><strong>derived event</strong> (n.) an event that is created as a result of processing one or more other events.</p>
<p><strong>complex event</strong> (n.) an event that is a situation-entity abstraction of two or more simple, derived or other complex events.</p>
<p><strong>complex event processing</strong> (n.) CEP is a technology for extracting information from message-based systems. CEP is primarily an event processing concept that deals with the task of processing multiple events from an event cloud with the goal of identifying the meaningful events within the event cloud. CEP employs techniques such as detection of complex patterns of many events, event correlation and abstraction, event hierarchies, and relationships between events such as causality, membership, and timing, and event-driven processes.</p>
<p><strong>event</strong> (n.) a instance of an event definition. It is an immutable object that represents a business activity that happened at a single point in time. Just as one cannot change the fact that a given activity occurred, one cannot change an event — events are immutable.</p>
<p><strong>event aggregation</strong> (n.) the aggregation of simple, derived or complex events into higher levels of event abstractions.</p>
<p><strong>event definition</strong> (n.) a set of properties related to a given activity that represents an important or interesting change of state in a human, system or computational activity. An event definition includes event properties such as event priority, event time to live (TTL), and a description of the payload, which is comprehensive information related to the activity that occurred. Events expire when the TTL has elapsed, unless the event processing agent has instructions to consume them prior to that time.</p>
<p><strong>event channel</strong> (n.) a communications channel in which events are transmitted from event source to event receivers, typically received as electronic messages. Each channel can have multiple destination and. events can be configured to transmit to a default destination. JMS is an example of an event channel.</p>
<p><strong>event cloud</strong> (n.) a partially ordered set of events (poset), either bounded or unbounded, where the partial orderings are imposed by the causal, timing and other relationships between the events. Typically an event cloud is created by the events produced by one or more distributed systems. An event cloud may contain many event types, event streams and event channels. The difference between a cloud and a stream is that there is no event relationship that totally orders the events in a cloud.</p>
<p><strong>event-driven</strong> (n.) the behavior of a human, system or computational entity whose execution or actuation is in response to events, typically received as electronic messages.</p>
<p><strong>event-driven architecture</strong> (n.) an architectural style for distributed computing applications in which some of the components are event-driven and communicate by means of events.</p>
<p><strong>event processing</strong> (n.) computing that performs operations on events, including modifying, creating and destroying events.</p>
<p><strong>event-object</strong> (n.) an software object that represents an event, generally for the purpose of computer processing, that exhibits both encapsulation, inheritance and polymorphism.</p>
<p><strong>event prediction</strong> (n.) computational activity where the impact of events, complex events, and situations caused by events identified, including both opportunity or threat. Sometimes referred to as “Level 2” event processing, impact assessment or predictive analytics.</p>
<p><strong>event pre-processing</strong> (n.) computational activity where events are cleansed or normalized to produce semantically understandable data. Sometimes referred to as “Level 0” event processing.</p>
<p><strong>event processing</strong> (n.) computational activities on events dealing with the association, correlation, and combination of event data and information from single and multiple event sources to achieve refined identity and situation estimates for observed event objects, and to achieve complete and timely assessments of opportunities, threats, and their significance. Event processing is characterized by continuous refinements of event estimates and assessments and by evaluation of the need for additional sources, or modification of the process itself, to achieve improved results.</p>
<p><strong>event processing agent</strong> (n.) an EPA is a computational entity that performs event processing.</p>
<p><strong>event processing network</strong> (n.) a set of event processing agents and a set of event channels connecting them.</p>
<p><strong>event properties</strong> (n.) data representation of an event, typically by name-value pairs of type string, integer, real, boolean or a complex data type.</p>
<p><strong>event refinement</strong> (n.) filter, identify and track events &amp; make initial processing decisions based on association, correlation and state estimation. Sometimes referred to as “Level 1” event, or event-object, track and trace.</p>
<p><strong>event stream</strong> (n.) a time-ordered sequence of events. An event stream may be bounded by a certain time interval or other contextual dimension (content, space, source, certainty), or be open ended and unbounded.</p>
<p><strong>event stream processing</strong> (n.) a time-ordered sequence of events. An event stream may be bounded by a certain time interval or other contextual dimension (content, space, source, certainty), or be open ended and unbounded.</p>
<p><strong>rule</strong> (n.) defines what triggers unusual, suspicious, problematic, or advantageous activity within an event processing agent and what the EPA does when it discovers these types of activities. Rules execute actions based on certain conditions on events, instances, or a combination of both. A rule includes a group of condition-rule statements and action-rule statements. The condition statements instruct the EPA what to look for in events, and action statements instruct the EPA how to respond when conditions are met. If all the conditions in a rule are satisfied by events or instances or both, the EPA fires the actions. The action might be to execute tasks, create an event instance, modify property values in an event instance, create and send an event, or something else.</p>
<p><strong>rules engine</strong> (n.) a type of event processing agent that uses a declarative programming model to process events. Formally described as &#8220;an abstract structure that describes a formal language precisely, i.e., a set of rules that mathematically delineates a (usually infinite) set of finite-length strings over a (usually finite) alphabet“. Informally, it can be any system that uses rules, in any form, that can be applied to data to produce outcomes.</p>
<p><strong>rule language</strong> (n.) is an artificial language that is used to control the behavior of an event processing agent. Rules languages, like human languages, have syntactic and semantic rules to define meaning.</p>
<p><strong>situation refinement</strong> (n.) identify situations, or complex events, based on event clustering, event-event relationships and relationship analysis and context. Sometimes referred to as “Level 2” event processing.</p>
<p><strong>simple event</strong> (n.) an event that is not an abstraction or composition of other events.</p>
<p><strong>virtual event</strong> (n.) an event that is imagined, modeled or simulated.</p>
<hr />Note:  The Emerging Technologies Engineering Team at <a href="http://www.tibco.com" target="_blank">TIBCO Software </a>significantly contributed to these event processing terms and definitions.</p>
]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 01:47:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/event-object">event-object</category>
      <category domain="http://securityratty.com/tag/business process management">business process management</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/event correlation">event correlation</category>
      <category domain="http://securityratty.com/tag/process refinement">process refinement</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/simple event">simple event</category>
      <category domain="http://securityratty.com/tag/process events">process events</category>
      <source url="http://www.thecepblog.com/2008/08/21/epts-proposed-event-processing-definitions-september-20-2006/">EPTS: Proposed Event Processing Definitions, September 20, 2006</source>
    </item>
    <item>
      <title><![CDATA[PCI Compliance: Reaction to the Summary of Changes]]></title>
      <link>http://securityratty.com/article/ddeefb896f6d234b28dddac20a55a9c5</link>
      <guid>http://securityratty.com/article/ddeefb896f6d234b28dddac20a55a9c5</guid>
      <description><![CDATA[On August 18 the PCI Security Standards Council formally announced ( http://www.pcisecuritystandards.org/pdfs/08-18-08 2.pdf ) forthcoming changes to the Payment Card Industry's Data Security Standard...]]></description>
      <content:encoded><![CDATA[On August 18 the PCI Security Standards Council formally announced (<a href="http://www.pcisecuritystandards.org/pdfs/08-18-08_2.pdf" target=_blank>http://www.pcisecuritystandards.org/pdfs/08-18-08_2.pdf</a>) forthcoming changes to the Payment Card Industry's Data Security Standard (PCI DSS) as it moves from version 1.1 to version 1.2 in October 2008.  The release represents the first major update since September 2006.
<P>
What's my take on the summary of changes? <B>Most merchants will be pleased to see that these are relatively minor changes...</b>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/payment card industry">payment card industry</category>
      <category domain="http://securityratty.com/tag/data security standard">data security standard</category>
      <category domain="http://securityratty.com/tag/release represents">release represents</category>
      <category domain="http://securityratty.com/tag/version">version</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/summary">summary</category>
      <category domain="http://securityratty.com/tag/october">october</category>
      <category domain="http://securityratty.com/tag/pdf">pdf</category>
      <category domain="http://securityratty.com/tag/minor">minor</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1330">PCI Compliance: Reaction to the Summary of Changes</source>
    </item>
    <item>
      <title><![CDATA[On Stratfor]]></title>
      <link>http://securityratty.com/article/3a9d4cea7cf308c71df112b7ea133337</link>
      <guid>http://securityratty.com/article/3a9d4cea7cf308c71df112b7ea133337</guid>
      <description><![CDATA[I love Stratfor . I am addicted. They have a unique way of saying things, an elegant mix of insight, cynicism and humor. How about this one, for instance

But in Georgias twilight hour, Stratfors gaze...]]></description>
      <content:encoded><![CDATA[I love <a href="http://www.stratfor.com"><span style="font-weight: bold;">Stratfor</span></a>. I am addicted.  They have a unique way of saying things, an elegant mix of insight, cynicism and humor. How about this one, for instance:<br /><br />"But in Georgia’s twilight hour, Stratfor’s gaze is not particularly riveted on Tbilisi. Georgia’s fate is more or less sealed. At dawn either the bombs will fall and the tanks will advance and depose the Georgian government by force, or a siege will begin that will depose it in time. Either way, the government of what is currently known as Georgia will evolve into a form that slavishly respects Russian wishes. The only reason Russian officials have not said they will enforce “regime change” is because they feel the term is too American. Whatever the nomenclature, the details of how this change happens pale in comparison to what such a change represents."<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=NXp5xK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=NXp5xK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=CZEzHK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=CZEzHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xNtdpK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xNtdpK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/363162187" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 07:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/change">change</category>
      <category domain="http://securityratty.com/tag/change represents">change represents</category>
      <category domain="http://securityratty.com/tag/enforce regime change">enforce regime change</category>
      <category domain="http://securityratty.com/tag/georgias">georgias</category>
      <category domain="http://securityratty.com/tag/georgias twilight hour">georgias twilight hour</category>
      <category domain="http://securityratty.com/tag/georgian government">georgian government</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/reason russian officials">reason russian officials</category>
      <category domain="http://securityratty.com/tag/love stratfor">love stratfor</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/363162187/on-stratfor.html">On Stratfor</source>
    </item>
    <item>
      <title><![CDATA[Red Herring Fallacies: The Straw Man Argument]]></title>
      <link>http://securityratty.com/article/fd8b4d90abc87b580bec45cf10aafeeb</link>
      <guid>http://securityratty.com/article/fd8b4d90abc87b580bec45cf10aafeeb</guid>
      <description><![CDATA[According to our friend Wikipedia, the Straw Man argument is a red-herring fallacy where one party in a debate describes a position that, on the surface, resembles an opponents actual view but is...]]></description>
      <content:encoded><![CDATA[<p>According to our friend Wikipedia, the <a href="http://en.wikipedia.org/wiki/Straw_man" target="_blank">Straw Man argument</a> is a <a href="http://en.wikipedia.org/wiki/List_of_fallacies" target="_blank">red-herring fallacy</a> where one party in a debate describes a position that, on the surface, resembles an opponent&#8217;s actual view but is easier to refute.  Then, in counterpoint, the debating partner attributes an easily refutable position to the opponent (for example, deliberately overstating the opponent&#8217;s position). Wikipedia says:</p>
<blockquote><p><strong>1. Person A has position X.</strong></p>
<p><strong>2. Person B ignores X and instead presents position Y.</strong><br />
Y is a distorted version of X and can be set up in several ways, including:</p>
<ol>
<li>Presenting a misrepresentation of the opponent&#8217;s position and then refuting it, thus giving the appearance that the opponent&#8217;s actual position has been refuted.</li>
<li>Quoting an opponent&#8217;s words out of context — i.e., choosing quotations that are not representative of the opponent&#8217;s actual intentions.<a title="Quote mining" href="http://en.wikipedia.org/wiki/Quote_mining"> </a></li>
<li>Presenting someone who defends a position poorly as <em>the</em> defender and then refuting that person&#8217;s arguments, thus giving the appearance that <em>every</em> upholder of that position, and thus the position itself, has been defeated.</li>
<li>Inventing a fictitious persona with actions or beliefs that are criticized, such that the person represents a group of whom the speaker is critical.</li>
<li>Oversimplifying an opponent&#8217;s argument, then attacking the simplified version.</li>
</ol>
<p><strong>3. Person B attacks position Y.</strong></p>
<p><strong>4. Person B draws a conclusion that X is false/incorrect/flawed.</strong><br />
This sort of &#8220;reasoning&#8221; is fallacious because attacking a distorted version of a position simply does not constitute an attack on the position itself.</p></blockquote>
<p>For example, there has been some lively discussions recently around the notion that CEP is overhyped.</p>
<blockquote><p>Debate:      &#8220;CEP is Overhyped.&#8221;</p>
<p>Person A:   &#8220;CEP has been overhyped.&#8221;</p>
<p>Person B:     &#8220;CEP is just hype.&#8221;</p></blockquote>
<p>The point of the discussion by person A was to point out that CEP has been overhyped.  Person B has exaggerated this to a harder to defend position, &#8220;CEP is mere hype.&#8221; or &#8220;CEP is just hype.&#8221;</p>
<p>From the customer perspective, I don&#8217;t think that fallacies and red-herring arguments are good for CEP.   Believe me, if we could take an &#8220;out of the box&#8221; stream processing rules-engine and bolt it on to a network and insure a client it would detect complex fraud, or diagnose network faults accurately, and not put my entire professional reputation on the line, I would do it in a heartbeat.</p>
<p>It is not the speed of the an engine which makes a good CEP engine, it is the capability of the analytics to deliver high-quality, high-confidence complex event detection in real-time.</p>
]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 05:40:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/position">position</category>
      <category domain="http://securityratty.com/tag/defend position">defend position</category>
      <category domain="http://securityratty.com/tag/easily refutable position">easily refutable position</category>
      <category domain="http://securityratty.com/tag/opponents position">opponents position</category>
      <category domain="http://securityratty.com/tag/position simply">position simply</category>
      <category domain="http://securityratty.com/tag/position poorly">position poorly</category>
      <category domain="http://securityratty.com/tag/cep engine">cep engine</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/attacks position">attacks position</category>
      <source url="http://www.thecepblog.com/2008/08/07/red-herring-fallacies-the-straw-man-argument/">Red Herring Fallacies: The Straw Man Argument</source>
    </item>
    <item>
      <title><![CDATA[Italians Use Soldiers to Prevent Crime]]></title>
      <link>http://securityratty.com/article/c78f1c770359cb273d03943d7dec2ab0</link>
      <guid>http://securityratty.com/article/c78f1c770359cb273d03943d7dec2ab0</guid>
      <description><![CDATA[Interesting : Soldiers were deployed throughout Italy on Monday to embassies, subway and railway stations, as part of broader government measures to fight violent crime here for which illegal...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.nytimes.com/2008/08/05/world/europe/05italy.html">Interesting</a>:</p>

<blockquote>Soldiers were deployed throughout Italy on Monday to embassies, subway and railway stations, as part of broader government measures to fight violent crime here for which illegal immigrants are broadly blamed.

<p>[...]</p>

<p>The conservative government of Silvio Berlusconi won elections in April while promising to crack down on petty crime and illegal immigrants. The new patrols of soldiers, who are not empowered to make arrests, do not seem aimed only at illegal immigrants, though the patrols were deployed to centers where illegal immigrants are housed. </p>

<p>“Security is something concrete,” Mr. La Russa said on Monday. The troops, he said, will be a “deterrent to criminals.”</blockquote></p>

<p>That reminds me of one of my favorite logical fallacies: "We must do something.  This is something. Therefore, we must do it."  It does seem largely to be a demonstration of "doing something" by the Berlusconi government.  The legitimate police, of course, think it's a terrible idea.</p>

<blockquote>“You need to be specially trained to carry out some kinds of controls,” Nicola Tanzi, the secretary of a trade union that represents Italian police officers. “Soldiers just aren’t qualified.”

<p>He also questioned whether the $93.6 million that will be spent for the extra deployment, called Operation Safe Streets, might not have been better used to increase the budgets for Italy’s police and military.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=lUII6K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=lUII6K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=lLsCCK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=lLsCCK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 02:36:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/illegal immigrants">illegal immigrants</category>
      <category domain="http://securityratty.com/tag/soldiers">soldiers</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/broader government measures">broader government measures</category>
      <category domain="http://securityratty.com/tag/italys police">italys police</category>
      <category domain="http://securityratty.com/tag/favorite logical fallacies">favorite logical fallacies</category>
      <category domain="http://securityratty.com/tag/operation safe streets">operation safe streets</category>
      <category domain="http://securityratty.com/tag/fight violent crime">fight violent crime</category>
      <category domain="http://securityratty.com/tag/silvio berlusconi">silvio berlusconi</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/italians_use_so.html">Italians Use Soldiers to Prevent Crime</source>
    </item>
    <item>
      <title><![CDATA[Long Island Proposal Snags Again, on Poles]]></title>
      <link>http://securityratty.com/article/479733758aebc5a0eefa89ed8a473de2</link>
      <guid>http://securityratty.com/article/479733758aebc5a0eefa89ed8a473de2</guid>
      <description><![CDATA[Long Island proposal still mired: The plan to put Wi-Fi up across two Long Island counties has seemed doomed to me from the start. The company that won the bid was untested, and its other...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/muni_icon.jpg" align="right" border="0" hspace="5" /><a href="http://www.newsday.com/news/local/ny-liwifi0728,0,7393890.story?track=rss"><strong>Long Island proposal still mired:</strong></a> The plan to put Wi-Fi up across two Long Island counties has seemed doomed to me from the start. The company that won the bid was untested, and its other in-deployment or in-proposal networks are off the table. Expertise aside, it needs tens of millions to build such a network, and financing for company-funded metro-scale projects is not available. The counties involved have pledged no purchases of services. And, perhaps the final stroke, the local utility says that E-Path doesn't meet the test of being a telecom and paying less than $10 per year for pole placement, but instead must pay the all-comer rate of $50 per year.</p>

<p>This is a critical distinction. Telecoms are covered under the Telecom Act of 1996 that requires non-discriminatory access to utility poles to avoid incumbent local exchange carriers (ILECs) and utilities from being gatekeepers that prevent competitive service from emerging. There are a series of tests in the law and local qualifications, too, that allow a firm to be a registered telecom. An FCC decision last year ruled that companies that mix telecom and unregulated information services on the same wires aren't disqualified from getting the Telecom Act deal, however. </p>

<p>But E-Path seems to meet none of the criteria except their desire to pay $10 instead of $50 per year per pole. Utility poles have held up many other municipal networks. We're not hearing more about them these days because such networks are now being built on a smaller scale for different purposes, where the number of nodes and their placement is rather different than networks built with the intent of providing indoor coverage.</p>

<p>Cablevision, by the way, qualifies as a telecom, this article states, which helps them in placing nodes for their planned $300m network across their coverage territory. They can also mount nodes in-line with their cable lines, using power from their cable plant on the lines already.</p>

<p>E-Path appears to have a variety of communication problems as well. The article notes, "Tortoretti said his Washington, D.C., attorneys disagree with LIPA's interpretation. But the attorney Tortoretti said represents E-Path, Charles Rohe, said he couldn't speak about the company or the dispute."</p>

<p>Later, E-Path's "chief executive said he hopes the county will help with his LIPA dispute." But an aide to the Suffolk County executive said, "That's not really our issue. That's out of our control."</p>

<p>Correspondent Craig Plunkett, quoted near the end, points out that if the counties were to change their minds and want to buy services on the network, the proposal would have to be rebid (appears as the sound-alike "rebuild" by accident in the online article at this moment).</p>]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 07:07:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/telecom act">telecom act</category>
      <category domain="http://securityratty.com/tag/telecom act deal">telecom act deal</category>
      <category domain="http://securityratty.com/tag/telecom">telecom</category>
      <category domain="http://securityratty.com/tag/proposal">proposal</category>
      <category domain="http://securityratty.com/tag/island proposal">island proposal</category>
      <category domain="http://securityratty.com/tag/e-path">e-path</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <category domain="http://securityratty.com/tag/represents e-path">represents e-path</category>
      <category domain="http://securityratty.com/tag/municipal networks">municipal networks</category>
      <source url="http://wifinetnews.com/archives/008403.html">Long Island Proposal Snags Again, on Poles</source>
    </item>
  </channel>
</rss>
