<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: risk-management]]></title>
    <link>http://securityratty.com/tag/risk-management</link>
    <description></description>
    <pubDate>Fri, 14 Nov 2008 03:06:18 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Updated Microsoft Security Assessment Tool]]></title>
      <link>http://securityratty.com/article/b22bf798fdddd9574ca6b43e5006fd66</link>
      <guid>http://securityratty.com/article/b22bf798fdddd9574ca6b43e5006fd66</guid>
      <description><![CDATA[Greetings. In case you havent already read about it, we recently updated the Microsoft Security Assessment Tool (MSAT). Version 4.0 hit the web on 31 October. Its been four years since the initial...]]></description>
      <content:encoded><![CDATA[<p>Greetings. In case you haven’t already read about it, we recently updated the Microsoft Security Assessment Tool (MSAT). Version 4.0 hit the web on 31 October. It’s been four years since the initial release, and two years since the prior version. Between then and now your security world has evolved a lot, and the tool now reflects that.</p>  <p>Read more: <a title="http://technet.microsoft.com/en-us/security/cc185712.aspx" href="http://technet.microsoft.com/en-us/security/cc185712.aspx">http://technet.microsoft.com/en-us/security/cc185712.aspx</a></p>  <p>Download now: <a title="http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en</a></p>  <p>Take a few moments and give yourself a security checkup. If you have any comments or feedback on the tool, feel free to leave them here on my blog—I’ll make sure the right people see it.</p>  <p>&#160;</p>  <p>From the download page:</p>  <p>The MSAT employs a holistic approach to measuring your security posture by covering topics across people, process, and technology. Findings are coupled with prescriptive guidance and recommended mitigation efforts, including links to more information for additional industry guidance. These resources may assist you in keeping you aware of specific tools and methods that can help change the security posture of your IT environment. </p>  <p>There are two assessments that define the Microsoft Security Assessment Tool: </p>  <ul>   <li>Business Risk Profile Assessment</li>    <li>Defense in Depth Assessment (UPDATED)</li> </ul>  <p>The questions identified in the survey portion of the tool and the associated answers are derived from commonly accepted best practices around security, both general and specific. The questions and the recommendations that the tool offers are based on standards such as ISO 17799 and NIST-800.x, as well as recommendations and prescriptive guidance from Microsoft’s Trustworthy Computing Group and additional security resources valued in the industry.</p>  <p>After completing an Assessment, you will gain access to a detailed report of your results. You may also compare your results with those of your peers (by industry and company size), provided that you upload your results anonymously to the secure MSAT Web server. When you upload your data the application will simultaneously retrieve the most recent data available. To be able to provide this comparative data, we need customers such as you to upload their information. All information is kept strictly confidential and no personally identifiable information whatsoever will be sent.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3162703" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 01:13:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security world">security world</category>
      <category domain="http://securityratty.com/tag/additional security resources">additional security resources</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/security posture">security posture</category>
      <category domain="http://securityratty.com/tag/identifiable information whatsoever">identifiable information whatsoever</category>
      <category domain="http://securityratty.com/tag/assessment">assessment</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/tool offers">tool offers</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/12/01/updated-microsoft-security-assessment-tool.aspx">Updated Microsoft Security Assessment Tool</source>
    </item>
    <item>
      <title><![CDATA[SOA Security in Real Life]]></title>
      <link>http://securityratty.com/article/444bcf73dc28e9ef7ab7d0cf7b145901</link>
      <guid>http://securityratty.com/article/444bcf73dc28e9ef7ab7d0cf7b145901</guid>
      <description><![CDATA[I started off my last article on SOA Security this way

When I park my car in the garage, I lock it. Why? Well, although I would hate for someone to steal my snow shovel and hockey sticks, my car is...]]></description>
      <content:encoded><![CDATA[<p>I started off my last <a href="http://soamag.com/I15/0208-2.asp">article</a> on SOA Security this way:</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>When I park my car in the garage, I lock it. Why? Well, although I would hate for someone to steal my snow shovel and hockey sticks, my car is much more valuable to me. Security is about managing risk, specifically protecting valuable assets like my car. I have a higher level of protection on my car than on my garage. In dollar terms, the contents of my garage are orders of magnitude less valuable than my car. I could spend a lot of money fortifying my garage, and that would add some security to my car while it is parked there, but it is not a cost-effective investment. First, my car is the asset of value, and second the garage - no matter how well protected it is - doesn&#39;t move.&#0160;</p><p>Car manufacturers know this, insurance companies know this, consumers know this. Even media publishers know, yet in the common enterprise, programmers and architects seem to roam in ignorance. Your average download of a Michael Bolton song carries a far higher level of security than valuable user data, like passwords, social security numbers, and credit card details. Why do we keep protecting critical data with point-to-point security solutions (like SSL) that protect the transmission channel, but leave the valuable assets being transported wide open everywhere else? This is a critical question that needs to be answered in order to successfully add an effective layer of security to an SOA.</p></blockquote><br /><div>Well guess what happened last weekend? I always do lock my car in the garage, but last week I came home with an armful of holiday cheer and forgot. I went out to the garage over the weekend and noticed that a local knucklehead who could see that the car was unlocked tried to jimmy the lock on my garage door, and busted off a piece of wood before giving up (probably when they saw the sign that said the garage was monitored).</div><br /><div>The response of the police actually further supports my assertion that security is about assets not threats. I called the police and said someone tried to jimmy my garage door. They said its a holiday weekend, call back on Monday and get a case number. This disturbed me not at all. All they are going to do is record a threat (or security event) metric anyway.</div><br /><div>Now in a hypothetical scenario if my car was compromised it would have been a completely different response from both me and the police; why is it different urgency? Not because of the threat and intent which &#0160;were similar in both scenarios, but its the fact that the asset was put into motion that&#39;s what makes it important.</div><br /><div>For infosec what do we learn? Infosec is spending waaayyyy too much time and money protecting garages and <a href="http://1raindrop.typepad.com/1_raindrop/2008/11/the-economics-of-finding-and-fixing-vulnerabilities-in-distributed-systems-.html">not enough protecting assets</a>.</div>]]></content:encoded>
      <pubDate>Sun, 30 Nov 2008 14:29:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/soa">soa</category>
      <category domain="http://securityratty.com/tag/soa security">soa security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/car manufacturers">car manufacturers</category>
      <category domain="http://securityratty.com/tag/garage">garage</category>
      <category domain="http://securityratty.com/tag/security event">security event</category>
      <category domain="http://securityratty.com/tag/garage door">garage door</category>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/point-to-point security solutions">point-to-point security solutions</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/soa-security-in-real-life.html">SOA Security in Real Life</source>
    </item>
    <item>
      <title><![CDATA[Forensic genomics]]></title>
      <link>http://securityratty.com/article/db4fa79fc51e6d9290abb3a8fd263e3f</link>
      <guid>http://securityratty.com/article/db4fa79fc51e6d9290abb3a8fd263e3f</guid>
      <description><![CDATA[I recently presented a paper on Forensic genomics: kin privacy, driftnets and other open questions (co-authored with Lucia Bianchi, Pietro Liò and Douwe Korff ) at WPES 2008 , the Workshop for...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.cl.cam.ac.uk/~fms27/">I</a> recently presented a paper on <a href="http://www.cl.cam.ac.uk/~fms27/papers/2008-StajanoBiaLioKor-genomics.pdf"><em>Forensic genomics: kin privacy, driftnets and other open questions</em></a> (co-authored with Lucia Bianchi, <a href="http://www.cl.cam.ac.uk/~pl219/">Pietro Liò</a> and <a href="http://www.londonmet.ac.uk/research-units/hrsj/staff/douwe-korff.cfm">Douwe Korff</a>) at <a href="http://dais.cs.uiuc.edu/wpes08/">WPES 2008</a>, the Workshop for Privacy in the Electronic Society of <a href="http://www.sigsac.org/ccs/CCS2008/">ACM CCS</a>, the ACM Computer and Communication Security</a> conference. Pietro and I also gave a <a href="http://talks.cam.ac.uk/talk/index/13300">related talk</a> here at the Computer Laboratory in Cambridge.</p>
<p>While <a href="http://en.wikipedia.org/wiki/Genetics">genetics</a> is concerned with the observation of specific sections of DNA, genomics is about studying the entire <a href="http://en.wikipedia.org/wiki/Genome">genome </a> of an organism, something that has only become practically possible in recent years. In forensic genetics, which is the technology behind the large national DNA databases being built in several countries including notably UK and USA (<a href="http://www.nature.com/embor/journal/v7/n1s/pdf/7400727.pdf">Wallace&#8217;s outstanding article</a> lucidly exposes many significant issues), investigators compare scene-of-crime samples with database samples by checking if they match, but only on a very small number of specific locations in the genome (e.g. 13 locations according to the <a href="http://en.wikipedia.org/wiki/Codis">CODIS</a> rules). In our paper we explore what might change when forensic analysis moves from genetics to genomics over the next few decades. This is a problem that can only be meaningfully approached from a multi-disciplinary viewpoint and indeed our combined backgrounds cover computer security, bioinformatics and law.</p>
<p><img src="http://upload.wikimedia.org/wikipedia/commons/7/7a/Codis_profile.jpg" alt="CODIS markers" /><em><br />
(Image from <a href="http://en.wikipedia.org/wiki/Image:Codis_profile.jpg">Wikimedia commons</a>, in turn from <a href="http://www.cstl.nist.gov/div831/strbase/fbicore.htm">NIST</a>.)</em></p>
<p>Sequencing the first human genome (2003) cost 2.7 billion dollars and took 13 years. The US&#8217;s National Human Genome Research Institute has <a href="http://www.medicalnewstoday.com/articles/118963.php">offered over 20 M$ worth of grants</a> towards the goal of <a href="http://www.genome.gov/27527584">driving the cost of whole-genome sequencing down to a thousand dollars</a>. This will enable <a href="http://en.wikipedia.org/wiki/Personal_genomics">personalized genomic medicine</a> (e.g. predicting genetic risk of contracting specific diseases) but will also open up a number of ethical and privacy-related problems. Eugenetic abortions, genomic pre-screening as precondition for healthcare (or even just dating&#8230;), (mis)use of genomic data for purposes other than that for which it was collected and so forth. In various jurisdictions there exists legislation (such as the recent <a href="http://www.govtrack.us/congress/billtext.xpd?bill=h110-493&amp;show-changes=0&amp;page-command=print">GINA</a> in the US) that attempts to protect citizens from some of the possible abuses; but how strongly is it enforced? And is it enough? In the forensic context, is the DNA analysis procedure as infallible as we are led to believe? There are many subtleties associated with the interpretation of statistical results; when even professional statisticians disagree, how are the poor jurors expected to reach a fair verdict? Another subtle issue is kin privacy: if the scene-of-crime sample, compared with everyone in the database, partially matches Alice, this may be used as a hint to investigate all her relatives, who aren&#8217;t even in the database; indeed, some 1980s murders were recently solved in this way. &#8220;This raises compelling policy questions about the balance between collective security and individual privacy&#8221; [<a href="http://www.sciencemag.org/cgi/content/full/sci;312/5778/1315">Bieber, Brenner, Lazer, 2006</a>]. Should a democracy allow such a &#8220;driftnet&#8221; approach of suspecting and investigating all the innocents in order to catch the guilty?</p>
<p>This is a paper of questions rather than one of solutions. We believe an informed public debate is needed <em>before</em> the expected transition from genetics to genomics takes place. We want to stimulate discussion and therefore we invite you to read the paper, make up your mind and support what you believe are the right answers.</p>
]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 12:58:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/genomics">genomics</category>
      <category domain="http://securityratty.com/tag/forensic genomics">forensic genomics</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/individual privacy">individual privacy</category>
      <category domain="http://securityratty.com/tag/dna">dna</category>
      <category domain="http://securityratty.com/tag/national dna databases">national dna databases</category>
      <category domain="http://securityratty.com/tag/genome">genome</category>
      <category domain="http://securityratty.com/tag/whole-genome">whole-genome</category>
      <category domain="http://securityratty.com/tag/kin privacy">kin privacy</category>
      <source url="http://www.lightbluetouchpaper.org/2008/11/27/forensic-genomics/">Forensic genomics</source>
    </item>
    <item>
      <title><![CDATA[No one gets fired for banning IM ]]></title>
      <link>http://securityratty.com/article/9987b9f25f73162c3e619e43a099cc8f</link>
      <guid>http://securityratty.com/article/9987b9f25f73162c3e619e43a099cc8f</guid>
      <description><![CDATA[The argument for security that enables business risk where the risk brings a compelling ROI or competitive...]]></description>
      <content:encoded><![CDATA[The argument for security that enables business risk where the risk brings a compelling ROI or competitive differentiation]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/enables business risk">enables business risk</category>
      <category domain="http://securityratty.com/tag/risk brings">risk brings</category>
      <category domain="http://securityratty.com/tag/competitive differentiation">competitive differentiation</category>
      <category domain="http://securityratty.com/tag/argument">argument</category>
      <category domain="http://securityratty.com/tag/roi">roi</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://www.networkworld.com/columnists/2008/112508-andreas.html?fsrc=rss-security">No one gets fired for banning IM </source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-11-20 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/f0421d3d712a177576a6940fd9181128</link>
      <guid>http://securityratty.com/article/f0421d3d712a177576a6940fd9181128</guid>
      <description><![CDATA[Got SIEM? - Part IV eIQviews Customers tend to use SIEM technologies for more reactive efforts, such as post-event forensics, rather than as a true correlation solution to determine unusual behavior...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://blog.eiqnetworks.com/2008/11/20/got-siem-part-iv/">Got SIEM? - Part IV &laquo; eIQviews</a><br/>
Customers tend to use SIEM technologies for more reactive efforts, such as post-event forensics, rather than as a true correlation solution to determine unusual behavior or policy violations before they have a chance to affect systems and data.</li>
<li><a href="http://siemblog.com/?p=13">SIEM Blog &raquo; Unrestricted Data Collection for Maximum Compliance and Forensic Visibility</a></li>
<li><a href="http://beastorbuddha.com/2008/11/19/so-we-own-your-client-database-and-everything-important-to-you/">Beast Or Buddha &raquo; Blog Archive &raquo; So we own your client database and everything important to you&hellip;</a><br/>
Web Developer: “Just because you can do that doesn’t mean we have a major problem like you say it is. It’s just you that did it!”
SG dude: “Well more than likely, others have….we didn’t do anything fancy…”.
Web Developer: “Well nothing has ever happened so it’s just you guys!”
SG dude: “You have no logging”.
Web Developer: “We’ve never been hacked!”</li>
<li><a href="http://ondlp.com/2008/10/13/my-wife-finally-knows-what-i-do/">On Data Loss Prevention (DLP) &raquo; My Wife Finally Knows What I Do</a></li>
<li><a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">The Two Kinds Of Security Threats, And How They Affect Your Life | securosis.com</a><br/>
We get money for noisy threats, and get called paranoid freaks for trying to prevent quiet threats (which can still lose our organizations a boatload of money, but don’t interfere with the married CEO’s ability to flirt with the new girl in marketing over email).</li>
<li><a href="http://www.csoonline.com/article/461422/Marcus_Ranum_on_Network_Security">Marcus Ranum on Network Security - CSO Online - Security and Risk</a><br/>
The real best practices have been the same since the 1970s: know where your data is, who has access to what, read your logs, guard your perimeter, minimize complexity, reduce access to &quot;need only&quot; and segment your networks.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/460414088" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data collection">data collection</category>
      <category domain="http://securityratty.com/tag/web developer">web developer</category>
      <category domain="http://securityratty.com/tag/siem">siem</category>
      <category domain="http://securityratty.com/tag/data loss prevention">data loss prevention</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/siem blog">siem blog</category>
      <category domain="http://securityratty.com/tag/security threats">security threats</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/460414088/anton18">Links for 2008-11-20 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[News Report on Non Vulnerability in Windows Vista]]></title>
      <link>http://securityratty.com/article/3a7950aaea1375ea46dc4f0439559b20</link>
      <guid>http://securityratty.com/article/3a7950aaea1375ea46dc4f0439559b20</guid>
      <description><![CDATA[Are editors so excited to use the headline Vulnerability in Windows Vista in their SEO URLs that they will have their reporters write a story on a non-issue
IDG News has published a news report...]]></description>
      <content:encoded><![CDATA[<p>Are editors so excited to use the headline &#8220;Vulnerability in Windows Vista&#8221; in their SEO URLs that they will have their reporters write a story on a non-issue? </p>
<p>IDG News has published a news report titled, &#8220;<a href="http://www.itworld.com/windows/58144/researchers-find-vulnerability-windows-vista">Researchers find vulnerability in Windows Vista</a>&#8220;. The report says:</p>
<blockquote><p>An Austrian security vendor has found a vulnerability in Windows Vista that it says could possibly allow an attacker to run unauthorized code on a PC.</p>
<p>The problem is rooted in the Device IO Control, which handles internal device communication. Researchers at Phion have found two different ways to cause a buffer overflow that could corrupt the memory of the operating system&#8217;s kernel.</p>
<p>In one of the scenarios, a person would already have to have administrative rights to the PC. In general, vulnerabilities that require that level of access somewhat undermine the risk since the attacker already has permission to use to the PC.</p></blockquote>
<p>Somewhat undermine the risk? If you need admin rights to exercise a bug it is not a security issue since you could already run any code with whatever privilege you wanted.  Microsoft is not issuing a patch, but creating a bug fix in a service pack, yet this is newsworthy?  This story has no comment from anyone but the finder of the bug.  Let&#8217;s see if other news outlets pick up on this one.</p>
]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 15:41:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows vista">windows vista</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/news report">news report</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/bug fix">bug fix</category>
      <category domain="http://securityratty.com/tag/bug">bug</category>
      <category domain="http://securityratty.com/tag/headline vulnerability">headline vulnerability</category>
      <category domain="http://securityratty.com/tag/austrian security vendor">austrian security vendor</category>
      <category domain="http://securityratty.com/tag/news outlets pick">news outlets pick</category>
      <source url="http://www.veracode.com/blog/2008/11/news-report-on-non-vulnerability-in-windows-vista/">News Report on Non Vulnerability in Windows Vista</source>
    </item>
    <item>
      <title><![CDATA[Just Love This: Noisy vs Quiet from Rich]]></title>
      <link>http://securityratty.com/article/5b13607c4ea355a79b9b366f3adb21fd</link>
      <guid>http://securityratty.com/article/5b13607c4ea355a79b9b366f3adb21fd</guid>
      <description><![CDATA[OMG, some people (usually ex-Gartner... for whatever mystical reason) have this uncanny ability to present information in a way that just triggers an avalanche of insight. Here is an example: &quot; The...]]></description>
      <content:encoded><![CDATA[OMG, some people (usually ex-Gartner... for whatever mystical reason) have this uncanny ability to present information in a way that just triggers an avalanche of insight.  Here is an example: "<a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/" rel="bookmark" title="Permanent Link to The Two Kinds Of Security Threats, And How They Affect Your Life">The Two Kinds Of Security Threats, And How They Affect Your Life </a>" from Rich Mogul.<br /><br />Some <a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">quotes</a>:  "We get money for noisy threats, and get called paranoid freaks for trying to prevent quiet threats (which can still lose our organizations a boatload of money, but don’t interfere with the married CEO’s ability to flirt with the new girl in marketing over email)."<br /><br />and<br /><br />"Slice up your budget and see how much you spend preventing noisy vs. quiet threats. It’s often our own little version of security theater."<br /><br />and<br /><br />"The problem is, noisy vs. quiet may bear little to no relationship to your actual risk and losses, but that’s just human nature."<br /><br />Overall, a MUST <a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">read</a>.<br /><br />God, please, send us some credible <a href="http://www.securitymetrics.org/content/Wiki.jsp">security metrics</a>... please.<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Raf0N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Raf0N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=fKCxN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=fKCxN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=VLpzN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=VLpzN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/460247667" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 14:50:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/quiet">quiet</category>
      <category domain="http://securityratty.com/tag/prevent quiet threats">prevent quiet threats</category>
      <category domain="http://securityratty.com/tag/noisy">noisy</category>
      <category domain="http://securityratty.com/tag/quiet threats">quiet threats</category>
      <category domain="http://securityratty.com/tag/noisy threats">noisy threats</category>
      <category domain="http://securityratty.com/tag/credible security metrics">credible security metrics</category>
      <category domain="http://securityratty.com/tag/uncanny ability">uncanny ability</category>
      <category domain="http://securityratty.com/tag/human nature">human nature</category>
      <category domain="http://securityratty.com/tag/mystical reason">mystical reason</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/460247667/just-love-this-noisy-vs-quiet-from-rich.html">Just Love This: Noisy vs Quiet from Rich</source>
    </item>
    <item>
      <title><![CDATA[Raffys Visualization Book]]></title>
      <link>http://securityratty.com/article/f4265f82839e3f66c8b6b3a78d7fa468</link>
      <guid>http://securityratty.com/article/f4265f82839e3f66c8b6b3a78d7fa468</guid>
      <description><![CDATA[Here is my long-overdue book review for Applied Security Visualization by Raffy Marty
First, here is what my early endorsement for the book said (can be found on the inside cover of the book
Amazingly...]]></description>
      <content:encoded><![CDATA[<p>Here is my long-overdue book review for <a href="http://www.amazon.com/Applied-Security-Visualization-Raffael-Marty/dp/0321510100">“Applied Security Visualization“&#160; by Raffy Marty</a>.</p>  <p>First, here is what my early endorsement for the book said (can be found on the inside cover of the book):</p>  <p>“Amazingly useful (and fun to read!) book that does justice to this&#160; somewhat esoteric subject - and this is coming from a long-time&#160; visualization skeptic! What is most impressive that&#160; this book is&#160; actually 'hands-on-useful,&quot; not conceptual, with examples usable by&#160; readers in their daily jobs. Chapter 8 on insiders is my favorite!”</p>  <p>What else do I think of the book, apart from the fact that it is awesome? :-)</p>  <p>First, I have to admit that I used to argue with Raffy about usefulness of visualization. I was burned by having to look at bad “visualization” tools and would take <em>an ugly, meaningful table over an ugly, meaningless picture</em> any day now. Thus, I was a visualization skeptic. Buy you know what? The book does justice to visualization really well, and it explains when to use it and when not to use it.</p>  <p>The book gives just the right amount of visualization theory, which is not onerous to read at all (unlike some other books), as well as other visualization basics. The fun starts at Chapter 4, where he covers&#160; the process from data to useful pictures. This actually explains why some visualization are useful and some are not; if you just jam data into a graphing program, there is a good chance that it would not be too useful. If you follow the ideas from Ch4, it is more likely to be useful.</p>  <p>Ch5 and 6 cover network data analysis: logs, packets, flows. This is what most people usually try to visualize; this book goes beyond “worms and scans” into nice visuals of email traffic, wireless and even vulnerability data (I found the latter slightly confusing). Ch7 covers “compliance”, which, in this case, covers all sorts of fun things, from risk assessment to database log visualization.&#160; As I said, Ch8 is my favorite: I agree that insider tracking MAY be the area where visualization tools and approaches beat others. In Ch9, the book covers a few visualization tools; obviously, including the author’s AfterGlow.</p>  <p>So, to summarize, get the book if you have any connection to security AND data analysis. In fact, it is very likely that if you are doing security, you’d have to do data analysis at some point and so will benefit from reading the book. And, yes, it does come with a CD full of visualization tools (DAVIX).</p>  <p>BTW, I am posting it <a href="http://www.amazon.com/Applied-Security-Visualization-Raffael-Marty/dp/0321510100">at Amazon</a> as well.</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=wgwyN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=wgwyN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=ADZPN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=ADZPN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=N8CKN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=N8CKN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/460098463" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 11:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/visualization">visualization</category>
      <category domain="http://securityratty.com/tag/visualization tools">visualization tools</category>
      <category domain="http://securityratty.com/tag/bad visualization tools">bad visualization tools</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/database log visualization">database log visualization</category>
      <category domain="http://securityratty.com/tag/security visualization">security visualization</category>
      <category domain="http://securityratty.com/tag/long-time visualization skeptic">long-time visualization skeptic</category>
      <category domain="http://securityratty.com/tag/long-overdue book review">long-overdue book review</category>
      <category domain="http://securityratty.com/tag/book covers">book covers</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/460098463/raffys-visualization-book.html">Raffys Visualization Book</source>
    </item>
    <item>
      <title><![CDATA[Stuff You Might Like]]></title>
      <link>http://securityratty.com/article/f7d7ecdf244d783a6d24770a16b2c7ff</link>
      <guid>http://securityratty.com/article/f7d7ecdf244d783a6d24770a16b2c7ff</guid>
      <description><![CDATA[Usually I beg off of doing posts that link to other posts ( Liquidmatrix does a great job of this on a regular basis), but I was afraid that James &amp; Daves usually excellent intern might miss some...]]></description>
      <content:encoded><![CDATA[<p>Usually I beg off of doing posts that link to other posts (<strong><a href="http://www.liquidmatrix.org/blog/">Liquidmatrix</a></strong> does a great job of this on a regular basis), but I was afraid that James &amp; Dave&#8217;s usually excellent intern might miss some items of note and so I thought I&#8217;d offer up a couple of things today:</p>
<p>1)  <strong><a href="http://1raindrop.typepad.com/1_raindrop/2008/11/the-economics-of-finding-and-fixing-vulnerabilities-in-distributed-systems-.html">Gunnar has put up his speech as the Quality of Protection Keynote:  &#8220;The Economics of Finding and Fixing Vulnerabilities in Distributed Systems.&#8221;</a></strong> Don&#8217;t worry if that title doesn&#8217;t turn you on, his post is one of the best this year.  I wanted to make today&#8217;s blog post some reflection on what he says there, but I haven&#8217;t the time today and we&#8217;ll have to table that until next week.  Anyway, it&#8217;s excellent.</p>
<p>2)  Aleks Jakulin writes about <strong><a href="http://www.stat.columbia.edu/~cook/movabletype/archives/2008/11/the_future_of_bayes.html">The Future of Data Analysis</a></strong>.  I spoke with a CSO who is morphing into a CRO role and one of the things he plans on doing is hiring about  a half dozen data analysts.  If you think better use of Security Information is in your future, you&#8217;ll want to take a look at that blog.</p>
<p>3)  <strong><a href="http://stateofsecurity.com/?p=521">Brent Huston of the Ohio voting machine fame writes</a></strong> about an incident he just worked on and risk and rational security.</p>
<p>4)  Our friend Mike Rothman and our friends at Business Of Security/Cisco are<a href="http://www.businessofsecurity.com/ExecutiveForum/PragmaticCSO.htm"><strong> doing a Pragmatic CSO thing</strong></a>.  Mike is always entertaining and practical (dare I say, pragmatic) so I think this should be a fun webex.  Hope you&#8217;ll sign up.</p>
<p>Namaste Risk Geeks!</p>
]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 10:29:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/todays blog post">todays blog post</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/namaste risk geeks">namaste risk geeks</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/mike">mike</category>
      <category domain="http://securityratty.com/tag/pragmatic cso">pragmatic cso</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/friend mike rothman">friend mike rothman</category>
      <category domain="http://securityratty.com/tag/pragmatic">pragmatic</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=523">Stuff You Might Like</source>
    </item>
    <item>
      <title><![CDATA[Reducing the Risk of Human Extinction]]></title>
      <link>http://securityratty.com/article/7350fd5676c07c4725588f627a9f2e13</link>
      <guid>http://securityratty.com/article/7350fd5676c07c4725588f627a9f2e13</guid>
      <description><![CDATA[Not a threat people think a lot...]]></description>
      <content:encoded><![CDATA[<p>Not a <a href="http://www.upmc-biosecurity.org/website/resources/publications/2007_orig-articles/2007-10-15-reducingrisk.html">threat</a> people think a lot about.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=dHwON"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=dHwON" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=pTuUN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=pTuUN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 03:06:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/threat people">threat people</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/reducing_the_ri.html">Reducing the Risk of Human Extinction</source>
    </item>
  </channel>
</rss>
