<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: solution]]></title>
    <link>http://securityratty.com/tag/solution</link>
    <description></description>
    <pubDate>Mon, 25 Aug 2008 08:19:23 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Should You Install Messaging Security Software on Your Exchange Server?]]></title>
      <link>http://securityratty.com/article/11b169283ed84827dab06cd87ebe699c</link>
      <guid>http://securityratty.com/article/11b169283ed84827dab06cd87ebe699c</guid>
      <description><![CDATA[Source: Sunbelt Software) Osterman Research shares insights gleaned from a just completed survey that dispel the fears of employing server-based email security solutions. Read this white paper to help...]]></description>
      <content:encoded><![CDATA[<b>(Source:  Sunbelt Software)</b> Osterman Research shares insights gleaned from a just completed survey that dispel the fears of employing server-based email security solutions.  Read this white paper to help you understand the latest Exchange security risks and also learn about reasons why an installed security solution may be the best option for you in countering those challenges.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:4c2325713dd32016c18954ac278d0864:NFQXxHFMI5joATi8rb9XqG1wphiNoRddmISCypgry8gEDx2Kenb%2BwST2VWrGNREyFwdH5a2LrernMF3UzVyemXdU3bxFrh23RewQbJvsbuU%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:ae8b7af0edbdcbad40287f4417dc000e:fzsuOnQABO%2F8zb5KR73dVE95rbdex%2BnHTgnrI25OHes0WbXZDNfE9nFNPIILxlOYupKK7IkQgzmbRxlSncXrguiZ7MZAsL4%2FH5S1pQG82Pw%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:9c187aa78b037950ceedc32de289ca2a:oM6A8Agm%2F3STbmMJgABVmGsiNFyFOaEhlsz8Si9HGzhxFAyAewDxbjLhdwiEQuD0ypx4eY%2BBm21mHRQFzIJF9g8%2FNKkoh0hbbKprpRjTCWY%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:be6d95967a93a89dc81e7f6b60ac6416:ibgVPVeXQV%2FqsmmMgf4t8i5bA1sbwSydZxlubOrocwKd3AketgClxa1YazuQW6MMa1W2lTZwLFa1Y8zrp1bym0dpybbsmX4n87C8piBSqHs%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=27986667fa8fa86c25fb326572f03aad" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=27986667fa8fa86c25fb326572f03aad" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/email security solutions">email security solutions</category>
      <category domain="http://securityratty.com/tag/exchange security risks">exchange security risks</category>
      <category domain="http://securityratty.com/tag/white paper">white paper</category>
      <category domain="http://securityratty.com/tag/sunbelt software">sunbelt software</category>
      <category domain="http://securityratty.com/tag/security solution">security solution</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/challenges">challenges</category>
      <category domain="http://securityratty.com/tag/reasons">reasons</category>
      <category domain="http://securityratty.com/tag/dispel">dispel</category>
      <source url="http://www.pheedo.com/click.phdo?i=27986667fa8fa86c25fb326572f03aad">Should You Install Messaging Security Software on Your Exchange Server?</source>
    </item>
    <item>
      <title><![CDATA[3PAR Thin Copy Desktop: A VDI-Optimized Storage Solution]]></title>
      <link>http://securityratty.com/article/faa1c491c2560f03d26087ce540dd0ef</link>
      <guid>http://securityratty.com/article/faa1c491c2560f03d26087ce540dd0ef</guid>
      <description><![CDATA[Source: 3PAR) The advent of Virtual Desktop Infrastructure (VDI) holds great promise in corporate, government, and service provider environments. Virtual Desktop Infrastructure, such as VMware VDI,...]]></description>
      <content:encoded><![CDATA[<b>(Source: 3PAR)</b> The advent of Virtual Desktop Infrastructure (VDI) holds great promise in corporate, government, and service provider environments. Virtual Desktop Infrastructure, such as VMware VDI, enables end users or their hosting providers to provision and manage hundreds of individual, virtual desktops from a set of centrally administered, consolidated servers. This approach delivers a number of potential benefits, including lower administrative and maintenance costs, higher levels of security, and increased user mobility and flexibility. 3PAR has introduced Thin Copy Desktop for VMware VDI, a storage solution designed for virtualized desktop infrastructures. This offering meets all the requirements for a VDI Optimized Storage solution, which we have outlined in this document. 3PAR Thin Copy Desktop significantly decreases physical disk space requirements for virtual desktop images and enables the rapid, simultaneous booting of hundreds  or even thousands  of virtual machines (VMs).
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=OqJXst"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=OqJXst" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/383300985" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vdi">vdi</category>
      <category domain="http://securityratty.com/tag/storage solution">storage solution</category>
      <category domain="http://securityratty.com/tag/virtual desktop infrastructure">virtual desktop infrastructure</category>
      <category domain="http://securityratty.com/tag/vmware vdi">vmware vdi</category>
      <category domain="http://securityratty.com/tag/thin copy desktop">thin copy desktop</category>
      <category domain="http://securityratty.com/tag/3par">3par</category>
      <category domain="http://securityratty.com/tag/manage hundreds">manage hundreds</category>
      <category domain="http://securityratty.com/tag/virtual desktop images">virtual desktop images</category>
      <category domain="http://securityratty.com/tag/hundreds">hundreds</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/383300985/whitepapers.do">3PAR Thin Copy Desktop: A VDI-Optimized Storage Solution</source>
    </item>
    <item>
      <title><![CDATA[3PAR Thin Copy Desktop: A VDI-Optimized Storage Solution]]></title>
      <link>http://securityratty.com/article/16989dfab02bffbda4d73e938dc0852d</link>
      <guid>http://securityratty.com/article/16989dfab02bffbda4d73e938dc0852d</guid>
      <description><![CDATA[Source: 3PAR) The advent of Virtual Desktop Infrastructure (VDI) holds great promise in corporate, government, and service provider environments. Virtual Desktop Infrastructure, such as VMware VDI,...]]></description>
      <content:encoded><![CDATA[<b>(Source: 3PAR)</b> The advent of Virtual Desktop Infrastructure (VDI) holds great promise in corporate, government, and service provider environments. Virtual Desktop Infrastructure, such as VMware VDI, enables end users or their hosting providers to provision and manage hundreds of individual, virtual desktops from a set of centrally administered, consolidated servers. This approach delivers a number of potential benefits, including lower administrative and maintenance costs, higher levels of security, and increased user mobility and flexibility. 3PAR has introduced Thin Copy Desktop for VMware VDI, a storage solution designed for virtualized desktop infrastructures. This offering meets all the requirements for a VDI Optimized Storage solution, which we have outlined in this document. 3PAR Thin Copy Desktop significantly decreases physical disk space requirements for virtual desktop images and enables the rapid, simultaneous booting of hundreds - or even thousands - of virtual machines (VMs).<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:f4f34ae1a56fad240bc637717ae98a3e:Q0uxw8yNx8poQ%2FQKxJQtAycZkRBw4pO4%2F2AGV5i1QMLMpEg2wgSl974RKBrmsuGEkQ5WWxAA3cO0rmN8tY2Dc8t9mmhNJA%2BfmXpVhaXj9Wc%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:2f92a7c011d256cf733e878cbfad9e42:zmYgYG2YKzzlSqg0dKBU4vOJ6SzSo2bX5p2jt5xYGjnjyCfcQrfayiFgom7WLp%2BcZVbH3mNXyPHe0ntOxt6o17HTWmmqsd4nmzytBBrlCiA%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:2686fa7fc02e8dc83fc49f23561537a8:7HFkUgKP22vzQQhW%2BPfraFFlO08ySGGz%2FvdMs1d9Yi%2FVBWxq9bNZDFJuucs1na7awgkKYmUxiPuHMq%2FNWwlgnbmxz50Ko9%2Bdgq7tudSyk6w%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:03149008a954edb6eaba5c5cab76cee9:Y%2F7m6%2BnHXo6F8t5s1q5N10fSXIUjiQ6dP8bwkLrOfzikRIkKy%2Br8XNGAK6%2F1FF8LUtdQNIBbHyx84L%2Fpv0CIYzHFSmkdR1qeozC7xPY7aSM%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=f871915fc679b17cbf8fb0103b3574aa" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=f871915fc679b17cbf8fb0103b3574aa" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vdi">vdi</category>
      <category domain="http://securityratty.com/tag/storage solution">storage solution</category>
      <category domain="http://securityratty.com/tag/virtual desktop infrastructure">virtual desktop infrastructure</category>
      <category domain="http://securityratty.com/tag/vmware vdi">vmware vdi</category>
      <category domain="http://securityratty.com/tag/thin copy desktop">thin copy desktop</category>
      <category domain="http://securityratty.com/tag/3par">3par</category>
      <category domain="http://securityratty.com/tag/manage hundreds">manage hundreds</category>
      <category domain="http://securityratty.com/tag/virtual desktop images">virtual desktop images</category>
      <category domain="http://securityratty.com/tag/hundreds">hundreds</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=f871915fc679b17cbf8fb0103b3574aa">3PAR Thin Copy Desktop: A VDI-Optimized Storage Solution</source>
    </item>
    <item>
      <title><![CDATA[Security ROI]]></title>
      <link>http://securityratty.com/article/22a56a0fbf977e9d5e4cffb543ff0d74</link>
      <guid>http://securityratty.com/article/22a56a0fbf977e9d5e4cffb543ff0d74</guid>
      <description><![CDATA[Return on investment, or ROI, is a big deal in business. Any business venture needs to demonstrate a positive return on investment, and a good one at that, in order to be viable
It's become a big deal...]]></description>
      <content:encoded><![CDATA[<p>Return on investment, or ROI, is a big deal in business. Any business venture needs to demonstrate a positive return on investment, and a good one at that, in order to be viable.</p>

<p>It's become a <a href="http://www.csoonline.com/article/print/217727">big</a> <a href="http://www.computerworld.com/securitytopics/security/story/0,10801,83207,00.html?nas=ROI-83207">deal</a> in IT security, too. Many corporate customers are demanding ROI models to demonstrate that a particular security investment pays off. And in response, vendors are providing ROI models that demonstrate how their particular security solution provides the best return on investment.</p>

<p>It's a <a href="http://communities.intel.com/openport/blogs/it/2008/08/25/are-security-roi-figures-meaningless">good</a> <a href="http://communities.intel.com/openport/blogs/it/2007/08/14/the-problem-of-measuring-information-security">idea</a> in <a href="https://buildsecurityin.us-cert.gov/daisy/bsi/articles/knowledge/business/677-BSI.html">theory</a>, <a href="http://taosecurity.blogspot.com/2007/07/are-questions-sound.html">but</a> <a href="http://www.bloginfosec.com/2007/07/13/bejtlich-and-business-will-it-blend/">it's</a> <a href="http://blog.vorant.com/2007/07/my-input-to-roi-spat.html">mostly</a> <a href="http://taosecurity.blogspot.com/2007/07/no-roi-no-problem.html">bunk</a> <a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">in</a> <a href="http://taosecurity.blogspot.com/2007/07/security-roi-revisited.html">practice</a>.</p>

<p>Before I get into the details, there's one point I have to make. "ROI" as used in a security context is inaccurate. Security is not an investment that provides a return, like a new factory or a financial instrument. It's an expense that, hopefully, pays for itself in cost savings. Security is about loss prevention, not about earnings. The term just doesn't make sense in this context.</p>

<p>But as anyone who has lived through a company's vicious end-of-year budget-slashing exercises knows, when you're trying to make your numbers, cutting costs is the same as increasing revenues. So while security can't produce ROI, loss prevention most certainly affects a company's bottom line.</p>

<p>And a company should implement only security countermeasures that affect its bottom line positively. It shouldn't spend more on a security problem than the problem is worth. Conversely, it shouldn't ignore problems that are costing it money when there are cheaper mitigation alternatives. A smart company needs to approach security as it would any other business decision: costs versus benefits.</p>

<p>The classic methodology is called annualized loss expectancy (ALE), and it's straightforward. Calculate the cost of a security incident in both tangibles like time and money, and intangibles like reputation and competitive advantage. Multiply that by the chance the incident will occur in a year. That tells you how much you should spend to mitigate the risk. So, for example, if your store has a 10 percent chance of getting robbed and the cost of being robbed is $10,000, then you should spend $1,000 a year on security. Spend more than that, and you're wasting money. Spend less than that, and you're also wasting money.</p>

<p>Of course, that $1,000 has to reduce the chance of being robbed to zero in order to be cost-effective. If a security measure cuts the chance of robbery by 40 percent -- to 6 percent a year -- then you should spend no more than $400 on it. If another security measure reduces it by 80 percent, it's worth $800. And if two security measures both reduce the chance of being robbed by 50 percent and one costs $300 and the other $700, the first one is worth it and the second isn't.</p>

<p>The Data Imperative</p>

<p>The key to making this work is good data; the term of art is "actuarial tail." If you're doing an ALE analysis of a security camera at a convenience store, you need to know the crime rate in the store's neighborhood and maybe have some idea of how much cameras improve the odds of convincing criminals to rob another store instead. You need to know how much a robbery costs: in merchandise, in time and annoyance, in lost sales due to spooked patrons, in employee morale. You need to know how much not having the cameras costs in terms of employee morale; maybe you're having trouble hiring salespeople to work the night shift. With all that data, you can figure out if the cost of the camera is cheaper than the loss of revenue if you close the store at night -- assuming that the closed store won't get robbed as well. And then you can decide whether to install one.</p>

<p>Cybersecurity is considerably harder, because there just isn't enough good data. There aren't good crime rates for cyberspace, and we have a lot less data about how individual security countermeasures -- or specific configurations of countermeasures -- mitigate those risks. We don't even have data on incident costs.</p>

<p>One problem is that the threat moves too quickly. The characteristics of the things we're trying to prevent change so quickly that we can't accumulate data fast enough. By the time we get some data, there's a new threat model for which we don't have enough data. So we can't create ALE models.</p>

<p>But there's another problem, and it's that the math quickly falls apart when it comes to rare and expensive events. Imagine you calculate the cost -- reputational costs, loss of customers, etc. -- of having your company's name in the newspaper after an embarrassing cybersecurity event to be $20 million. Also assume that the odds are 1 in 10,000 of that happening in any one year. ALE says you should spend no more than $2,000 mitigating that risk.</p>

<p>So far, so good. But maybe your CFO thinks an incident would cost only $10 million. You can't argue, since we're just estimating. But he just cut your security budget in half. A vendor trying to sell you a product finds a Web analysis claiming that the odds of this happening are actually 1 in 1,000. Accept this new number, and suddenly a product costing 10 times as much is still a good investment.</p>

<p>It gets worse when you deal with even more rare and expensive events. Imagine you're in charge of terrorism mitigation at a chlorine plant. What's the cost to your company, in money and reputation, of a large and very deadly explosion? $100 million? $1 billion? $10 billion? And the odds: 1 in a hundred thousand, 1 in a million, 1 in 10 million? Depending on how you answer those two questions -- and any answer is really just a guess -- you can justify spending anywhere from $10 to $100,000 annually to mitigate that risk.</p>

<p>Or take another example: airport security. Assume that all the new airport security measures increase the waiting time at airports by -- and I'm making this up -- 30 minutes per passenger. There were 760 million passenger boardings in the United States in 2007. This means that the extra waiting time at airports has cost us a collective 43,000 years of extra waiting time. Assume a 70-year life expectancy, and the increased waiting time has "killed" 620 people per year -- 930 if you calculate the numbers based on 16 hours of awake time per day. So the question is: If we did away with increased airport security, would the result be more people dead from terrorism or fewer?</p>

<p>Caveat Emptor</p>

<p>This kind of thing is why most ROI models you get from security vendors are <a href="http://www.postini.com/services/roi_calculator.html">nonsense</a>. Of course their model demonstrates that their product or service makes financial sense: They've jiggered the numbers so that they do.</p>

<p>This doesn't mean that ALE is useless, but it does mean you should 1) mistrust any analyses that come from people with an agenda and 2) use any results as a general guideline only. So when you get an ROI model from your vendor, take its framework and plug in your own numbers. Don't even show the vendor your improvements; it won't consider any changes that make its product or service less cost-effective to be an "improvement." And use those results as a general guide, along with risk management and compliance analyses, when you're deciding what security products and services to buy.</p>

<p>This essay <a href="http://www.csoonline.com/article/446866/Security_ROI_Fact_or_Fiction_">previously appeared</a> in <i>CSO Magazine</i>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Ql60WL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Ql60WL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=npHViL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=npHViL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 02:05:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security countermeasures">security countermeasures</category>
      <category domain="http://securityratty.com/tag/countermeasures">countermeasures</category>
      <category domain="http://securityratty.com/tag/incident">incident</category>
      <category domain="http://securityratty.com/tag/security incident">security incident</category>
      <category domain="http://securityratty.com/tag/individual security countermeasures">individual security countermeasures</category>
      <category domain="http://securityratty.com/tag/security measure cuts">security measure cuts</category>
      <category domain="http://securityratty.com/tag/security measure reduces">security measure reduces</category>
      <category domain="http://securityratty.com/tag/security vendors">security vendors</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/security_roi_1.html">Security ROI</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Five]]></title>
      <link>http://securityratty.com/article/38118a4a2d1022021197659857d63ff3</link>
      <guid>http://securityratty.com/article/38118a4a2d1022021197659857d63ff3</guid>
      <description><![CDATA[The &quot;campaign managers&quot; behind these fake security software propositions are not just starting to take park them at up to three different locations, localize the sites to different languages and...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SL0JgRiDYeI/AAAAAAAACI8/6WOV1GjHRlY/s1600-h/fake_software_september1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SL0JgRiDYeI/AAAAAAAACI8/JMBr1bMh8no/s200-R/fake_software_september1.JPG" /></a>The "campaign managers" behind these <a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">fake security software propositions</a> are not just starting to take park them at up to three different locations, <a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">localize the sites</a> to different languages and introduce <a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">client-side exploits</a>, just in case the end user gets suspicious and doesn't install it, but also, the natural evasive practices. For instance, once some of their domains get detected and blocked, they put them in a stand by mode and relaunch them online in a week or so, or ensure that only those coming to the domains from where they are supposed to come - yet another blackhat SEO or SQL injection attack - are the only ones getting to see the download screen.<br />
<br />
Some of the new additions parked at the same IPs offered by the "known suspects" include :<br />
<br />
<b>main-scanner .com</b> - (77.244.220.138; 78.159.97.247; 89.149.209.251; 212.95.37.154)<br />
<b>scanner-mainpro .com<br />
scanner-online1 .com<br />
alldiskscheck300 .com<br />
myscanners101 .com<br />
download-a1 .com<br />
scanner-online1 .com<br />
multilang1 .com<br />
ratemyblog1 .com<br />
multisearch1 .com<br />
filescheck-list303 .com<br />
woodst-sale .com<br />
scanner-mainpro .com<br />
main-scanner .com<br />
directrevisions .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SL0MwkX0VNI/AAAAAAAACJE/QObbQi3_9Ng/s1600-h/doctor_antivirus1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="141" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SL0MwkX0VNI/AAAAAAAACJE/vDM5gk_K5fc/s200-R/doctor_antivirus1.png" width="200" /></a><b>supersolution-freeantivirus .com</b> - (213.155.2.69)<br />
<b>antivirus-bestsolution .net<br />
antivirus4protection .net<br />
antivirusproxp .com<br />
freebest-antivirus .net<br />
goodantivirus-free .net<br />
noadwareantivirus .com<br />
pwrantivirus2009 .com<br />
solution-freeantivirus .com<br />
supersolution-antivirus .com<br />
supersolution-freeantivirus .com<br />
antivirusdwl .com<br />
securesoftdl .com<br />
viva-codec .com<br />
win-antivirus-protect .com<br />
avxp-2008 .net<br />
antivirusq .net<br />
antivirus2008b .net<br />
antivirus2008m .net<br />
antivirus2008n .net<br />
antivirus2008v .net<br />
antivirus777 .com<br />
antivirusq .net<br />
antivirusr .net<br />
antivirust .net<br />
antivirusw .net<br />
antivirusu .net<br />
expressantivirus2009 .com<br />
spywarezscan .net<br />
antispywareq .net<br />
free-anti-spywaree .net<br />
avcheckyourpc .net<br />
</b><br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SL0NgVvxo5I/AAAAAAAACJM/zna4-YKQE_o/s1600-h/doctor_antivirus2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SL0NgVvxo5I/AAAAAAAACJM/4mda8Pv35yY/s200-R/doctor_antivirus2.png" /></a><b>software-for-me08 .com</b> - (78.157.143.250)<br />
<b>software-for-me-08 .com<br />
softwarefor-me2008 .com<br />
softwarefor-me-2008 .com<br />
software-forme08 .com</b><br />
<br />
<b>doctor2antivirus .com</b> - (217.112.94.226; 87.248.163.56)<br />
<b>doctor5antivirus .com<br />
doctor6antivirus .com<br />
doctor7antivirus .com<br />
doctor8antivirus .com<br />
doctorantivirus2008a .com<br />
doctor-antivirus .com<br />
bcodecnow .net</b><br />
<br />
<b>mysoftwarefreezone .com</b> - (91.203.92.97)<br />
<b>hotvid44 .com<br />
totsec2009 .com<br />
getdefender2009 .com<br />
totalsecure2009 .com<br />
myveryprivatevid .com<br />
mustseethatvid .com<br />
onlythebestvid .com<br />
ie-antivirus-order .com<br />
ie-anti-virus .com<br />
secure-order-box .com</b><br />
<br />
<b>secureexpertcleaner .com</b> - (89.149.227.50)<br />
<b>bestxpclean2008 .com<br />
virusremover2008 .com<br />
registrydoctor2008 .com<br />
securefileshredder .com<br />
hypersecurefileshredder .com<br />
bestsecureexpertcleaner .com</b><br />
<br />
<b>getdefender2009 .com</b> - (58.65.238.34)<br />
<b>malwarebell .com<br />
free-viruscan .com<br />
tmptmpservvv .com<br />
cometoseemyshow .com</b><br />
<br />
<b>getneededsoftware .com</b> - (91.203.93.25)<br />
<b>gettotalsec2008 .com<br />
thedownloadvid .com<br />
scan.pc-antispyware-scanner .com<br />
totalsecure2009 .com</b><br />
<br />
<b>wista-antivirus2009 .com</b> - (216.255.179.203)<br />
<b>usawindowsupdates .com</b> - (85.17.143.213)<br />
<b>mswindowsupdates .com</b><br />
<br />
The campaigns and the hosting providers are continuously monitored, especially taking into consideration the fact that the domains are already appearing in Alexa's web rankings with sudden peaks of traffic.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">Fake Security Software Domains Serving Exploits</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A Diverse Portfolio of Fake Security Software - Part Four</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse Portfolio of Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">Geolocating Malicious ISPs</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The Malicious ISPs You Rarely See in Any Report</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9RKAnL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9RKAnL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=S4YvYL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=S4YvYL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=J1kcWl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=J1kcWl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=q4Iwql"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=q4Iwql" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Cbh1CL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Cbh1CL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=b89bjL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=b89bjL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=t2D6Bl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=t2D6Bl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/381234025" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 01:04:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/introduce client-side exploits">introduce client-side exploits</category>
      <category domain="http://securityratty.com/tag/malicious isps">malicious isps</category>
      <category domain="http://securityratty.com/tag/exploits">exploits</category>
      <category domain="http://securityratty.com/tag/sql injection attack">sql injection attack</category>
      <category domain="http://securityratty.com/tag/lazy summer days">lazy summer days</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/381234025/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Five</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.29.08]]></title>
      <link>http://securityratty.com/article/f1038682e1a7f7e06f6d230b158bd8a3</link>
      <guid>http://securityratty.com/article/f1038682e1a7f7e06f6d230b158bd8a3</guid>
      <description><![CDATA[ChangeWave Research released a survey of 1,947 people responsible for IT spending. Thirty percent of the respondents reported that third-quarter IT spending was lower than previously planned while 12...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="240" alt="michaelphelps" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/michaelphelps.jpg" width="174" align="left" border="0" /> ChangeWave Research released a survey of 1,947 people responsible for IT spending. Thirty percent of the respondents <a href="http://www.infoworld.com/article/08/08/27/Grim_outlook_for_US_IT_spending_1.html?source=NLC-DAILY&amp;cgd=2008-08-28" target="_blank">reported that third-quarter IT spending was lower</a> than previously planned &#8211; while 12 percent spent more than planned. Thirty-five percent cited higher energy costs as the top factor for spending slowdown. </p>
<p>Parlez-vous open source? While wide-spread open source usage is still debated in many companies, the French have been advocating for <a href="http://www.infoworld.com/article/08/08/28/35NF-open-source-france-lessons_1.html" target="_blank">all open source all the time in government and education</a>. French President Nicolas Sarkozy set up an economic commission that recommended tax benefits to stimulate more open source development. Lesson learned from France: start &#8216;em early. &#8220;All students in France use open source.&#8221;</p>
<p>Just in time for Labor Day, John Edwards (no, not that one) comes out with an informative guide on &#8220;<a href="http://www.infoworld.com/article/08/08/27/35NF-cloud-providers_1.html" target="_blank">Who provides what in the cloud</a>&#8221;. No doubt, this will be a rapidly expanding list, but what&#8217;s really interesting is the comment on the article. People have very strong opinions on the cloud&#8230;</p>
<p>Research firm Aberdeen Group reports that <a href="http://www.cio.com/article/445863/Network_Management_Tips_for_Managing_Costs?page=1" target="_blank">network costs will increase</a> slightly more than 5 percent over 2007. Contributing factors: &#8220;need for speed&#8221;, shift from standard to mobile PCs (more end points of connectivity), and the ever-expanding network. And of course the hidden costs of multiple tools with multiple management consoles &#8211; if you&#8217;re not smart enough to choose say a comprehensive network management solution that is vendor agnostic&#8230;One tool to monitor them all&#8230;</p>
<p>And just because I miss the Olympics already, here&#8217;s an irreverent take on what it&#8217;s like to lose to Michael Phelps. <a href="http://www.thetechstop.net/?p=1503">http://www.thetechstop.net/?p=1503</a></p>
<p>Enjoy your long Labor Day Weekend!</p>
]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 10:00:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/source development">source development</category>
      <category domain="http://securityratty.com/tag/thirty percent">thirty percent</category>
      <category domain="http://securityratty.com/tag/labor day">labor day</category>
      <category domain="http://securityratty.com/tag/source usage">source usage</category>
      <category domain="http://securityratty.com/tag/costs">costs</category>
      <category domain="http://securityratty.com/tag/energy costs">energy costs</category>
      <category domain="http://securityratty.com/tag/thirty-five percent cited">thirty-five percent cited</category>
      <source url="http://blog.sciencelogic.com/links-list-82908/08/2008">Links List 8.29.08</source>
    </item>
    <item>
      <title><![CDATA[Web Services and XML Security Training at OWASP]]></title>
      <link>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</link>
      <guid>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</guid>
      <description><![CDATA[I am teaching Web Services and XML Security training at OWASP's AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application...]]></description>
      <content:encoded><![CDATA[<p>I am teaching <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">Web Services and XML Security training</a> at OWASP&#39;s AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application servers, databases, ERP, and CRM. &#160;Increasingly we are seeing Web services in more B2C roles with Rest, Federation and other technologies. The class looks at how Web services applications are built, what are common threats and vulnerabilities in Web services, and how to build your Web services application to defend against them.</p><br /><div>I have often said that OWASP conferences are my favorite ones because they are in depth technically and very practical. I always look forward to teaching at OWASP and the speaker lineup for this conference looks excellent.</div><br /><div>Here is a quick list of tools we have used in past classes<br /></div><br /><div><span style="color: #333333; line-height: 19px; "><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Web Services frameworks</strong><br /><a href="http://incubator.apache.org/cxf/" style="text-decoration: underline; color: #003366; ">Apache CXF</a>&#160;- very interesting open source Web services framework with support for JMS, SOAP, and Rest<br />Apache&#160;<a href="http://ws.apache.org/axis/" style="text-decoration: underline; color: #003366; ">Axis</a>&#160;&amp;&#160;<a href="http://ws.apache.org/axis2/" style="text-decoration: underline; color: #003366; ">Axis2</a><br /><a href="http://en.wikipedia.org/wiki/Windows_Communication_Foundation" style="text-decoration: underline; color: #003366; ">.Net</a><br /><a href="https://metro.dev.java.net/" style="text-decoration: underline; color: #003366; ">Metro</a>&#160;- interesting framework from Sun for interop with WCF</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Identity</strong>&#160;<br /><a href="http://www.pingidentity.com/products/pingfederate.cfm" style="text-decoration: underline; color: #003366; ">PingFederate</a>&#160;- leading federation tool, we&#39;ll look at browser based SSO with SAML<br /><a href="http://www.pingidentity.com/products/web-services.cfm" style="text-decoration: underline; color: #003366; ">PingFederate Web Services</a>&#160;- we&#39;ll look at how to implement a STS in Web services<br /><a href="http://www.bandit-project.org/index.php/Welcome_to_Bandit" style="text-decoration: underline; color: #003366; ">Bandit</a>&#160;-&#160;<a href="http://en.wikipedia.org/wiki/Windows_CardSpace" style="text-decoration: underline; color: #003366; ">Cardspace</a>, authorization, and auditing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Security Services</strong><br /><a href="http://www.vordel.com/products/vx_gateway/" style="text-decoration: underline; color: #003366; ">VordelSecure</a>&#160;- XML gateway, comprehensive web services security policy creation and enforcement, deploying decentralized security services<br /><a href="http://ws.apache.org/axis2/modules/rampart/1_0/security-module.html" style="text-decoration: underline; color: #003366; ">Apache Ramparts</a><br /><a href="http://www.modsecurity.org/" style="text-decoration: underline; color: #003366; ">modecurity</a></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Testing</strong><br /><a href="http://www.vordel.com/products/soapbox/" style="text-decoration: underline; color: #003366; ">Soapbox</a>&#160;- web services security testing<br /><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" style="text-decoration: underline; color: #003366; ">WebScarab</a>&#160;- web services fuzzing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Static Analysis</strong><br /><a href="http://www.fortifysoftware.com/products/sca/" style="text-decoration: underline; color: #003366; ">Fortify SC</a>A - how to scan your web services code for security bugs *before* you deploy</p></span><br /><div><span style="color: #333333; line-height: 19px; ">This is just a quick list, new tools are added periodically. If you are using tools of these types in your company you may find it interesting <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">to attend</a>.</span><br /></div><br /><div>Testimontials on past classes<br /><br /><div><span style="font-family: Times; font-size: 16px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; ">&quot;High quality detailed overview of SOA security standards and approaches. Well thought-out and structured presentation.&quot;<br />- Sr. IT Architect, Fortune 10 enterprise<p>&quot;The knowledge and transfer was a great baseline and with the additional resources Gunnar made available, made this one of the best one day classes I&#39;ve taken.&quot;<br />- IT Security Lead, Fortune 10 enterprise</p><p>&quot;This class was a thorough and well-organized trek through the current Web Services Security landscape. Going beyond just describing the standards and the options available in the Web Services Security world, this class discusses real-world use cases and offers implementable solutions, best practices, even vendor choices in several key areas. &#160;This class provided me with actionable tasks that I took back to my project teams the very next day!&quot;<br />-Jesse Aalberg, Sr. Enterprise Application Architect, United Healthcare</p><p>&quot;The class was distinctly focused on Security requirements and the strength and weaknesses of the various solution approaches we could consider. The result of the course was actionable approaches to providing security in our SOA environment.&quot;<br />-Brad Sillman, Director IT Security, Deluxe Corp.</p><p>&quot;Anyone who wants up-to-date information on SOA Security, security standards and best practices should take this class.&quot;<br />-Kevin Beam, Senior Systems Engineer, Union Pacific Railroad</p><p>&quot;Good comprehensive overview of subject, standards, and threats&quot;&#160;<br />- Sr.Security Consultant, Ubizen</p><p>&quot;The class helped me get my head around what &quot;SOA&quot; and WS-Security is really all about&quot;<br />- Mike Zusman, Independent consultant</p><p>&quot;Topics addressed are timely and relevant. Labs are hands-on and help see concepts in action&quot;<br />- Jerry Tan, Systems Analyst, DTCC</p><p>&quot;This class was concise and covered a majority of the problem set my company is looking at and dealing with.&quot;&#160;<br />- Steve Reilley, Technical consultant, Commerce Insurance</p><p>&quot;Excellent two day overview of security topics as related to Web Services.&quot;<br />- Daniel Reznick, Information Security, ADP</p><p>&quot;Issue affecting&#160;<span style="text-decoration: underline;">most</span>&#160;of us today &amp; for those that don&#39;t - will soon. Very necessary education and technology.&quot;<br />Aaron Delashmutt</p><p>&quot;Great class! Effective and relevant teaching in an area without much guidance.&quot;<br />- Mark DiSabato, Senior Information Security Architect, Roche</p><p>&quot;The class cut through jargon to communicate concepts and implementation details.&quot;<br />- Developer, Fortune 100 insurance company</p><p>&quot;Good overview regarding SOA Security. Contains new technology like AMQP and REST&quot;&#160;<br />- Lars Loland, Statoil</p><p>&quot;The course covered what I had to learn about Web services&quot;<br />- Sven Vetsch, Dreamlab Technologies</p><p>&quot;Very good, eye opening especially for websecurity noob.&quot;<br />-Michael Brandon</p><p>&quot;Presenter has very broad and deep technical knowledge on subject. Content: good overview and comparison of SAML and WS-*&quot;<br />- Security consultant, ING</p><p>&quot;Good to learn where our application is vulnerable to attacks and how we can avoid them.&quot;<br />- Application Development Programmer Lead, Fortune 100 Insurance company</p><p>&quot;Entirely thorough overview of technology surrounding the use of web services with a 1 day presentation&quot;<br />- Technical consultant Contextis</p><p>&quot;Gave a good overview of the Web services security environment&quot;<br />- Francesco Degrassi, Emaze Networks</p><p>&quot;A great entry point for securing your web services&quot;<br />- Stig Kluver</p><p>&quot;Lots of good technical information about an emerging area that&#39;s very useful&quot;<br />- Rory McClune, HBOS PLC</p><p>&quot;This class reinforced the importance of software security assurance to me as it lucidly demonstrated why being &#39;behind the firewall&#39; is an outdated concept.&quot;<br />-Senior Support Engineer, Software Security vendor</p><p>&quot;The area of SOA Security is complicated and youg. A course such as this helps bring it into focus.&quot;<br />-Jayme Frye, System Engineer, Union Pacific Railroad</p><p>&quot;Web services security class provided application security concepts valuable for applications audits.&quot;<br />- Mary Ma, IT Auditor, DTCC</p><p>&quot;Very knowledgeable coverage of security requirements for Web services.&quot;<br />- David Libershal, Network Security Engineer, Johns Hopkins University Applied Physics Laboratory</p><p>&quot;WS/XML security is not a &quot;black art&quot;, but you do need to know about it to be able to take it into consideration.&quot;<br />- Applications Specialist, Global 500 manufacturer</p><p>&quot;Good overview of techniques worth considering when planning secure apps&quot;<br />- EAI Specialist, Leading Mobility company</p><p>&quot;Brought concepts in very easily understood terms.&quot;<br />-Glenn Bernard, Systems Engineer</p><p>&quot;Gives ideas about the latest Web services security standards in the industry&quot;<br />- Security Coordinator, Global 500 manufacturer</p><p>&quot;Class cleared up various WS-* standards and gave great concrete examples of how to build a message using each standard. Very good general thoughts on security groups&#39; role in IT.&quot;<br />- Matt Kasselman, UP Systems Engineering</p><p>&quot;I found this very useful as an IT architect in a &quot;security critical environment&quot;.&quot;<br />- Mika Pullinen, IT Architect, Finnish Defense Forces</p><p>&quot;Lots of useful information packed in a small amount of time. Good overall picture.&quot;<br />- Jari Pirhonen, Security Director, Samlink</p><p>&quot;Gunnar is very knowledgeable about security topics and has a great ability to explain complex ideas using simple, appropriate, and amusing language and analogies.&quot;<br />- Scott Redd, Sr. Project Engineer, Union Pacific</p><p>&quot;Excellent instructor who had a good pace to go through the presentation&quot;&#160;<br />- Anna Vaahtokan, Specialist, Nordea</p><p>&quot;Good application security principles.&quot;<br />- Tuomas Kivinen, IT Security Specialist, Nordea</p><p>&quot;I liked the class quite a bit. I took it in a &quot;survey mode&quot; where I wanted to learn about topics at a high level, and this was accomplished. It was good to listen to those in the class that were much more familiar with SAO than I.&quot;<br />- John Glazeski, Senior Systems Engineer</p></span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 04:55:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/soa security standards">soa security standards</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/soa security">soa security</category>
      <category domain="http://securityratty.com/tag/soa">soa</category>
      <category domain="http://securityratty.com/tag/security critical environment">security critical environment</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/application security principles">application security principles</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/web-services-and-xml-security-training-at-owasp.html">Web Services and XML Security Training at OWASP</source>
    </item>
    <item>
      <title><![CDATA[SDL and the XSS Filter]]></title>
      <link>http://securityratty.com/article/ce479edf032699e552a4cb52750d1f63</link>
      <guid>http://securityratty.com/article/ce479edf032699e552a4cb52750d1f63</guid>
      <description><![CDATA[Steve Lipner here. When the Internet Explorer team posted the announcement about the XSS Filter feature in IE8 I asked some other members of the SDL blog team why arent we talking about the new XSS...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Steve Lipner here.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>When the Internet Explorer team posted the announcement about the </FONT><A href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iv-the-xss-filter.aspx"><FONT face=Calibri color=#0000ff size=3>XSS Filter feature in IE8</FONT></A><FONT size=3><FONT face=Calibri> <SPAN style="mso-spacerun: yes">&nbsp;</SPAN>I asked some other members of the SDL blog team “why aren’t we talking about the new XSS Filter feature on the SDL blog?” &nbsp;Bryan and Jeremy said something like “that’s a mitigation that only applies to specific clients and a subset of attacks”.&nbsp; So we didn’t cross-reference IE’s XSS Filter post on the SDL blog at the time.&nbsp; Instead, I agreed to write a subsequent post about the relationship of XSS Filter to the SDL and to the ways that our SDL and security science teams think about improving product security.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>For those of you who aren’t familiar with XSS Filter, a brief summary is that it is a client-side defense against reflected cross-site scripting (XSS) attacks.&nbsp; It works by recognizing that reflected XSS attacks inject script into the string that the browser sends to the targeted web server.&nbsp; If the server doesn’t neuter or strip out the injected script, it gets sent back to the browser and executed in the context of the target web page.&nbsp; Bad things then happen.&nbsp; At a high level, XSS Filter remembers the string that the browser sent to the server, and looks at the server’s response to see if any of the script was actually in that string.&nbsp; If it was, then XSS Filter decides that it got there because it was injected by an XSS attack and blocks the script from executing.&nbsp; The rest of the web page renders as usual.&nbsp; This is a vastly oversimplified sketch of XSS Filter – for details, see the post by David Ross, inventor of XSS Filter on the </FONT><A href="http://blogs.technet.com/swi/archive/2008/08/19/ie-8-xss-filter-architecture-implementation.aspx"><FONT face=Calibri color=#0000ff size=3>Security Vulnerability Research and Defense blog</FONT></A><FONT size=3><FONT face=Calibri>.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>So what does XSS Filter have to do with the SDL?&nbsp; Well, for almost nine years, since XSS was first discovered at Microsoft, we’ve been trying to figure out effective ways to reduce vulnerability to XSS attacks.&nbsp; Our focus has been on improving the ways that web page developers code their pages, and we’ve developed a lot of tools and techniques for making web content safer from XSS attacks and for detecting XSS vulnerabilities in live pages.&nbsp; The SDL requires the use of many of these tools and techniques, and we’re sure we’ve prevented a lot of XSS vulnerabilities from being introduced into Microsoft web pages as a result.&nbsp; <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>But while we identify (and the SDL requires) measures that allow developers to avoid classes of vulnerabilities, we also look to identify more sweeping solutions that can either 1) eliminate classes of vulnerabilities, 2) reduce their severity, or 3) reduce the likelihood of attacks being successful.&nbsp; The process usually starts from deep understanding of a class of vulnerabilities and attacks, and then we broaden defenses from there.&nbsp; In the case of XSS Filter, David’s years of work researching XSS led him to come up with an approach that blocks many of the most common vulnerabilities to reflected attacks found on the web today.&nbsp; The solution is compatible with existing web pages (doesn’t “break the web”) and thus we were able to enable it by default for users of Internet Explorer 8.&nbsp; Because it’s a client-side mitigation, it will help protect users from attacks even though the sites they visit may be vulnerable to XSS.&nbsp; <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Our work on buffer overrun defenses follows a somewhat similar pattern – we started by prescribing coding techniques, banning the use of some APIs, and building tools that detect coding constructs that look like buffer overruns.&nbsp; As we gained a deeper understanding of how buffer overruns can be exploited, we enhanced the </FONT><A href="http://msdn.microsoft.com/en-us/library/8dbf701c(VS.80).aspx"><FONT face=Calibri size=3>/GS compiler flag</FONT></A><FONT face=Calibri size=3> and added </FONT><A href="http://blogs.msdn.com/michael_howard/archive/2006/05/26/address-space-layout-randomization-in-windows-vista.aspx"><FONT face=Calibri color=#0000ff size=3>ASLR</FONT></A><FONT size=3><FONT face=Calibri> in a quest to cause classes of exploits to fail even if a buffer overrun remains.&nbsp; We’re not yet close to eliminating the SDL requirements for use of tools and coding techniques, but the SDL also requires the use of the mitigations to reduce the severity of vulnerabilities that slip past.&nbsp; Will we ever get to the point where the mitigating technologies are so strong that we can relax the coding requirements?&nbsp; Maybe not, but we will continue to introduce technologies that reduce the chances of a successful attack.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Similarly, in the case of XSS, even after IE8 ships, the SDL will continue to require the use of safe web site coding practices and tools such as the </FONT><A href="http://msdn.microsoft.com/en-us/library/aa973813.aspx"><FONT face=Calibri color=#0000ff size=3>Anti-XSS library</FONT></A><FONT size=3><FONT face=Calibri> both to protect users of browsers other than IE8 and to provide protection in recognition of the fact that XSS Filter is a mitigation or defense in depth rather than a complete solution.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>But we’ll also be keeping our eyes open (and doing active research) in the quest for an even more effective defense – whether client or server side – that eliminates XSS for good.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>This post is a little far afield from the normal content of the SDL blog, but I thought it was important to provide a picture of the role of security science and security research in defining SDL requirements and in making major improvements in software security.&nbsp; You can read more about our work in security science in the </FONT><A href="http://blogs.technet.com/swi/default.aspx"><FONT face=Calibri color=#0000ff size=3>Security Vulnerability Research and Defense blog</FONT></A><FONT size=3><FONT face=Calibri>.</FONT></FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8900490" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 11:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/xss filter">xss filter</category>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/xss led">xss led</category>
      <category domain="http://securityratty.com/tag/anti-xss library">anti-xss library</category>
      <category domain="http://securityratty.com/tag/xss attack">xss attack</category>
      <category domain="http://securityratty.com/tag/xss attacks">xss attacks</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/xss filter remembers">xss filter remembers</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/08/27/sdl-and-the-xss-filter.aspx">SDL and the XSS Filter</source>
    </item>
    <item>
      <title><![CDATA[File Integrity Monitoring: Secure Your Virtual and Physical IT Environments]]></title>
      <link>http://securityratty.com/article/f25697c6547acff1ffe2bf8a0039f459</link>
      <guid>http://securityratty.com/article/f25697c6547acff1ffe2bf8a0039f459</guid>
      <description><![CDATA[Source: Tripwire) Looking for a File Integrity Monitoring Solution? With the numerous servers, devices and applications organizations rely on to support their everyday business, outages and security...]]></description>
      <content:encoded><![CDATA[<b>(Source: Tripwire)</b>  Looking for a File Integrity Monitoring Solution? With the numerous servers, devices and applications organizations rely on to support their everyday business, outages and security breaches due to poor IT configurations are unacceptable. In addition, many organizations must now prove compliance with standards like PCI DSS designed to protect systems and sensitive data. File integrity monitoring solutions minimize security risk resulting from undesirable configuration change by monitoring, detecting, and reconciling changes to key files throughout the virtual and physical IT infrastructures.<p>Learn how file integrity monitoring solutions work and the capabilities you should expect your solution to have. Then review a detailed checklist you should complete before purchasing your solution. Finally, discover how Tripwire Enterprise effectively combines file integrity monitoring with configuration assessment-a single configuration control solution that proactively assesses and monitors the IT infrastructure and enables organizations to achieve and maintain compliance with standards and regulations.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=4fD2VT"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=4fD2VT" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/374621002" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/file integrity">file integrity</category>
      <category domain="http://securityratty.com/tag/applications organizations rely">applications organizations rely</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/enables organizations">enables organizations</category>
      <category domain="http://securityratty.com/tag/security breaches due">security breaches due</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/undesirable configuration change">undesirable configuration change</category>
      <category domain="http://securityratty.com/tag/maintain compliance">maintain compliance</category>
      <category domain="http://securityratty.com/tag/numerous servers">numerous servers</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/374621002/whitepapers.do">File Integrity Monitoring: Secure Your Virtual and Physical IT Environments</source>
    </item>
    <item>
      <title><![CDATA[Red Light Cameras Don't Work]]></title>
      <link>http://securityratty.com/article/8352bdbeaa301a76267200c64791415d</link>
      <guid>http://securityratty.com/article/8352bdbeaa301a76267200c64791415d</guid>
      <description><![CDATA[Interesting : the solution to one problem causes another. &quot;The rigorous studies clearly show red-light cameras don't work,&quot; said lead author Barbara Langland-Orban, professor and chair of health...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.ridelust.com/red-light-cameras-just-dont-work/">Interesting</a>: the solution to one problem causes another.</p>

<blockquote>"The rigorous studies clearly show red-light cameras don't work," said lead author Barbara Langland-Orban, professor and chair of health policy and management at the USF College of Public Health. "Instead, they increase crashes and injuries as drivers attempt to abruptly stop at camera intersections."

<p>Comprehensive studies from North Carolina, Virginia, and Ontario have all reported cameras are associated with increases in crashes. The study by the Virginia Transportation Research Council also found that cameras were linked to increased crash costs. The only studies that conclude cameras reduced crashes or injuries contained "major research design flaws," such as incomplete data or inadequate analyses, and were always conducted by researchers with links to the Insurance Institute for Highway Safety. The IIHS, funded by automobile insurance companies, is the leading advocate for red-light cameras since insurance companies can profit from red-light cameras by way of higher premiums due to increased crashes and citations.</blockquote></p>

<p>And, of course, the agenda of the government is to increase revenue due to fines:</p>

<blockquote>A 2001 paper by the Office of the Majority Leader of the U.S. House of Representatives reported that red-light cameras are "a hidden tax levied on motorists." The report came to the same conclusions that all of the other valid studies have, that red-light cameras are associated with increased crashes and that the timings at yellow lights are often set too short to increase tickets for red-light running. That's right, the state actually tampers with the yellow light settings to make them shorter, and more likely to turn red as you're driving through them.

<p>In fact, six U.S. cities have been found guilty of shortening the yellow light cycles below what is allowed by law on intersections equipped with cameras meant to catch red-light runners. Those local governments have completely ignored the safety benefit of increasing the yellow light time and decided to install red-light cameras, shorten the yellow light duration, and collect the profits instead.</p>

<p>The cities in question include Union City, CA, Dallas and Lubbock, TX, Nashville and Chattanooga, TN, and Springfield, MO, according to Motorists.org, which collected information from reports from around the country.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=GkyduK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=GkyduK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=gARYoK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=gARYoK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:19:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/red">red</category>
      <category domain="http://securityratty.com/tag/red-light">red-light</category>
      <category domain="http://securityratty.com/tag/red-light runners">red-light runners</category>
      <category domain="http://securityratty.com/tag/install red-light cameras">install red-light cameras</category>
      <category domain="http://securityratty.com/tag/cameras">cameras</category>
      <category domain="http://securityratty.com/tag/red-light cameras">red-light cameras</category>
      <category domain="http://securityratty.com/tag/conclude cameras">conclude cameras</category>
      <category domain="http://securityratty.com/tag/studies">studies</category>
      <category domain="http://securityratty.com/tag/rigorous studies">rigorous studies</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/red_light_camer.html">Red Light Cameras Don't Work</source>
    </item>
  </channel>
</rss>
