<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: syslog]]></title>
    <link>http://securityratty.com/tag/syslog</link>
    <description></description>
    <pubDate>Fri, 25 Apr 2008 10:12:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Events per Second the difference between a target and an assurance]]></title>
      <link>http://securityratty.com/article/f9815504814bde06b74afe918ec8d827</link>
      <guid>http://securityratty.com/article/f9815504814bde06b74afe918ec8d827</guid>
      <description><![CDATA[Weve been getting a good few questions recently about how many Events Per Second a SIEM product support. Well, that depends on a few factors
The transport processing Syslog events takes up a heck of a...]]></description>
      <content:encoded><![CDATA[<p>We&rsquo;ve been getting a good few questions recently about how many Events
  Per Second a SIEM product support. Well, that depends on a few factors:</p>

<ul>
  <li><strong>The transport</strong> &ndash; processing Syslog events takes up
    a heck of a lot less processing power than collecting from a Windows box.
    Same with collecting data over an ODBC connection.</li>
</ul>]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/syslog events takes">syslog events takes</category>
      <category domain="http://securityratty.com/tag/siem product support">siem product support</category>
      <category domain="http://securityratty.com/tag/windows box">windows box</category>
      <category domain="http://securityratty.com/tag/questions recently">questions recently</category>
      <category domain="http://securityratty.com/tag/odbc connection">odbc connection</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/transport">transport</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1390">Events per Second the difference between a target and an assurance</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-15 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/76641371b3a7f5060624cdd792c7e9cb</link>
      <guid>http://securityratty.com/article/76641371b3a7f5060624cdd792c7e9cb</guid>
      <description><![CDATA[Quest grabs NetPro to strengthen Windows management wares - Network World NetPros lineup includes tools focused on security/compliance, infrastructure administration and identity/access. Those tools...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.networkworld.com/news/2008/091208-quest.html">Quest grabs NetPro to strengthen Windows management wares - Network World</a><br/>
NetPro’s lineup includes tools focused on security/compliance, infrastructure administration and identity/access.

Those tools include auditing, backup/recovery, policy enforcement, event log management, Exchange migration, group policy management, health/performance and user self-service password management</li>
<li><a href="http://searchsecurity.techtarget.com.au/articles/26900-Are-common-logging-and-audit-standards-emerging-">Are common logging and audit standards emerging? :: SearchSecurity.com.au</a></li>
<li><a href="http://news.zdnet.com/2424-9595_22-218408.html">SaaS market will 'collapse' in two years | Tech News on ZDNet</a><br/>
Q: Won&#039;t people avoid the mistakes of &quot;previous&quot; SaaS incarnations, as you mentioned?

A: People are stupid. History has shown it repeats itself, and people make the same mistakes.</li>
<li><a href="http://www.crmoutsiders.com/2008/08/28/lawson-ceo-saas-will-collapse-in-two-years/">CRM Outsiders &raquo; Blog Archive &raquo; Lawson CEO: SaaS Will &ldquo;Collapse&rdquo; In Two Years</a><br/>
I couldn’t disagree more, but than again it was also Harry Debes that predicted that many of today’s Web 2.0, cell phone gadgets would never catch on either. SaaS is certainly here to say. I</li>
<li><a href="http://www.dimitrimckay.com/Loglogic/Blog/Entries/2008/7/20_How_to_convert_windows_logs_to_syslog:.html">Nerd News: Eventlog to Syslog</a></li>
<li><a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">(ISC)2 Blog: Event Correlation</a></li>
<li><a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">Speaking of Security... | Blog Entry: Paul Stamp | Correlation is no silver bullet: 1301</a><br/>
So, when deploying SIEM to improve your security operations, remember that correlation only really works when backed up by real data about what is the biggest problem in your environment, and how that problem manifests itself in the event logs. I call it &quot;working out what type of needles you&#039;ll find in your haystack.&quot;</li>
<li><a href="http://blogs.zdnet.com/Gardner/?p=2723">Systems log analytics offers operators performance insights that set stage for IT transformation | Dana Gardner&rsquo;s BriefingsDirect | ZDNet.com</a></li>
<li><a href="http://www.nemertes.com/analyst_blogs/sharpening_stones_and_walking_coals">Sharpening Stones and Walking on Coals | Nemertes Research</a><br/>
When hunting for a needle in a haystack, after all, making the haystack larger is not an obviously productive course; getting a tool that can assist in the hunt - a magnet, or a metal detector - makes more sense!</li>
<li><a href="http://www.nemertes.com/analyst_blogs/search_or_destroy">Search or Destroy | Nemertes Research</a><br/>
It&#039;s not all about security, it&#039;s not all about events, it&#039;s not all about compliance. All those things are critically important to IT, of course, but even more fundamental is the task of keeping things running.</li>
<li><a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">jdm's Blog: How worthwhile is logging?</a><br/>
Logs are like a warm blanket; verbose logging means you can know what&#039;s happening on your systems if you keep up with the logs.  At the same time, logs become a burden very very easily, and they are easy to ignore.</li>
<li><a href="http://blog.gerhards.net/2008/07/what-is-event-and-what-event-log.html">Rainer's Blog: What is an Event? And what an Event Log?</a></li>
<li><a href="http://duckdown.blogspot.com/2008/07/taming-documentum-audit-trail.html">Enterprise Architecture: From Incite comes Insight...: Taming the Documentum Audit Trail</a><br/>
First and foremost, it is a good security principle to separate log data from the system.</li>
<li><a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">Log management is a pain | Thomas Nicholson</a><br/>
So for an administrator to not care about logs was a shock.</li>
<li><a href="http://blogs.splunk.com/thebaum/2008/09/03/situational-awareness/">thebaumblog &raquo; Blog Archive &raquo; Life after SIEM. Situational Awareness is next.</a><br/>
Life after SIEM. Situational Awareness is next.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/393875149" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/event logs">event logs</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/event log management">event log management</category>
      <category domain="http://securityratty.com/tag/event log">event log</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/saas market">saas market</category>
      <category domain="http://securityratty.com/tag/saas">saas</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/393875149/anton18">Links for 2008-09-15 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Logs and Log Management - 2]]></title>
      <link>http://securityratty.com/article/dac0b52428267c699e6e37706f29fb2a</link>
      <guid>http://securityratty.com/article/dac0b52428267c699e6e37706f29fb2a</guid>
      <description><![CDATA[I am amazed (no, AMAZED!) about how many people now write about logs; it is definitely not &quot;the original logging evangelist&quot; anymore :-) Here is a bunch of good log-related reading, useful for those...]]></description>
      <content:encoded><![CDATA[<p>I am amazed (no, AMAZED!) about how many people now write about logs; it is definitely not <a href="http://www.chuvakin.org">&quot;the original logging evangelist&quot;</a> anymore :-) Here is a bunch of good log-related reading, useful for those struggling with logs (aka &quot;everybody&quot; :-))</p>  <ol>   <li>Our brilliant field engineer Dimitri McKay <a href="http://www.dimitrimckay.com/Loglogic/Blog/Entries/2008/7/20_How_to_convert_windows_logs_to_syslog:.html">talks about</a> the eternal topic of converting Windows event logs to syslog. <a href="http://blogs.msdn.com/ericfitz/">Yes, Eric, we ALL know</a> it is ugly, but that is the only way that actually works well across all systems ...</li>    <li>More on Windows and syslog: &quot;<a href="http://redmondmag.com/columns/article.asp?editorialsid=1868">Syslog ... 20 Years Later</a>.&quot;&#160; BTW, this is really not about syslog, but about Vista/2k8 finally getting an ability to natively centralize the event logs via event subscriptions (&quot;It's only about twenty years behind schedule, if you're counting.&quot;)</li>    <li>Two fun pieces on correlation: <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">1</a> and <a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">2</a>. What often kills &quot;a log correlation project&quot;? &quot;Whoever had worked on it <em>had not had much time available to learn the way to properly configure the software</em>&quot; (from <a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">this</a>)&#160; and &quot;correlation only really works when backed up by real data about what is the biggest problem in your environment, and how that problem manifests itself in the event logs.&quot; (from <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">this</a>) None of this is new, but a useful reminder nonetheless</li>    <li>Fun <a href="http://www.loglogic.com">LogLogic</a> podcast is <a href="http://blogs.zdnet.com/Gardner/?p=2723">here</a>. The topic of this high-level discussion (CEO) is related to operational use for logs. I did one with them too; on logs and virtualization (will be up soon)</li>    <li>A couple of good posts on logging from Nemertes Research: &quot;<a href="http://www.nemertes.com/analyst_blogs/sharpening_stones_and_walking_coals">Sharpening Stones and Walking on Coals</a>&quot;,&#160; &quot;<a href="http://www.nemertes.com/analyst_blogs/search_or_destroy">Search or Destroy</a>&quot;</li>    <li><a href="http://eventlogs.blogspot.com/2008/08/why-your-hr-department-will-love.html">Reminder</a> about a few useful Windows Vista and 2k8 events: 4802 (screensaver engaged) and 4803 (screensaver dismissed)</li>    <li><a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">One person is wondering</a> about the usefulness of logging after &quot;experiencing&quot; Linux auditd logging (kernel audit): &quot;Logs are like a warm blanket; verbose logging means you can know what's happening on your systems if you keep up with the logs.&#160; At the same time, logs become a burden very very easily, and they are easy to ignore.&quot; <a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">This post</a> is a must read for <a href="http://www.chuvakin.org">us logging afficionados</a>; producing too much log data is a sure way to make people hate you...</li>    <li><a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">This</a> also follows the same theme: people doubting the god-like power of logs :-) &quot;So for an administrator to not care about logs was a shock.&quot; But would I argue that &quot;<a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">log management is NOT a pain?</a>&quot; Now, would I? :-)</li>    <li>A classic about logging for application developers: &quot;<a href="http://www.securityfocus.com/infocus/1888">Building Secure Applications: Consistent Logging</a>.&quot;&#160; I am noticing a lot more discussions about logging in a developer community, e.g. see <a href="http://ayende.com/Blog/archive/2008/08/02/Logging-Auditing-and-Alerts.aspx">this</a> and <a href="http://www.softwaremag.com/l.cfm?doc=1048-5/2007">this</a> (the latter, BTW, contains a lot of info on &quot;why log&quot; for developers). Overall, &quot;getting logging right&quot; is important (and will get more important in the future) and people need something NOW and cannot wait for the <a href="http://cee.mitre.org">standards.</a>&#160; BTW, I am planning a mini-crusade on how to train application developers to include useful logging in their applications...</li>    <li>Finally, the &quot;Is SIEM dead?&quot; theme is continued in this fun post &quot;<a href="http://blogs.splunk.com/thebaum/2008/09/03/situational-awareness/">Life after SIEM. Situational Awareness is next.</a>&quot; Indeed, <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">context is key for logs</a>. BTW, if somebody mentions that I have &quot;vendor bias&quot;, I will kick your ass! :-)</li> </ol>  <p>Enjoy!</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=gABUL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=gABUL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=5mpyL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=5mpyL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=AMhOL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=AMhOL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/393291744" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 04:03:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/windows event logs">windows event logs</category>
      <category domain="http://securityratty.com/tag/event logs">event logs</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/developers">developers</category>
      <category domain="http://securityratty.com/tag/train application developers">train application developers</category>
      <category domain="http://securityratty.com/tag/log correlation project">log correlation project</category>
      <category domain="http://securityratty.com/tag/application developers">application developers</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/393291744/fun-reading-on-logs-and-log-management.html">Fun Reading on Logs and Log Management - 2</source>
    </item>
    <item>
      <title><![CDATA[Even More Logging Questions - Answered]]></title>
      <link>http://securityratty.com/article/42419cabc2c6779620c8b8bb44fe54c9</link>
      <guid>http://securityratty.com/article/42419cabc2c6779620c8b8bb44fe54c9</guid>
      <description><![CDATA[I did this fun webcast on logging for accountability ( here ) and people asked a lot of good questions. Here are some of the answers for them and all my blog readers

Q1: How do you handle variety of...]]></description>
      <content:encoded><![CDATA[<p>I did <a href="http://isc2.brighttalk.com/node/403">this fun webcast</a> on logging for accountability (<a href="http://isc2.brighttalk.com/node/403">here</a>) and people asked a lot of good questions. Here are some of the answers for them and all my blog readers.</p>  <p>&#160;</p>  <p>Q1: How do you handle variety of log sources? There are so many, almost beyond my capability. </p>  <p>A1: Sorry to ponder the meaning of &quot;is&quot; here, but what is meant by &quot;handle&quot;? It is really not that hard to collect logs from a large number of diverse sources (as long as the logs can be delivered via syslog or exist as files and can be collected). Now, there will certainly be challenges&#160; when the volume of logs gets large, but if by &quot;handle&quot; you mean &quot;collect + store&quot;, it is really not that hard, given <a href="http://www.loglogic.com">the right tools.</a> Now, if &quot;handle&quot; means &quot;make sense of what all those logs are trying to tell you,&quot; it is a different story altogether.</p>  <p>&#160;</p>  <p>Q2: You talked about the importance of logging; however for an intermediate or novice admin what are the starting steps .. what are the minimal logs they should start at once?</p>  <p>A2: Answered in <a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">&quot;Log Management - Day 1&quot;</a> If you want a simple list of things to &quot;enable today,&quot;&#160; I cannot really answer it since I know neither your needs, nor your environment. In other words, this is the &quot;what is the meaning of life question?&quot; :-)</p>  <p>&#160;</p>  <p>Q3: What regulations, rules or guidance exist regarding sharing or visibility of logs to users?</p>  <p>A3: PCI DSS says in Requirement 10.5:&#160; &quot;Secure audit trails so they cannot be altered.    <br /><em>10.5.1 Limit viewing of audit trails to those with a job-related need      <br /></em>10.5.2 Protect audit trail files from unauthorized modifications     <br />10.5.3 Promptly back-up audit trail files to a centralized log server or media that is difficult to     <br />alter&quot; </p>  <p>NIST guidance for FISMA also says something similar (for example, look in <a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf">NIST 800-92 doc</a>). Overall, <a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">log protection and security</a> are mentioned in many other regulations as well. </p>  <p>&#160;</p>  <p>Q4: Privileged groups membership monitoring in AD one of the most important from my point of view. However I did not find effective way to monitor/report on changes in those groups. Any recommendations?</p>  <p>A4: This is indeed a tricky one which might take more space to answer than I have here; it might also take you 'beyond logs.' One good source of information is <a href="http://www.ultimatewindowssecurity.com/encyclopedia.aspx">Randy Smith's site</a> and, specifically, his webinar on 'Active Directory &quot;Logging Gap&quot;' (<a href="http://www.ultimatewindowssecurity.com/aaad/">here somewhere</a>) - which covers how to audit things of that sort when then native logging is not sufficient.</p>  <p>&#160;</p>  <p>Q5: How I can learn what exactly I need to log?</p>  <p>A5: OMG, this is a $1,000,000 question :-) Let me answer &quot;how can I learn&quot; part and not the &quot;what exactly I need to log part,&quot;&#160; (also see discussion on &quot;<a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a>&quot;) as it is actually answerable. To learn what you need to log, first ask &quot;Why?&quot; (and then see <a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">this</a>) - basically establish what you want to accomplish with logs, catalogue your systems, figure how to tweak the logging knobs - and then do it!</p>  <p>&#160;</p>  <p>Q6: How granular should logging be? What is your recommendation for enterprise servers like domain servers and Windows servers?</p>  <p>A6: Again, too long to answer here in details (it will become a subject of a longer blog post later), but some pointers follow: <a href="http://www.ultimatewindowssecurity.com/blog/blog_commento.asp?blog_id=23&amp;month=05&amp;year=2007&amp;giorno=&amp;archivio=OK">here for Windows</a> (MS site also have a few recommendations on audit policies)</p>  <p>&#160; </p>  <p>Q7: What is &quot;more control&quot; and what is &quot;less control&quot; that you <a href="http://isc2.brighttalk.com/node/403">mention in the webcast</a>? Can you give an example?</p>  <p>A7: OK, I did say that &quot;sometimes when you implement more controls, you actually have less control.&quot; What do I mean? If you buy a firewall (a network security control) and then - over time, of course - configure it with 7800 rules (!) that are supposed to give you control over who can and cannot access your network, you will not gain control over your environment. You will actually be less in control of who is touching your network, compared to, say, having only 20 rules.</p>  <p>&#160;</p>  <p>Q8: What about mandated NIST controls for government systems? Auditing is a specific control for Moderate and High risk systems. What list of events do you recommend for auditing?</p>  <p>A8: This is too long to answer here, but <a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf ">NIST 800-92 Guide</a> is a really good source of such info (&quot;<a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf">Guide to Computer Security Log Management [PDF]</a>&quot;) Also, see my presentation on <a href="http://www.slideshare.net/anton_chuvakin/nist-80092-log-management-guide-in-the-real-world/">NIST 800-92 Guide in the Real World</a>.</p>  <p>&#160;</p>  <p>Q9: The issue that many organizations get stuck on, is the monitoring process, and defining what exceptions to monitor for? Is there guidance / framework for this? How much of it is system specific and how much is applicable generally to all systems?</p>  <p>A9: I outlined some general ideas <a href="http://www.slideshare.net/anton_chuvakin/what-every-organization-should-log-and-monitor">back in 2004 via this presentation</a>&#160;<em>(note to self - update that to be more 2008-relevant);</em> it is mostly general, but also has pointers to specific system. Keep in mind that it is focused on security, not operational monitoring (which is often no less important - in fact, often <a href="http://rationalsecurity.typepad.com/blog/2008/02/omg-availabilit.html">MORE important</a>)</p>  <p>&#160;</p>  <p>Enjoy! Sorry for being brief with some of the answers - I am woefully late with this even as they are...</p>  <p><strong>Other questions that I answered in the past:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/05/more-log-management-questions-answered.html">More Log Management Questions - Answered!</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/some-burning-logging-questions-answered.html">Some Burning Logging Questions - Answered!</a> </li> </ul>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=juyDeK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=juyDeK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=o5WeXK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=o5WeXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mnNGqK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mnNGqK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/357664119" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 07:43:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log server">log server</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/log sources">log sources</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <category domain="http://securityratty.com/tag/questions">questions</category>
      <category domain="http://securityratty.com/tag/specific control">specific control</category>
      <category domain="http://securityratty.com/tag/network security control">network security control</category>
      <category domain="http://securityratty.com/tag/log protection">log protection</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/357664119/even-more-logging-questions-answered.html">Even More Logging Questions - Answered</source>
    </item>
    <item>
      <title><![CDATA[Q&A with Sergey Katsev of Coyote Point Systems]]></title>
      <link>http://securityratty.com/article/e57e1ace426f0aef838f8f362c558571</link>
      <guid>http://securityratty.com/article/e57e1ace426f0aef838f8f362c558571</guid>
      <description><![CDATA[I recently had the opportunity to sit down with Sergey Katsev , an Engineering Project Manager at Coyote Point Systems and discuss his experiences with InteropNet and talk about the Coyote Point...]]></description>
      <content:encoded><![CDATA[<p>I recently had the opportunity to sit down with <a href="http://www.facebook.com/profile.php?id=24405331" target="_blank">Sergey Katsev</a>, an Engineering Project Manager at <a href="http://coyotepoint.com/" target="_blank">Coyote Point Systems</a> and discuss his experiences with InteropNet and talk about the Coyote Point products.  With a couple of years of experience as a vendor for Interop, he had some interesting insights in to how participating in the InteropNet can help a vendor.</p>
<p><strong>ScienceLogic:</strong> How long have you been involved in InteropNet?</p>
<p><strong>Katsev: </strong>I started at Coyote Point 3 years ago and <a href="http://blog.interop.com/2006" target="_blank">InteropNet 2006</a> was my first &#8220;big&#8221; assignment.  This was the first time Coyote Point had put in a proposal to participate, so we were very excited when we were selected.</p>
<p><strong></strong></p>
<p><strong>ScienceLogic: </strong>How long has Coyote Point been involved in Interop overall?</p>
<p><strong>Katsev: </strong>We&#8217;ve been exhibiting at Interop for a number of years, and after seeing the InteropNet in action, we decided to submit a proposal in &#8216;06.  We were actually one of the first companies in the load balancing/traffic management space (we&#8217;ve been doing this for almost 10 years), so we have a lot of experience to share with InteropNet.</p>
<p><strong>ScienceLogic:</strong> What is your role at Coyote Point?</p>
<p>My official title is &#8220;Engineering Project Manager&#8221;.  Basically, that means that I&#8217;m in charge of product releases and maintenance.  It sounds like a weird title for someone participating in InteropNet, but I&#8217;ve actually found it extremely useful since my position means that I don&#8217;t get to see our systems out in the field a lot.  We&#8217;ve added several features and have ideas for others just from my experiences at InteropNet.</p>
<p><strong></strong></p>
<p><strong>ScienceLogic:</strong> What do the Coyote Point products do?</p>
<p><strong>Katsev: </strong>Coyote Point makes a Traffic Management appliance called <a href="http://coyotepoint.com/products/e650.php" target="_blank">Equalizer</a>.  What this means is that any traffic destined for a datacenter&#8217;s servers goes through our appliances and we make sure that the server which is best equipped to handle it, does.  Our systems sit between the clients and the servers and monitor the client traffic and the state of the servers.  If the clients start sending more traffic, we&#8217;ll balance it out so that no server is overloaded.  If one of the servers stops responding or starts responding very slowly, we&#8217;ll steer traffic away from that server.</p>
<p><strong>ScienceLogic: </strong>In what way are your products being used as part of InteropNet?</p>
<p><strong>Katsev: </strong>In the InteropNet, we&#8217;re utilizing a lot of our expertise:  We&#8217;re making sure that traffic is balanced and servers are redundant for show services such as DNS and SMTP.  We&#8217;re also using our geographic load balancing technology to ensure that the ScienceLogic EM7 appliances and some other internal NOC services are available from anywhere, with the lowest latency, with our <a href="http://www.coyotepoint.com/products/xcel.php" target="_blank">SSL acceleration </a>and <a href="http://www.coyotepoint.com/products/express.php" target="_blank">GZIP compression technology</a>.  Finally, we&#8217;re helping logistics in the NOC by allowing a physical separation between systems <a href="http://blog.interop.com/interopnet/2008/04/what-are-these-peds-you-speak-of" target="_blank">located in the NOC</a> and those in an emergency rack outside of the NOC.  If either of these two locations were to fail, the network will continue operating without a glitch.</p>
<p><strong>ScienceLogic:</strong> Are there any special considerations for Interop that cause you to deploy your systems there differently that any other place?</p>
<p><strong>Katsev: </strong>Interop is definitely different than most of our customer installations.   One difference from a standard environment is that the network (at least this year) is one large flat network, with pieces carved out where extra security is needed.  Because of this, we can actually run our failover pairs of Equalizer systems in a non-standard configuration where the two peers are in different racks, or even on different floors.  That&#8217;s one of the things that I really like about InteropNet &#8212; it definitely brings new ideas to mind, which end up becoming &#8217;special configuration&#8217; white papers after the show.</p>
<p><strong>ScienceLogic:</strong> Has InteropNet taught you anything that caused you to actually change your product?</p>
<p><strong>Katsev: </strong>In addition to the failover configuration differences I mentioned above, participating in InteropNet has actually caused us to add several new features and allowed configurations.  One example is the &#8220;no-spoof&#8221; option for <a href="http://www.springerlink.com/content/dcmmpmb53rjp5hr8/" target="_blank">Layer 4 clusters</a>.  Prior to the 2006 shows, we always &#8217;spoofed&#8217; the client&#8217;s IP address when talking to a server so that the server would see the client&#8217;s IP address instead of our own.  At Interop, we ran into a special configuration which would&#8217;ve been very difficult to set up in this manner, so our engineers added this feature, and it&#8217;s been very a very popular configuration with our customers ever since.</p>
<p>We have also had a couple of business relationships that extended outside of the show.  In 2006, we had a good experience using <a href="http://www.spirent.com/analysis/index.cfm?media=3&amp;ws=2" target="_blank">Spirent Communications</a> gear to benchmark the network, so we ended up purchasing a couple of these systems to test our products.  More recently, we have found a way to bundle our Equalizer e350si load balancers with the ScienceLogic <a href="http://www.sciencelogic.com/techdiagram.htm" target="_blank">EM7 collector appliances</a> to help ScienceLogic get the best performance in load balancing large quantities of syslog messages to be processed.  If it wasn&#8217;t for our participation in InteropNet, neither of these relationships would&#8217;ve happened.</p>
<p><strong>ScienceLogic: </strong>What’s the best part of being involved with InteropNet?  What do you most look forward to?</p>
<p><strong>Katsev: </strong>InteropNet is an amazing networking opportunity (no pun intended).  The group of engineers that put the network together every year is, well, amazing.  There is so much combined experience that any question instantly has several possible answers, and the best answer is chosen very quickly.  One of the &#8217;sayings&#8217; at Interop is &#8220;if you run into a problem, ask someone&#8230; we&#8217;ve probably seen that problem before&#8230; five times.&#8221;  One would think that being part of InteropNet is the same thing, year after year.  However, in the two years that I&#8217;ve been part of this (for four shows), there have been huge differences in the way that the network is designed and put together.  These are both because the vendors selected every year are different, and because the engineers who design the network change from year to year.  Somehow, though, when all is said and done, we have a <a href="http://blog.sciencelogic.com/interop-las-vegas-2008-some-interesting-stats/06/2008" target="_blank">network that works</a>.</p>
<p><strong>ScienceLogic:</strong> You don’t have to answer this one if you’re not comfortable… What would you like to see changed with the way things are done at InteropNet?</p>
<p><strong>Katsev: </strong>This isn&#8217;t a cop-out&#8230; I really can&#8217;t think of anything I would do differently.  Sure, there are small problems that pop up sometimes, but every project has those, and the people at InteropNet are more than capable of figuring them all out.  In fact, I know that Interop started out as a show to test the interoperability of devices&#8230; but I&#8217;m still amazed that all of these devices actually talk to each other and <a href="http://blog.sciencelogic.com/qa-with-geoff-horne-of-interopnet/06/2008" target="_blank">&#8220;play nice&#8221; together</a>.</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Q%26%23038%3BA+with+Sergey+Katsev+of+Coyote+Point+Systems&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fqa-with-sergey-katsev-of-coyote-point-systems%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 12:34:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/katsev">katsev</category>
      <category domain="http://securityratty.com/tag/sergey katsev">sergey katsev</category>
      <category domain="http://securityratty.com/tag/interopnet">interopnet</category>
      <category domain="http://securityratty.com/tag/coyote">coyote</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/sciencelogic">sciencelogic</category>
      <category domain="http://securityratty.com/tag/sciencelogic em7 appliances">sciencelogic em7 appliances</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/client traffic">client traffic</category>
      <source url="http://blog.sciencelogic.com/qa-with-sergey-katsev-of-coyote-point-systems/08/2008">Q&amp;A with Sergey Katsev of Coyote Point Systems</source>
    </item>
    <item>
      <title><![CDATA[Ideal Tool to Solve Real Problems ... of the Near Future? - II]]></title>
      <link>http://securityratty.com/article/4d45e2880b790245f00c577a7d0b0226</link>
      <guid>http://securityratty.com/article/4d45e2880b790245f00c577a7d0b0226</guid>
      <description><![CDATA[I would like to continue the discussion I started in my previous post called &quot; Ideal Tool to Solve Real Problems ... of the Near Future? &quot; Specifically, upon outlining some problems with logging, I...]]></description>
      <content:encoded><![CDATA[<p>I would like to continue the discussion I started in my previous post called &quot;<a href="http://chuvakin.blogspot.com/2008/06/ideal-tool-to-solve-real-problems-of.html">Ideal Tool to Solve Real Problems ... of the Near Future?</a>&quot; Specifically, upon outlining some problems with logging, I will now forecast what will happen with them in 18-24 months. </p>  <ul>   <li>Which problems will be solved and forgotten? </li>    <li>Which ones will simply go away? </li>    <li>Which ones will persist and in fact increase? </li>    <li>Finally, which new ones might emerge? </li> </ul>  <p>First, let me bet my ass that &quot;<strong>Not knowing what to log</strong>&quot;<strong> </strong>problem <strong>will be licked in 18-24 months</strong>; at least as far as major regulations go, people will have a pretty good idea a) what&#160; the auditors want them to log (and review!) b) what they need to log for solving their problems. Now, for esoteric log sources (and custom applications) might still present a challenge from that point of view, but for basic &quot;staples&quot; (firewall, network gear, major OS) the mystery will be over (again, see &quot;<a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">Tell me EXACTLY what to log for PCI?</a>&quot;&#160; for reference)</p>  <p>Next, the problem of &quot;<strong>Log volume&quot; will&#160; definitely get worse, much worse</strong>.&#160; One might think that <em>100,000 each second</em> is a lot of log - but there WILL BE more at many companies! <em>Big application log explosion is coming</em>, fueled by the need to address logging in areas where such motivation was lacking before (basically, custom and vertical applications) as well as harness the power of &quot;uncommon&quot; logs for such tasks as fraud analysis or SOA monitoring. Keep in mind that even though in some areas logging is NOT a preferred way of monitoring and auditing activities (see <a href="http://chuvakin.blogspot.com/2007/12/how-to-do-database-loggingmonitoring.html">this discussion</a> on database logs <u><a href="http://chuvakin.blogspot.com/2007/12/how-to-do-database-loggingmonitoring.html">here</a></u>), application logging will still explode on us...</p>  <p>The problem of &quot;<strong>Log diversity&quot; </strong>(the fact that most logs all look different in format and meaning) <strong>will get worse before it will get better</strong> - and better it WILL (!!!) get since <a href="http://cee.mitre.org">standards are being developed</a>. We will see people struggling with all sorts bizarro log data in the coming years. Virtualization, web services and SOA, various ERP applications and even cloud services will increase the diversity of logging in the coming years.</p>  <p>Similar to the above, a problem of &quot;<strong>Bad logs&quot; </strong>(ones that are subjective, miss key information, require groping for a crystal ball to understand, turn log <em>analysis</em> into dark voodooistic experience or are <a href="http://www.loganalysis.org/pipermail/loganalysis/2008-January/000534.html">useless in some other way</a>) will also follow the pattern of the above log diversity problems - it <strong>will get worse before it gets better</strong> (via the <a href="http://cee.mitre.org">CEE standard effort</a> that now covers the <u><a href="http://openxdas.sourceforge.net/">OpenXDAS effort as well</a>!</u>) I noticed that people started asked me questions about &quot;how to do application logging right?&quot; and &quot;what to tell application developers about logging?&quot; which almost never happened in the past. BTW, watch <a href="http://www.securitywarrior.org">my blog</a> for some uber-fun info on that!</p>  <p><strong>&quot;Getting the logs&quot;</strong>&#160; has gotten much easier in recent years; agentless collectors like <u><a href="http://sourceforge.net/projects/lassolog">Project Lasso</a></u> (which, BTW, just <u><a href="http://www.loglogic.com/news/news-releases/2008/07/loglogic-launches-centralized-windows-event-log-collection-appliance-for-enterprise/">got updated</a></u>) and grabbing&#160; files remotely via secure protocols made application log collection easier (syslog-NG with TCP transfer and buffering also helped). Next, Windows 2008 will make it MUCH easier for the whole Windows kingdom due to their <a href="http://www.realtime-windowsserver.com/tips_tricks/2007/08/event_log_subscriptions_in_win.htm">use of web serv</a>ices (<u><a href="http://blogs.msdn.com/ericfitz/">thanks Eric!</a></u>). However, in the future it <strong>might resurface</strong> as we try to collect logs from &quot;weird&quot; places, again, <u><a href="http://chuvakin.blogspot.com/2008/05/cloud-this-cloud-that.html">clouds come to mind</a></u> as well as <u><a href="https://www.sans.org/webcasts/show.php?webcastid=91979">virtual environments</a></u> (e.g. how do you get logs off a dormant VM?). What's the next frontier in this area? Log discovery - automatic finding and identifying log files on systems in order to analyze and retain them (Yo, <u><a href="http://chuvakin.blogspot.com/2008/06/thanks-for-wonderful-t-shirt.html">my t-shirt-making colleagues...</a> </u>:-))</p>  <p>All this, however, pales in comparison with my favorite &quot;uber-challenge&quot;, &quot;<strong>Making sense of logs in&#160; an automated fashion&quot;</strong> - this baby is definitely not going away in 2-3 years. Much more research is needed to make that &quot;<strong>log-&gt;conclusion&quot;</strong> jump automatically without head-scratching, invoking ancient deities and cursing under ones's breath. Only then we can attempt to reliable handle &quot;proactive logging&quot; (i.e. analyzing various failure or compromise precursors in logs and then predicting the future based on them), another Holy Grail of logging domain.</p>  <p>Anything new will emerge? Yes, I think awareness of the <strong>&quot;Logging Gap&quot; problem will grow</strong>. &quot;Logging gap&quot; happens when you combine &quot;a need to log&quot; with utter &quot;inability to do so.&quot;&#160; For example, this will happen when people will know that they HAVE TO log, say, for compliance, but will have no way of doing it due to application or platform limitations. This will become one of the challenges and special &quot;logging add-ons&quot; will appear to close the logging gap and create additional logs where activity audit is desperately needed, but native logging is not helping to achieve it.</p>  <p>Also, I think people will <strong>finally</strong> <strong>wake up to</strong> &quot;<strong>Log security</strong>&quot; challenges - i.e. producing for use as evidence, compliance attestations, etc. <u><a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Log security</a></u> is not getting the attention <u><a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">it deserves</a></u>, but I think this challenge will finally emerge in full force in the next 2-3 years. My next poll will address that :-)</p>  <p>Anything else I missed? Share away!</p>  <p><strong>Related posts:</strong></p>  <ul>   <li>     <h5><a href="http://chuvakin.blogspot.com/2008/06/ideal-tool-to-solve-real-problems-of.html">Ideal Tool to Solve Real Problems ... of the Near Future?</a></h5>   </li>    <li>     <h5><a href="http://chuvakin.blogspot.com/2007/11/ideal-log-management-tool.html">Ideal Log Management Tool?</a></h5>   </li> </ul>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=OiE77K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=OiE77K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mHZh5K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mHZh5K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=MlgSPK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=MlgSPK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/356001661" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 17:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log discovery">log discovery</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/log diversity">log diversity</category>
      <category domain="http://securityratty.com/tag/esoteric log sources">esoteric log sources</category>
      <category domain="http://securityratty.com/tag/log security">log security</category>
      <category domain="http://securityratty.com/tag/application log explosion">application log explosion</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/log analysis">log analysis</category>
      <category domain="http://securityratty.com/tag/log volume">log volume</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/356001661/ideal-tool-to-solve-real-problems-of.html">Ideal Tool to Solve Real Problems ... of the Near Future? - II</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-07-24 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/8bdbe08ff6a16b22d7fe500f4bba3eb9</link>
      <guid>http://securityratty.com/article/8bdbe08ff6a16b22d7fe500f4bba3eb9</guid>
      <description><![CDATA[Event Log Subscriptions in Windows Server 2008 (and Vista) - Realtime Windows Server
Redmond | Column: Syslog ... 20 Years Later
San Francisco network lockup justifies CIO fears A determined IT...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.realtime-windowsserver.com/tips_tricks/2007/08/event_log_subscriptions_in_win.htm">Event Log Subscriptions in Windows Server 2008 (and Vista)&nbsp;-&nbsp;Realtime Windows Server</a></li>
<li><a href="http://redmondmag.com/columns/article.asp?editorialsid=1868">Redmond | Column: Syslog ... 20 Years Later</a></li>
<li><a href="http://searchcio-midmarket.techtarget.com/news/article/0,289142,sid183_gci1322169,00.html">San Francisco network lockup justifies CIO fears</a><br/>
A determined IT staffer has countless opportunities to sabotage a business&#039;s operations. Eliminating that risk is impossible, experts say, and minimizing it requires a series of security efforts that go beyond the IT department and extend across the busin</li>
<li><a href="http://www.windowsecurity.com/articles/Understanding_Windows_Logging.html">Understanding Windows Logging</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/345323412" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows server">windows server</category>
      <category domain="http://securityratty.com/tag/realtime windows server">realtime windows server</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/event log subscriptions">event log subscriptions</category>
      <category domain="http://securityratty.com/tag/security efforts">security efforts</category>
      <category domain="http://securityratty.com/tag/countless opportunities">countless opportunities</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/vista">vista</category>
      <category domain="http://securityratty.com/tag/busin">busin</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/345323412/anton18">Links for 2008-07-24 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Logging, Correlation and IT Search: An Analogy]]></title>
      <link>http://securityratty.com/article/afb1c89e44633641f1e7b1761b065c21</link>
      <guid>http://securityratty.com/article/afb1c89e44633641f1e7b1761b065c21</guid>
      <description><![CDATA[We were having some in-house training the other day and trying to demonstrate and explain the value of IT logging, event correlation and IT search functions to non-technical folk. Unfortunately, I...]]></description>
      <content:encoded><![CDATA[<p>We were having some in-house training the other day and trying to demonstrate and explain the value of IT logging, event correlation and IT search functions to non-technical folk. Unfortunately, I think the data being used was unfamiliar and made it difficult to get the point across of what we can do with these tools and why we like them. Everyone was caught up in the whole &#8220;<em>what does that src mean</em>&#8221; and &#8220;<em>what IP address is that</em>&#8221; etc. </p><p>Sometimes I&#8217;m the queen of analogies (likely a trait I inherited from my Dad). Quite often&nbsp;my analogies are&nbsp;pretty silly, but they almost always get the point across. </p><p>So I was trying to work out an analogy to explain how we can use logs, events and searching and why these are advantageous. I was in the shower and it hit me!&nbsp;And&#8230; here it is.&nbsp; <em><strong>FYI</strong>- If you&#8217;re a techie, just stop reading now&#8230; (I warned you). </em></p><p><strong>The analogy.</strong> Imagine a house&#8230; actually, imagine <em>your</em> house. Let&#8217;s say that your house is like a network.&nbsp;The&nbsp;house and all the&nbsp;major appliance and structures&nbsp;of the house&nbsp;are like infrastructure devices- switches and servers, for example. Of course, the people living&nbsp;in your house&nbsp;are users. In addition&nbsp;you have &#8216;gateways&#8217; from your house to the outside world, in the form of&nbsp;doors, windows, vents, etc.&nbsp;These house gateways are like our&nbsp;WAN devices- firewalls, IDS/IPS and other gateway appliances. </p><p>Let&#8217;s say you live in the house with your spouse and family. You&#8217;re going to be the wife for now, so imagine you, your husband, three kids and a dog&nbsp;(only because that amuses me). Each of your house users have a key to get in.</p><p><span class="full-image-float-right"><img style="width: 300px; height: 232px" alt="graphic_toastersyslog_lg.gif" src="http://www.securityuncorked.com/storage/graphic_toastersyslog_lg.gif" /></span>Your major appliances- the TVs, refrigerator, oven, the family computers and alarm system&nbsp;are all creating logs when anything happens and they&#8217;re all giving their logs to the toaster. (<em>The toaster is greatly under appreciated so I&#8217;m giving him a big role here- yes- <strong>your toaster is the Syslog server</strong></em>). The doors, windows and other &#8216;portals&#8217; to the outside are also creating events and logging each time they&#8217;re opened, closed, locked or broken and, they too, are sending their info to the toaster. </p><p><strong>Here&#8217;s where life in your house gets interesting</strong>. Let&#8217;s figure out what&#8217;s normal&#8230; it&#8217;s probably normal for your husband to come home,&nbsp;do some work on the computer while you cook, and then everyone watch TV. The kids are doing their homework, playing on the computer and probably rummaging around the fridge for an after-school snack. You see your syslogging toaster shows you&#8230; &nbsp;</p><ul><li><div>the src= <u>Refrigerator</u> was opened multiple times in a short period of time between 3:43pm and 4:16pm by multiple users</div></li><li><div>the src= <u>Kids Computer</u> was logged off the Internet at 4:30 by user: Kid2</div></li><li><div>the src= <u>Front Door</u> was opened at 5:20pm by user: Husband</div></li><li><div>the src= <u>Oven</u> was turned on Bake at 350 at 5:32pm by user: You </div></li><li><div>the src= <u>LivingRoom TV</u> was turned on at 5:56pm by user: Husband</div></li><li><div>the src= <u>LivingRoom TV</u> channel was modified multiple times in a short period of time between 5:56pm and 6:02pm (your husband was probably looking for the ball game)</div></li></ul><p><strong>These are all things you expect to see. So, what&#8217;s not normal?</strong> Some things your toaster may tell you that would be out of the ordinary&#8230; </p><ul><li><div>the src= <u>Refrigerator</u> was opened at 02:40am by user: Kid1 <br /><em>What does this mean? Someone&#8217;s late-night snacking, no big deal</em>.</div></li><li><div>the src= <u>Kids Computer</u> was logged onto the Internet at 02:45am by user: Kid1<br /><em>Uh-oh, Kid1 is gallivanting on the Internet&nbsp;in the&nbsp;middle of the night&nbsp;un-chaperoned. Might need to check that out</em>. </div></li><li><div>the src= <u>Front Door</u> was attempted to be opened unsuccessfully 14 times in a short period of time beginning at 10:15am by user: UNKNOWN. The toaster logged the key code attempts tried by user UNKNOWN.<br /><em>Kids were at school, you were at work- someone&#8217;s trying to break in.</em> </div></li><li><div>the src= <u>Front Door</u> was opened the next day at 1:20pm by user: ROOT<br /><em>You were still not home- someone just broke into your house. </em></div></li></ul><p><strong>Maybe we want to be alerted when these things are happening</strong>, or have happened. With some log search and correlation tools, in conjunction with your toaster syslog, we can get immediate alerts when something unexpected is happening. We could tell the log search to keep talking to the toaster and immediately send us a text message if the toaster sees the front door or any windows&nbsp;being accessed between 09:00am and 3:00pm on any weekday, by any user. If the toaster saw something happening, we would know immediately and could take appropriate actions- maybe call the police to notify them of a break-in. </p><p><strong>Now, back to the network.</strong> Now that you have an idea of how we can use logs and events in the house to identify what&#8217;s going on and spot abnormal activity, we can port that over to our network. Go back and again think of the house and its appliances as resources on the network. We can see when someone- inside or outside- is trying to or has successfully accessed something and we can alert, take action, or keep logs and reports for future use and accounting.</p><p><strong>Replaying events.</strong> If you&#8217;re using a super-nifty tool, you may be able to replay specific events back in a visual format- almost like a video into the network. Let&#8217;s take our Kid1&#8217;s midnight snacking. If we replayed all the events that contained user= Kid1 from time 10:00pm (bedtime) to 07:00am (gettin&#8217; up time) we could see Kid1 go from the bedroom down to the kitchen, opening the fridge, watching TV for a bit before going back to the room and surfing the Internet for an hour. We could actually &#8216;watch&#8217; these events happening with a re-constructed timeline. A great example (and my favourite toy) to do this is <a class="offsite-link-inline" href="http://www.splunkbase.com/apps/All/Technologies/app:Splunk+Replay" target="_blank">Splunk&#8217;s Replay application</a>. </p><p>That&#8217;s the basic gist of it all. There are some other detailed &#8216;things&#8217; we can do with these technologies, and I may elaborate on those another time. We all have A.D.D. and this one is long enough already!</p><p># # # </p>
]]></content:encoded>
      <pubDate>Fri, 06 Jun 2008 13:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kids">kids</category>
      <category domain="http://securityratty.com/tag/src kids computer">src kids computer</category>
      <category domain="http://securityratty.com/tag/src">src</category>
      <category domain="http://securityratty.com/tag/src livingroom tv">src livingroom tv</category>
      <category domain="http://securityratty.com/tag/house">house</category>
      <category domain="http://securityratty.com/tag/in-house">in-house</category>
      <category domain="http://securityratty.com/tag/house gateways">house gateways</category>
      <category domain="http://securityratty.com/tag/src front door">src front door</category>
      <category domain="http://securityratty.com/tag/kid1">kid1</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/6/6/logging-correlation-and-it-search-an-analogy.html">Logging, Correlation and IT Search: An Analogy</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Security - 2]]></title>
      <link>http://securityratty.com/article/44c91f772953aa48d30abd91879f33cd</link>
      <guid>http://securityratty.com/article/44c91f772953aa48d30abd91879f33cd</guid>
      <description><![CDATA[Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot; Fun Reading on Security .&quot; Here is an issue #2, dated May 8, 2008
So my next...]]></description>
      <content:encoded><![CDATA[<p>Instead of my usual "blogging frenzy" machine gun blast of short posts, I will just combine them into my new blog series "<a href="http://chuvakin.blogspot.com/search/label/reading">Fun Reading on Security</a>." Here is an issue #2, dated May 8, 2008.</p> <p>So my next iteration of fun reading on security, logging and other topics.</p> <ol> <li><a href="http://www.0x000000.com">0x000000 blog</a> has <a href="http://www.0x000000.com/?i=545">a neat post on security</a>, word definition and all. It reminds us that "security is forever" since it is about people, not broken technologies. A quote: "And so we will never able to secure other people, they have to secure them self. And we know that they can't." Same blog also have a fun (but a little bizarre with a little 80s feel) <a href="http://www.0x000000.com/?i=551">interview with Richard Stallman</a>.</li> <li>Along the same line, discussion about security industry longevity is <a href="http://1raindrop.typepad.com/1_raindrop/2008/04/message-to-secu.html">here</a> at <a href="http://1raindrop.typepad.com/1_raindrop/">Gunnar Peterson's blog</a>: specifically, he debates <a href="http://securityincite.com/TDI-2008-04-28#TSN1">Mike R's semi-humorous prediction</a> that in 2012 there will be 0 "security professionals." Indeed, secure networks + secure OS + secure apps &lt; security.</li> <li>Also a very fun read comes from DarkReading: <a href="http://www.infoworld.com/article/08/05/01/7-dirty-secrets-of-the-security-industry_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/05/01/7-dirty-secrets-of-the-security-industry_1.html">"7 dirty secrets of the security industry.</a>" Example quotes: "The goal of the security vendor is not to secure, it's to make money" , "Security vendors want businesses to buy what they sell, so they push specific products to block specific threats "; it also discusses another facet of compliance vs security.</li> <li>Fun - and as usual heated - debates about the "AV is dead" and "anti-anti-virus revolt" happen <a href="http://anti-virus-rants.blogspot.com/2008/05/anti-av-revolt.html">here</a>. Is blacklisting&nbsp; AV dead now? More dead than before? :-) Or just "limited",&nbsp; but still very useful? BTW, Matasano <a href="http://www.matasano.com/log/1049/contest-protest/">opines on the subject here</a> as well, calling it not a revolution, but a protest.</li> <li>The next&nbsp; <a href="http://securityviews.com/blog/2008/04/22/carnival-of-the-security-catalyst-community-april-22-2008/">Carnival of the Security Catalyst Community - April 22, 2008</a>; as always fun. Next carnival Apr 29 is <a href="http://securethink.blogspot.com/2008/04/security-catalyst-forums.html">here</a> and the last (so far) one is <a href="http://infosecramblings.wordpress.com/2008/05/06/security-catalyst-community-roundup-may-6th-2008/">here</a>.</li> <li>Really good look at logging for developers is <a href="http://www.codesecurely.org/wiki/view.aspx/security_code_reviews/logging__auditing">here</a>. "all too often logging gets treated as optional and not necessary. In this column we will cover the essentials of logging []for developers!] from a security perspective"</li> <li>Latest stolen account prices are posted <a href="http://www.avertlabs.com/research/blog/index.php/2008/05/07/you-have-to-pay-for-quality/">here</a> by AVERT Labs guys. Account with $16,000 goes for about 700 euros (!) Also, Finjan <a href="http://www.finjan.com/Pressrelease.aspx?id=1944&amp;PressLan=1819&amp;lan=3">reminds us</a> that top corporations are all owned.</li> <li>ISP data retention rears <a href="http://www.news.com/8301-13578_3-9926803-38.html">its (ugly?) head again</a>. Good business for <a href="http://www.loglogic.com">LogLogic</a> or privacy nightmare?</li> <li>A fun read from <a href="http://blog.tizor.com">Tizor Blog</a>: "<a href="http://blog.tizor.com/data_auditing_blog/tabid/8146/bid/4793/How-did-the-TJX-data-breach-happen-Part-1-Anatomy.aspx">How did the TJX data breach happen? Part 1: Anatomy</a>" A must read, with diagrams, etc. "After breaching the TJX wireless system, the attacker was able to gain administrative privileges to the RTS servers located at the TJX corporate headquarters in Framingham, MA."</li> <li>A very good read from Greg Shipley: "<a href="http://www.informationweek.com/shared/printableArticle.jhtml?articleID=207000078">Risk Management: Do It Now, Do It Right</a>." A lot of interesting bits about CSOs, security technologies evolution, etc. "The journey continues. We invested hundreds of millions of dollars in intrusion-detection systems without a solid understanding of their relative effectiveness and total cost of ownership. The IDS craze led to reinvestments in intrusion-prevention systems that even today are only partially enabled, and PKI is still a bad word in many IT circles. There's no shortage of disappointments on other product fronts."</li> <li>"<a href="http://securosis.com/2008/04/23/data-classification-is-dead/">Data Classification Is Dead</a>?"&nbsp; <a href="http://securosis.com">Rich Mogul</a> explains why data classification by the owners is never going to fly... "Enterprise content is just too volatile for static tags to really represent its value. Even those of you in defense/intelligence don’t *really* do granular data classification. " This is a good reminder to shoe that just spout the propaganda "first, need to classify data." Can you hope to do "DLP" without it? Also, <a href="http://securosis.com/2008/05/05/information-centric-security-tip-know-your-users-and-infrastructure/">read this one</a> from Rich as well: not only you can't classify, you often don't know who owns what.</li> <li>Hot, hot, hot! "<a href="http://www.darkreading.com/blog.asp?blog_sectionid=403">Snake Bytes</a> " on DarkReading. "We are all in the business of stopping just enough crime to keep us in business." Wow! Definitely <a href="http://www.darkreading.com/blog.asp?blog_sectionid=403">a must read.</a></li> <li><a href="http://www.loganalysis.org/pipermail/loganalysis/2008-May/000679.html">Marcus Ranum on logging in Start Trek</a> (<a href="http://www.loganalysis.org/pipermail/loganalysis/2008-May/thread.html#679">read the whole thread</a>): "What do you expect from a starship that runs on Windows-24k? Microsoft added support for syslog in 2348 - citing customer demand - but still<br>has no Enterprise-class log architecture." :-)</li> <li><a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1310853,00.html">Piece on PCI and log management</a> where a vendor makes an idiotic <em>faux pas</em> by saying that "less than 1% logs are of interest." In reality, all (OK, most) logs are of interest <em>under the right circumstances. </em>And we almost never know which ones we'd need.</li> <li><a href="http://www.scmagazineus.com/The-legal-implications-of-the-PCI-data-security-standard/article/109235/?DCMP=EMC-SCUS_Newswire">A fun blurb</a> from a lawyer on PCI. Good conclusion too: "Regardless, now is the time for merchants to begin engaging their legal teams to address PCI compliance, and opening the lines of communication between the lawyers and security pros." He also fights the <a href="http://chuvakin.blogspot.com/2007/09/war-on-security.html">checkbox mentality</a> by saying that&nbsp; "merchants should not view their internal security personnel or QSAs as “rubber stamps” of PCI compliance." I am happy to see this lawyer basically say that if you ignore PCI, your ass is&nbsp; 0wned :-)</li></ol> <p>On that happy note - see you next time! :-)</p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:878258d6-31bf-4155-9add-cda8cb70ef73" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/reading" rel="tag">reading</a>, <a href="http://technorati.com/tags/trends" rel="tag">trends</a>, <a href="http://technorati.com/tags/market" rel="tag">market</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Mz1bqH"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Mz1bqH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=XX3MXH"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=XX3MXH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=M424QH"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=M424QH" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/287071172" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 09 May 2008 08:20:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security industry longevity">security industry longevity</category>
      <category domain="http://securityratty.com/tag/security industry">security industry</category>
      <category domain="http://securityratty.com/tag/technologies">technologies</category>
      <category domain="http://securityratty.com/tag/security technologies evolution">security technologies evolution</category>
      <category domain="http://securityratty.com/tag/security vendors">security vendors</category>
      <category domain="http://securityratty.com/tag/security perspective">security perspective</category>
      <category domain="http://securityratty.com/tag/security catalyst community">security catalyst community</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/287071172/fun-reading-on-security-2.html">Fun Reading on Security - 2</source>
    </item>
    <item>
      <title><![CDATA[Log Haiku #4]]></title>
      <link>http://securityratty.com/article/5da34e01cab63685df5977e15bc75565</link>
      <guid>http://securityratty.com/article/5da34e01cab63685df5977e15bc75565</guid>
      <description><![CDATA[Think syslog is a standard
A standard of what
What were they smoking
About me:...]]></description>
      <content:encoded><![CDATA[<span style="font-style: italic;">Think syslog is a standard?</span><br /><span style="font-style: italic;">A standard of what?</span><br /><span style="font-style: italic;">What were they smoking?</span><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=RcQKQJG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=RcQKQJG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=rzdFIjG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=rzdFIjG" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/277870635" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 25 Apr 2008 10:12:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/standard">standard</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/syslog">syslog</category>
      <category domain="http://securityratty.com/tag/chuvakin">chuvakin</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/277870635/log-haiku-4.html">Log Haiku #4</source>
    </item>
  </channel>
</rss>
