<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: systems]]></title>
    <link>http://securityratty.com/tag/systems</link>
    <description></description>
    <pubDate>Wed, 03 Sep 2008 06:21:16 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Supporting CEP with Solace Content Routers]]></title>
      <link>http://securityratty.com/article/8d902f5832f1d3b5efbfc1f409e130b5</link>
      <guid>http://securityratty.com/article/8d902f5832f1d3b5efbfc1f409e130b5</guid>
      <description><![CDATA[Interested in content routing and event preprocessingsupporting futureCEP applications? Check out Solace Systems . You can click on the image below for a better picture of the Solace architecture for...]]></description>
      <content:encoded><![CDATA[<p>Interested in content routing and event preprocessing supporting future CEP applications?  Check out <a href="http://wwww.solacesystems.com" target="_blank">Solace Systems</a>.  You can click on the image below for a better picture of the Solace architecture for event processing.</p>
<p style="text-align: center;"><a href="http://www.solacesystems.com/images/solutions/cep_architecture.gif" target="_blank"><img class="aligncenter" src="http://www.solacesystems.com/images/solutions/cep_architecture.gif" alt="" width="450" height="283" /></a></p>
<p>Solace provides <a href="http://www.solacesystems.com/solutions/fs_event_processing.asp" target="_blank">sophisticated middleware functionality</a> in hardware to monitor, filter, route, transform and secure very large volumes of events in real time and with minimal processing overhead.  Solace uses leading-edge FPGA, ASIC and network processor technology to increase throughput and lower latency of event processing. Applications such as fraud detection, algorithmic trading, compliance, insider trade monitoring, risk management and more can be tackled more effectively by separating the simple monitoring, filtering and normalization of raw events from the complex processing of select events. This event pre-processing takes the burden off CEP engines allowing individual engines to be much more effective. </p>
]]></content:encoded>
      <pubDate>Sat, 06 Sep 2008 07:42:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solace">solace</category>
      <category domain="http://securityratty.com/tag/solace systems">solace systems</category>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/raw events">raw events</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/solace architecture">solace architecture</category>
      <category domain="http://securityratty.com/tag/network processor technology">network processor technology</category>
      <category domain="http://securityratty.com/tag/select events">select events</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <source url="http://www.thecepblog.com/2008/09/06/supporting-cep-with-solace-3230-and-solace-3260-content-routers/">Supporting CEP with Solace Content Routers</source>
    </item>
    <item>
      <title><![CDATA[Cisco 7600 OSR Backbone Router]]></title>
      <link>http://securityratty.com/article/a447dc34e61d2770ab6d723a54abcb31</link>
      <guid>http://securityratty.com/article/a447dc34e61d2770ab6d723a54abcb31</guid>
      <description><![CDATA[For our confused CEO blogger over at StreamBase, who thinks an Internetbackbone router is the small $30 device he set up in his home office, here is a photo of a the Cisco 7600 OSR which of course...]]></description>
      <content:encoded><![CDATA[<p style="text-align: left;">For our confused CEO blogger over at StreamBase, who thinks an Internet backbone router is the small $30 device he set up in his home office, here is a photo of a the <a href="http://newsroom.cisco.com/dlls/prod_022001b.html" target="_blank">Cisco 7600 OSR</a> which of course runs <a href="http://www.cisco.com/en/US/products/sw/iosswrel/products_ios_cisco_ios_software_category_home.html" target="_blank">CISCO IOS</a>.</p>
<p style="text-align: center;"><img style="vertical-align: middle;" src="http://newsroom.cisco.com/ts_images/Cisco-7600-OSR-high.jpg" alt="Cisco 7600 OSR" height="600" /></p>
<p style="text-align: left;">The Cisco 7600 OSR consists of a 256 Gbps switching fabric and a 30 million packets per second (mpps) forwarding engine. Its breadth of IP services comes from Cisco IOS, which provides features such as security, enhanced QoS, and destination sensitive services. In addition, the Cisco 7600 OSR allows the migration of existing port adapters from Cisco 7500 series routers, via the Cisco FlexWAN module, giving service providers one the industry&#8217;s widest array of interface options in any single platform. This provides service providers great flexibility in deploying the Cisco 7600 OSR for a variety of applications, protects their investment in existing systems, and gives them a practical migration path to the New World Optical Internet.</p>
<h3>A Revolutionary Platform For Evolving Networks</h3>
<p>The Cisco 7600 OSR helps service providers break through service and bandwidth barriers today, while designing networks to scale for future growth. The Cisco 7600 OSR achieves this through &#8220;adaptive network processing,&#8221; or the ability to evolve the platform for new IP services without hardware upgrades. Unlike fixed, ASIC-based platforms, which are hardware encoded, the Cisco 7600 OSR relies on the highly flexible Parallel eXpress Forwarding (PXF) technology for scalable performance of services. PXF is a patented, Cisco-developed network processor capable of line-rate IP services delivery that can support new IP services through periodic software upgrades. Each OSM has two PXF processors capable of 12 mpps of IP services delivery per interface card.</p>
<p>&#8220;IP+Optical combines the dynamism of the Internet world with the foundation of the transport world, creating an infrastructure that can deliver the services that service providers need,&#8221; said Lele Nardin, vice president of the Internet Systems Business Unit at Cisco. &#8220;Cisco will continue to add innovative solutions on top of this solid foundation to make service providers better equipped to meet the constantly escalating and changing customer demands for new networking services.&#8221;</p>
<h3>Pricing and Availability</h3>
<p>The base Cisco 7600 OSR system is list priced at $73,000 and the entry level system, with interfaces, start at $100,000. The interfaces modules are priced between $27,000 to $180,000. The Cisco 7600 OSR is available now worldwide.</p>
]]></content:encoded>
      <pubDate>Sat, 06 Sep 2008 07:25:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <category domain="http://securityratty.com/tag/cisco flexwan module">cisco flexwan module</category>
      <category domain="http://securityratty.com/tag/osr">osr</category>
      <category domain="http://securityratty.com/tag/runs cisco ios">runs cisco ios</category>
      <category domain="http://securityratty.com/tag/base cisco">base cisco</category>
      <category domain="http://securityratty.com/tag/cisco ios">cisco ios</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/destination sensitive services">destination sensitive services</category>
      <category domain="http://securityratty.com/tag/osr system">osr system</category>
      <source url="http://www.thecepblog.com/2008/09/06/cisco-7600-osr-backbone-router/">Cisco 7600 OSR Backbone Router</source>
    </item>
    <item>
      <title><![CDATA[Links List 9.5.08]]></title>
      <link>http://securityratty.com/article/a76e7e02c1b33be171e4bf894b4cceda</link>
      <guid>http://securityratty.com/article/a76e7e02c1b33be171e4bf894b4cceda</guid>
      <description><![CDATA[Sanjay Kumar is singing like a canary from federal prison. Just when you thought it was over, the CA accounting scandal is back and even more juicy. Ex-CEO Kumar is about a year into his 12-year...]]></description>
      <content:encoded><![CDATA[<p>Sanjay Kumar is <a href="http://online.wsj.com/article/SB122049724868198047.html?mod=djemTECH" target="_blank">singing like a canary</a> from federal prison. Just when you thought it was over, the CA accounting scandal is back and even more juicy. Ex-CEO Kumar is about a year into his <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2006/11/sanjay_kumar_ge.html" target="_blank">12-year prison term</a> but still busy pointing the finger at everyone else who he says knew about the company’s fraudulent accounting practices that lead to $2.2 billion in misstated revenue. From a former Salomon Brothers vice chairman to a former US senator to company founder <a href="http://blogs.computerworld.com/sanjay_kumar_hero_or_villain" target="_blank">Charles Wang</a>, it looks like open season on CA board directors.
<p>Ten days before <a href="http://www.vmworld.com/conferences/2008" target="_blank">VMworld</a> and VMware still can’t get good press. First their CEO, Diane Greene, gets ousted, then a high-profile <a href="http://toutvirtual.com/blogs/2008/09/02/vmware-really-hurting-or-just-really-bad-timing-for-a-simple-mistake/" target="_blank">licensing bug</a> is found and now the Director of R&amp;D, <a href="http://blogs.eweek.com/first_read/content/virtualization/vmware_rd_chief_resignation_is_bad_timing.html" target="_blank">Richard Sarwal</a>, leaves his $1.25 million salary after just 7 months. (Note to self: get into R&amp;D) It will be interesting to take the pulse of the VMware community at the show and in person. And in the meantime, Microsoft Hyper-V comes out of the gate with customers already <a href="http://www.nwwsubscribe.com/news/2008/082608-how-hyper-v-helped-my-it.html" target="_blank">touting its benefits</a>.
<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/09/borg-jean-luc.jpg"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="243" alt="borg_jean-luc" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/borg-jean-luc-thumb.jpg" width="244" border="0"></a> </p>
<p>The hypervisor is the “new” operating system. If you didn’t think that before, take a look at Red Hat’s purchase of Qumranet for $107 million. With Qumranet, Red Hat gets KVM, described by <a href="http://www.infoworld.com/article/08/09/04/Red_Hat_buys_Qumranet_to_extend_virtualization_reach_1.html?source=NLC-DAILY&amp;cgd=2008-09-04" target="_blank">CTO Brian Stevens</a> as an extension to the Linux kernel that allows it to be used as a bare-metal hypervisor, running directly on the underlying hardware and hosting guest operating systems. But according to <a href="http://www.brianmadden.com/blog/BrianMadden/Red-Hat-buys-Qumranet-for-107M-What-does-this-mean-for-KVM-and-SolidICE" target="_blank">Brian Madden,</a> the “press” around the purchase is all focusing on the not-so-interesting part. Along with KVM, the SolidICE product includes Spice, a remote display protocol for VDI. </p>
<blockquote><p>I wonder if this will be like Symantec buying Altiris or Microsoft buying Softricity, where the portion that we care about sort of loses focus as The Borg concentrates on the parts of the acquired technology that are more relevant to them?</p>
</blockquote>
<p>(I’m a sucker for quotes that reference The Borg)
<p>Network World publishes “<a href="http://www.networkworld.com/news/2008/090208-open-to-watch.html?page=1">10 open source companies to watch</a>”. On the list, Qumranet!
<p>Also on the list: Kickfire, Marketcetera, Vyatta, Sonatype, Untangle, XAware, SnapLogic, Acquia and Openmoko. What’s best about the list: <a href="http://news.cnet.com/8301-13505_3-10030356-16.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" target="_blank">Matt Asay</a> gives it a thumbs up. </p>
]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 14:52:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/brian">brian</category>
      <category domain="http://securityratty.com/tag/cto brian stevens">cto brian stevens</category>
      <category domain="http://securityratty.com/tag/purchase">purchase</category>
      <category domain="http://securityratty.com/tag/red hats purchase">red hats purchase</category>
      <category domain="http://securityratty.com/tag/hypervisor">hypervisor</category>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/million salary">million salary</category>
      <category domain="http://securityratty.com/tag/bare-metal hypervisor">bare-metal hypervisor</category>
      <source url="http://blog.sciencelogic.com/links-list-9508/09/2008">Links List 9.5.08</source>
    </item>
    <item>
      <title><![CDATA[Your Companies Biggest Security Hole - What is the BGP-style Vuln Lurking in Software Security?]]></title>
      <link>http://securityratty.com/article/95b08326dc660fff6cb1103621e8f2f3</link>
      <guid>http://securityratty.com/article/95b08326dc660fff6cb1103621e8f2f3</guid>
      <description><![CDATA[My vote is MQ Series and other enterprise messaging systems. Schneier's succinct summary of BGP

It's a man-in-the-middle attack. &quot;The Internet's Biggest Security Hole&quot; has been that interior relays...]]></description>
      <content:encoded><![CDATA[<p>My vote is MQ Series and other enterprise messaging systems. Schneier&#39;s succinct <a href="http://www.schneier.com/blog/archives/2008/08/border_gateway.html">summary</a> of BGP:</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">It&#39;s a man-in-the-middle attack. &quot;The Internet&#39;s Biggest Security Hole&quot; &#160;has been that interior relays have always been trusted even though they are not trustworthy.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br />That could apply word for word to how MQ Series and other enterprise messaging systems are deployed. Let&#39;s say you are a bank and have been happily running your business on a mainframe for decades. Life is good, come in at 9 leave at 5, count the cash. Then some dotcommer comes along and tells you that you need to get online. What are you gonna do? Rewrite your whole system from scratch? Hard to make that case.</span></p><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Nope what you&#39;ll do is build out a web farm to talk to the consumer, but then you will realize all of your business runs on the mainframe, and you need to connect to it. How exactly? Enter MQ Series and friends, they broker the communications to legacy backends for most major corporations, but there is one slight problem - they didn&#39;t even bother to support useful security protocols until very recently, and most of the time the security protocols are not even implemented.</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Typical anti-patterns include:</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* no authentication, no authorization (just open up a queue) - run your whole book of business transaction backbone on anonymous ftp</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* authorization with no authentication (mq enforces authorization policy on unverifiable tokens) -&#160;run your whole book of business transaction backbone on anonymous ftp, but think that you have security</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">What is strange about the MQ Series, enterprise messaging vulns is that there is no need for them, there are no technical excuses to not add better tokens, message security, and encryption. People don&#39;t do it, because of poor tool support,</span><span style="font-family: Verdana; font-size: 12px; line-height: normal;">&#160;a </span><a href="http://1raindrop.typepad.com/1_raindrop/2008/08/mainframe-mindset.html">mainframe mindset</a><span style="font-family: Verdana; font-size: 12px; line-height: normal;">, silo projects, and a whole variety of reasons. But just because you choose to ignore a fact doesn&#39;t mean its not true. On the plus side, some of the open source ESBs are </span><a href="http://1raindrop.typepad.com/1_raindrop/2008/04/cxf-axis2-and-e.html">adding support for message security</a><span style="font-family: Verdana; font-size: 12px; line-height: normal;">, so you can improve security and save your company money at the same time, what&#39;s not to like?</span></div>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 04:31:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security hole">security hole</category>
      <category domain="http://securityratty.com/tag/security protocols">security protocols</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/business runs">business runs</category>
      <category domain="http://securityratty.com/tag/business transaction backbone">business transaction backbone</category>
      <category domain="http://securityratty.com/tag/improve security">improve security</category>
      <category domain="http://securityratty.com/tag/message security">message security</category>
      <category domain="http://securityratty.com/tag/enforces authorization policy">enforces authorization policy</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/your-companies-biggest-security-hole---what-is-the-bgp-style-vuln-lurking-in-software-security.html">Your Companies Biggest Security Hole - What is the BGP-style Vuln Lurking in Software Security?</source>
    </item>
    <item>
      <title><![CDATA[Browser war redux, patch time, iPod news]]></title>
      <link>http://securityratty.com/article/0509140ca72ca130993f22228ecaf70a</link>
      <guid>http://securityratty.com/article/0509140ca72ca130993f22228ecaf70a</guid>
      <description><![CDATA[Google garnered headlines all week with its new Chrome browser. Rival Microsoft announced it will release just four patches next Tuesday, but that may not be cause to think the day will be an easy one...]]></description>
      <content:encoded><![CDATA[Google garnered headlines all week with its new Chrome browser. Rival Microsoft announced it will release just four patches next Tuesday, but that may not be cause to think the day will be an easy one for those responsible for keeping systems patched. Also looking ahead, Apple is expected to announce iPod news. Otherwise, a warning was issued about new trickery from spammers and in case we all weren't aware of it by now, social-networking sites could be ripe for malware.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=74333?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=74333?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/announce ipod news">announce ipod news</category>
      <category domain="http://securityratty.com/tag/rival microsoft">rival microsoft</category>
      <category domain="http://securityratty.com/tag/chrome browser">chrome browser</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/ripe">ripe</category>
      <category domain="http://securityratty.com/tag/headlines">headlines</category>
      <category domain="http://securityratty.com/tag/spammers">spammers</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/trickery">trickery</category>
      <source url="http://www.networkworld.com/news/2008/090508-browser-war-redux-patch-time.html?fsrc=rss-security">Browser war redux, patch time, iPod news</source>
    </item>
    <item>
      <title><![CDATA[Blue Box SE#026 - Astricon 2007 presentation on VoIP security and Asterisk]]></title>
      <link>http://securityratty.com/article/ceff3c168541790ec71113285297b6e6</link>
      <guid>http://securityratty.com/article/ceff3c168541790ec71113285297b6e6</guid>
      <description><![CDATA[Synopsis: Blue Box Special Edition #26: Astricon 2007 presentation - &quot;Hacking and Attacking VoIP Systems: What you need to worry about
Welcome to Blue Box: The VoIP Security Podcast Special Edition...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box Special Edition #26: Astricon 2007 presentation - &quot;Hacking and Attacking VoIP Systems: What you need to worry about&quot;</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> Special Edition #26, a 55-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3" rel="enclosure">Download the show here</a> (MP3, 6MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3&amp;bgcolor=#FFFFFF" /></object> </p> 

<p><strong>Show Content:</strong></p> 
<p>A year ago in September 2007, I (Dan York) spoke at Astricon 2007 in Arizona, USA, about &quot;Hacking and Attacking VoIP Systems: What You Need To Worry About&quot; My presentation covered a lot of the typical VoIP security threats, tools and best practices but also expanded a bit into specific security issues with Asterisk.&nbsp; Please do keep in mind that it has been a year since this presentation and so some of the issues I mention have been addressed. (<a href="http://www.astricon.net/">Astricon</a>, for those who don't know, is an annual developer conference for those who work with the <a href="http://www.asterisk.org/">Asterisk open source telephony platform</a>. Astricon 2008 is, in fact, coming up in about 3 weeks but I will not be attending this year.)
</p>

<p>The slides for this talk <a href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know/">are available from Slideshare</a>:
</p>



<div id="__ss_178451" style="width: 425px; text-align: left;"><a title="Hacking and Attacking VoIP Systems - What You Need To Know" href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know?src=embed" style="margin: 12px 0pt 3px; font-family: Helvetica,Arial,Sans-serif; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none; display: block; text-decoration: underline;">Hacking and Attacking VoIP Systems - What You Need To Know</a><object width="425" height="355" style="margin: 0px;"><param value="http://static.slideshare.net/swf/ssplayer2.swf?doc=hacking-and-attacking-voip-systems-what-you-need-to-know-119595215763603-5&amp;stripped_title=hacking-and-attacking-voip-systems-what-you-need-to-know" name="movie" /><param value="true" name="allowFullScreen" /><param value="always" name="allowScriptAccess" /><embed width="425" height="355" allowfullscreen="true" allowscriptaccess="always" type="application/x-shockwave-flash" src="http://static.slideshare.net/swf/ssplayer2.swf?doc=hacking-and-attacking-voip-systems-what-you-need-to-know-119595215763603-5&amp;stripped_title=hacking-and-attacking-voip-systems-what-you-need-to-know"></embed></object><div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View SlideShare <a title="View Hacking and Attacking VoIP Systems - What You Need To Know on SlideShare" href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know?src=embed" style="text-decoration: underline;">presentation</a> or <a href="http://www.slideshare.net/upload?src=embed" style="text-decoration: underline;">Upload</a> your own. (tags: <a href="http://slideshare.net/tag/voip" style="text-decoration: underline;">voip</a> <a href="http://slideshare.net/tag/voipsecurity" style="text-decoration: underline;">voipsecurity</a>)</div></div>
<p><em>(And yes, at some point I'll sync the audio with the slides.)</em>
</p>

<p>Production assistance on this Special Edition was provided by Michael Graves who had a very tough task given the poor quality of the recording that I gave to him!&nbsp; Kudos to Michael for getting it to sound as good as it does.

</p>

<p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>
]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 15:54:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/astricon">astricon</category>
      <category domain="http://securityratty.com/tag/view slideshare presentation">view slideshare presentation</category>
      <category domain="http://securityratty.com/tag/slideshare">slideshare</category>
      <category domain="http://securityratty.com/tag/voip systems">voip systems</category>
      <category domain="http://securityratty.com/tag/audio comments">audio comments</category>
      <category domain="http://securityratty.com/tag/audio">audio</category>
      <category domain="http://securityratty.com/tag/specific security issues">specific security issues</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <source url="http://www.blueboxpodcast.com/2008/09/blue-box-se026.html">Blue Box SE#026 - Astricon 2007 presentation on VoIP security and Asterisk</source>
    </item>
    <item>
      <title><![CDATA[Blue Box SE#026 - Astricon 2007 presentation on VoIP security and Asterisk]]></title>
      <link>http://securityratty.com/article/f2bb50144dae112aaea9593bf1748c51</link>
      <guid>http://securityratty.com/article/f2bb50144dae112aaea9593bf1748c51</guid>
      <description><![CDATA[Synopsis: Blue Box Special Edition #26: Astricon 2007 presentation - &quot;Hacking and Attacking VoIP Systems: What you need to worry about
Welcome to Blue Box: The VoIP Security Podcast Special Edition...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box Special Edition #26: Astricon 2007 presentation - &quot;Hacking and Attacking VoIP Systems: What you need to worry about&quot;</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> Special Edition #26, a 55-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3" rel="enclosure">Download the show here</a> (MP3, 6MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3&amp;bgcolor=#FFFFFF" /></object> </p> 

<p><strong>Show Content:</strong></p> 
<p>A year ago in September 2007, I (Dan York) spoke at Astricon 2007 in Arizona, USA, about &quot;Hacking and Attacking VoIP Systems: What You Need To Worry About&quot; My presentation covered a lot of the typical VoIP security threats, tools and best practices but also expanded a bit into specific security issues with Asterisk.&nbsp; Please do keep in mind that it has been a year since this presentation and so some of the issues I mention have been addressed. (<a href="http://www.astricon.net/">Astricon</a>, for those who don't know, is an annual developer conference for those who work with the <a href="http://www.asterisk.org/">Asterisk open source telephony platform</a>. Astricon 2008 is, in fact, coming up in about 3 weeks but I will not be attending this year.)
</p>

<p>The slides for this talk <a href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know/">are available from Slideshare</a>:
</p>



<div id="__ss_178451" style="width: 425px; text-align: left;"><a title="Hacking and Attacking VoIP Systems - What You Need To Know" href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know?src=embed" style="margin: 12px 0pt 3px; font-family: Helvetica,Arial,Sans-serif; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none; display: block; text-decoration: underline;">Hacking and Attacking VoIP Systems - What You Need To Know</a><object width="425" height="355" style="margin: 0px;"><param value="http://static.slideshare.net/swf/ssplayer2.swf?doc=hacking-and-attacking-voip-systems-what-you-need-to-know-119595215763603-5&amp;stripped_title=hacking-and-attacking-voip-systems-what-you-need-to-know" name="movie" /><param value="true" name="allowFullScreen" /><param value="always" name="allowScriptAccess" /><embed width="425" height="355" allowfullscreen="true" allowscriptaccess="always" type="application/x-shockwave-flash" src="http://static.slideshare.net/swf/ssplayer2.swf?doc=hacking-and-attacking-voip-systems-what-you-need-to-know-119595215763603-5&amp;stripped_title=hacking-and-attacking-voip-systems-what-you-need-to-know"></embed></object><div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View SlideShare <a title="View Hacking and Attacking VoIP Systems - What You Need To Know on SlideShare" href="http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know?src=embed" style="text-decoration: underline;">presentation</a> or <a href="http://www.slideshare.net/upload?src=embed" style="text-decoration: underline;">Upload</a> your own. (tags: <a href="http://slideshare.net/tag/voip" style="text-decoration: underline;">voip</a> <a href="http://slideshare.net/tag/voipsecurity" style="text-decoration: underline;">voipsecurity</a>)</div></div>
<p><em>(And yes, at some point I'll sync the audio with the slides.)</em>
</p>

<p>Production assistance on this Special Edition was provided by Michael Graves who had a very tough task given the poor quality of the recording that I gave to him!&nbsp; Kudos to Michael for getting it to sound as good as it does.

</p>

<p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=ro8CGS"><img src="http://feeds.feedburner.com/~a/BlueBox?i=ro8CGS" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=lF8MaL"><img src="http://feeds.feedburner.com/~f/BlueBox?i=lF8MaL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=d2zQmL"><img src="http://feeds.feedburner.com/~f/BlueBox?i=d2zQmL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=h8U0ZL"><img src="http://feeds.feedburner.com/~f/BlueBox?i=h8U0ZL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=8B82bL"><img src="http://feeds.feedburner.com/~f/BlueBox?i=8B82bL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=keFvsl"><img src="http://feeds.feedburner.com/~f/BlueBox?i=keFvsl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=WSWkOL"><img src="http://feeds.feedburner.com/~f/BlueBox?i=WSWkOL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/382765294" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 14:54:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/astricon">astricon</category>
      <category domain="http://securityratty.com/tag/view slideshare presentation">view slideshare presentation</category>
      <category domain="http://securityratty.com/tag/slideshare">slideshare</category>
      <category domain="http://securityratty.com/tag/voip systems">voip systems</category>
      <category domain="http://securityratty.com/tag/audio comments">audio comments</category>
      <category domain="http://securityratty.com/tag/audio">audio</category>
      <category domain="http://securityratty.com/tag/specific security issues">specific security issues</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/382765294/blue-box-se026.html">Blue Box SE#026 - Astricon 2007 presentation on VoIP security and Asterisk</source>
    </item>
    <item>
      <title><![CDATA[PCI V1.2, a good start but still not enough]]></title>
      <link>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</link>
      <guid>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</guid>
      <description><![CDATA[Blogger: Randall Gamby
Two weeks ago the PCI Security Standards Council released the preliminary details of the PCI Data Security Standard (DSS) V1.2 thats due out in October. While many Analysts and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>Two weeks ago the PCI Security Standards Council released the preliminary details of the <a href="https://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">PCI Data Security Standard (DSS) V1.2</a> that’s due out in October.&nbsp; While many Analysts and Reporters have already written on the topic (I’ll be releasing an extensive update on Burton Group’s PCI coverage around the October release date), they really haven’t commented on what’s still not been addressed by the standard for enterprises still working on attaining compliance.</p>

<p>While I applaud the PCI Security Standards Council in further clarifying and adjusting the standard, a lot of work still needs to be done.&nbsp; I receive about one or two PCI questions a week from our clients and they seem to revolve around a couple of topics I’ve yet to see addressed:</p>

<ul><li><strong>Guidelines for selecting a Qualified Security Assessor (QSA)</strong> – while there are a large number of QSA organizations listed on the PCI Security Standards Council web site; they can’t really recommend a particular QSA for an individual organization.&nbsp; This leads a lot of organizations to struggle with determining what criteria they should use in selecting a QSA for their certification.</li>

<li><strong>The role of the QSA</strong> – organizations are also still trying to understand the role of a QSA.&nbsp; Should they get a QSA involved in the gap and remediation process in advance of certification?&nbsp; If so, should it be the same QSA that will do their certification (knowing there’s a risk that the QSA will be pre-disposed to only care about certain vulnerabilities)?</li>

<li><strong>Industry-specific best practices</strong> – while each organization may have different infrastructures, in general, most industries try to be consistent with the major functions they perform.&nbsp; So are credit card transactions handled differently between say, a major retailer with 10,000 POS systems and an insurance company that has hundreds of independent agents receiving remittances? Probably, so what are best practices around these industry-specific configurations?</li>

<li><strong>Virtualized environments</strong> – while the PCI Security Standards Council recognizes that some organizations have moved to virtual services for consolidation and management, the DSS really doesn’t provide guidelines for QSAs to evaluate and certify these environments.</li>

<li><strong>Monitoring and audit</strong> – while the PCI DSS recommends minimum timeframes for scanning, doing pen tests, etc. what are the real levels of monitoring and audit needed for ensuring security?&nbsp; With the Hannaford and Okemo breaches that occurred (both where PCI compliant), neither discovered the problem until months after the breaches had happened.&nbsp; So identifying what should be scanned and tested and if some of this should be on a continuous basis still requires refinement.</li>

<li><strong>PCI as part of an overall security model</strong> – what are the best practices around merging PCI security requirements into an enterprise’s overall security model?&nbsp; Should it be maintained separately? Should some components be integrated with similar security mechanisms?&nbsp; Should PCI be at the top of the security model and other configurations be based upon its requirements?&nbsp; There are really no answers coming forth on this topic and the other question is where will they come from? Surely enterprises won’t expect the PCI Security Standards Council to tell them how to run their security services.</li></ul>

<p>I will be providing Burton Group’s perspective on most of these questions in my upcoming report, but rather than relying on third parties to resolve these, I’d hope that the PCI Security Standards Council will be able to continue to provide answers to the questions they can in future updates, and releases, of the PCI DSS.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/382655858" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:56:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security assessor">security assessor</category>
      <category domain="http://securityratty.com/tag/security model">security model</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/dss">dss</category>
      <category domain="http://securityratty.com/tag/pci security requirements">pci security requirements</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/qsa">qsa</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/382655858/pci-v12-a-good.html">PCI V1.2, a good start but still not enough</source>
    </item>
    <item>
      <title><![CDATA[CEP is Not Low Latency Messaging, EAI or ESB]]></title>
      <link>http://securityratty.com/article/ca4a4c065cad28536dda34d18757089d</link>
      <guid>http://securityratty.com/article/ca4a4c065cad28536dda34d18757089d</guid>
      <description><![CDATA[In respose to CEP is Not BPM, BAM, BRE, BRMS or SOA , fellow blogger Mark Palmer posts, Smart Order Routing and CEP - Made for Each Other . Mark does a good job describing his perspective on smart...]]></description>
      <content:encoded><![CDATA[<p>In respose to <a title="CEP is Not BPM, BAM, BRE, BRMS or SOA" rel="bookmark" href="http://www.thecepblog.com/2008/08/27/cep-is-not-bpm-bam-bpm-brms-or-soa/"><span style="color: #105cb6;">CEP is Not BPM, BAM, BRE, BRMS or SOA</span></a>, fellow blogger Mark Palmer posts, <a href="http://streambase.typepad.com/streambase_stream_process/2008/09/smart-order-routing-and-cep.html" target="_blank">Smart Order Routing and CEP - Made for Each Other</a>.   Mark does a good job describing his perspective on smart order routing (SOR), yet his counterpoint that SOR is &#8220;complex event processing&#8221; is quite unconvincing.</p>
<p>I agree with Mark that SOR is important and very interesting; but in his reply he seems to be confusing CEP with &#8220;complex EAI&#8221; or a &#8220;complex messaging&#8221; application.  For example, Mark says,</p>
<blockquote><p><em>&#8220;It&#8217;s not uncommon for a single SOR system to connect to 10 or more markets and multiple asset classes.  Not only is this a confluence of events, it&#8217;s a stunningly complicated environment in which to create a complex, real-time model in which to apply &#8220;simple&#8221; routing decisions. On this basis alone, SOR needs CEP</em>.&#8221;</p></blockquote>
<p>Connecting to many market feeds with multiple asset classes might be complicated, but &#8220;complicated connections&#8221; are an EAI  (adaptation layer) function, not a core CEP function.   In fact, TIBCO Software has been doing this type of low latency back-office order routing for many years, and TIBCO historically calls this &#8220;messaging.&#8221;  Adding some rules to high speed, low latency messaging does not make it a &#8220;CEP&#8221; application.</p>
<p>Mark goes on to set up a counter argument to ILOG&#8217;s <a rel="external nofollow" href="http://forums.ilog.com/brms/index.php?action=profile;u=16"><strong>Changhai Ke</strong></a>, comments with,</p>
<blockquote><p><em>&#8220;SOR operates by analyzing the confluence of events from market data feeds, order flows from OMS systems, and executions, aggregating and analyzing those events in real time, and adjust routing decisions on the fly.&#8221;</em></p></blockquote>
<p>This is the well travelled argument the &#8220;new stream processing vendors in capital markets&#8221; have been saying, still unconvincingly, for the last few years.  Basically their perspective is that if you have a lot of &#8221;feeds&#8221; and a core requirement for &#8220;speed&#8221; - &#8220;feeds and speed&#8221; - you are doing &#8220;complex event processing.&#8221; </p>
<p>Mark Palmer forcefully stated his opinon that the folks who do not agree with him do not &#8220;understand&#8221; modern day SOR.    However,  a strong counter argument can be made that the &#8220;newcomers&#8221; to capital markets like StreamBase do not understand that &#8220;feeds and speeds&#8221; with order routing is little more than moderan day EAI.   This is a basic message routing capability and it has been around for a long time.  After all, Wall Street operated quite well before the term CEP was coined!  TIBCO technology was providing Wall Street back office, low latency, smart order routing a decade ago, and they called this technology &#8220;messaging&#8221;.  </p>
<p>So, I remain unconvinced, at least by Mark&#8217;s passionate counter post, that SOR is CEP.   SOR, as Mark and other have described it, is a low latency messaging technology.  Message routing rules have exisited in this technology space for decades.</p>
<p>I agree with Mark completely that low latency EAI (like SOR has been described) can be quite complex, from a &#8220;feeds and speeds&#8221; perspective.   However,  I remain skeptical that &#8220;feeds and speeds&#8221; is much more than  modern day messaging and message routing.</p>
<p>In closing, in the network and security management world we have been dealing with &#8220;myriad feeds and speeds&#8221; for as long as I can remember, but admitted not like capital markets.    Taking myriad feeds, running rules against the feeds and then routing the messages/events for further processing, regardless of the complexity of the feeds and the data, is actually more of a messaging/ESB technology than a CEP technology. </p>
<p>I remain completely open minded to any convincing counter arguments.</p>
]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 08:31:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/cep technology">cep technology</category>
      <category domain="http://securityratty.com/tag/low latency">low latency</category>
      <category domain="http://securityratty.com/tag/modern day sor">modern day sor</category>
      <category domain="http://securityratty.com/tag/feeds">feeds</category>
      <category domain="http://securityratty.com/tag/myriad feeds">myriad feeds</category>
      <category domain="http://securityratty.com/tag/sor">sor</category>
      <category domain="http://securityratty.com/tag/vendorsin capital markets">vendorsin capital markets</category>
      <category domain="http://securityratty.com/tag/capital markets">capital markets</category>
      <source url="http://www.thecepblog.com/2008/09/03/cep-is-not-low-latency-messaging-eai-or-esb/">CEP is Not Low Latency Messaging, EAI or ESB</source>
    </item>
    <item>
      <title><![CDATA[Relax, the Net Backbone Has Space for Your Lolcats]]></title>
      <link>http://securityratty.com/article/b00a463d2bb0a5e64116bda67d599849</link>
      <guid>http://securityratty.com/article/b00a463d2bb0a5e64116bda67d599849</guid>
      <description><![CDATA[Many people have feared that lolcats and other traffic are going to block the tubes, but Ars says today that the net backbone bandwidth is in fact growing and plenty prepared to swallow those cats....]]></description>
      <content:encoded><![CDATA[<p>Many people have feared that lolcats and other traffic are going to block the &#8216;tubes, but Ars says today that the net backbone bandwidth is in fact growing and plenty prepared to swallow those cats. Actually they use a prettier analogy&#8211;</p>
<blockquote><p>Given recent media coverage, it&#8217;s easy to believe that P2P and streaming video traffic is a rising hurricane battering upon ISP levees, that ISPs are frantically sandbagging their systems against disaster, that throttling, bandwidth caps, and traffic management are urgent and absolute necessities to keep the storm surge at bay. But new research from Telegeography only confirms what we&#8217;ve been saying for some time: the Internet backbone isn&#8217;t drowning beneath any kind of exaflood. In fact, backbone capacity has grown faster than Internet traffic in the last year—for the second year in a row.</p></blockquote>
<p>Check out the <a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20080903-what-exaflood-net-backbone-shows-no-signs-of-osteoporosis.html">full article</a>, it even has some shiny graphs. It also reminds me of <a rel="nofollow" target="_blank" href="http://xkcd.com/470/">XKCD</a> the other day&#8230; header: &#8220;I get in trouble for showing up contented to protests,&#8221; and the stick figure&#8217;s holding signs: &#8220;Things are pretty OK!&#8221; and &#8220;Anyone for Scrabble later?&#8221;</p>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 06:21:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/internet traffic">internet traffic</category>
      <category domain="http://securityratty.com/tag/video traffic">video traffic</category>
      <category domain="http://securityratty.com/tag/traffic management">traffic management</category>
      <category domain="http://securityratty.com/tag/net backbone bandwidth">net backbone bandwidth</category>
      <category domain="http://securityratty.com/tag/recent media coverage">recent media coverage</category>
      <category domain="http://securityratty.com/tag/isp levees">isp levees</category>
      <category domain="http://securityratty.com/tag/lolcats">lolcats</category>
      <category domain="http://securityratty.com/tag/grown faster">grown faster</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/382565188/">Relax, the Net Backbone Has Space for Your Lolcats</source>
    </item>
  </channel>
</rss>
