<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: tank]]></title>
    <link>http://securityratty.com/tag/tank</link>
    <description></description>
    <pubDate>Thu, 10 Jul 2008 08:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[In-Flight VoIP Ban: Against FCC Rules? Highly Desirable?]]></title>
      <link>http://securityratty.com/article/04edfe3e5a28bd63c48bc3f4ded28db4</link>
      <guid>http://securityratty.com/article/04edfe3e5a28bd63c48bc3f4ded28db4</guid>
      <description><![CDATA[Think-tank wonders whether banning in-flight VoIP constitutes a violation of FCC rules about blocking services: The Progress and Freedom Foundation's Barbara Espin uses the ban on in-flight VoIP by...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://blog.pff.org/archives/2008/09/does_disclosure.html"><strong>Think-tank wonders whether banning in-flight VoIP constitutes a violation of FCC rules about blocking services:</strong></a> The Progress and Freedom Foundation's Barbara Espin uses the ban on in-flight VoIP by American Airlines (facilitated by provider Aircell) to make a broader argument about what she calls the FCC's "ad hoc approach to broadband network management issues." It's clever. American discloses that calling isn't allowed, and VoIP isn't even technically within the FAA or FCC's purview, as far as I can determine. The FAA could choose to regulate it as a safety issue. PFF generally tilts anti-regulation, and has as what it calls its "supporters" a broad area of multiple system cable operators and telecom firms, including Comcast, which was singled out and fined by the FCC for its undisclosed network disruption of P2P connections.</p>

<p><a href="http://www.nytimes.com/2008/09/14/business/14essay.html?_r=2&ei=5070&emc=eta1&oref=slogin&oref=slogin"><strong>Espin references Joe Sharkey's excellent column on in-flight calling in Sunday's New York Times:</strong></a> Sharkey, a veteran travel writer, who survived a mid-air collision over the Brazilian Amazon a few years ago, looks at varying attitudes about calls made during flights. He quotes Aircell's Jack Blumenstein saying what I've telling folks for months: Aircell has a lot of techniques to block VoIP calls already, and "as we identify new ways that people are trying to do voice calls on the airplane, we just kind of zero in and knock those off." Many geeks have assumed Aircell is a bunch of unsavvy folks who wouldn't be able to figure out how to disrupt their clever workarounds for making VoIP. (I keep noting that introducing jitter for suspicious data connections wouldn't disrupt legitimate applications, but would destroy VoIP call quality.)</p>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 05:50:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/in-flight voip constitutes">in-flight voip constitutes</category>
      <category domain="http://securityratty.com/tag/in-flight">in-flight</category>
      <category domain="http://securityratty.com/tag/in-flight voip">in-flight voip</category>
      <category domain="http://securityratty.com/tag/block voip calls">block voip calls</category>
      <category domain="http://securityratty.com/tag/fcc rules">fcc rules</category>
      <category domain="http://securityratty.com/tag/fcc">fcc</category>
      <category domain="http://securityratty.com/tag/voice calls">voice calls</category>
      <category domain="http://securityratty.com/tag/calls">calls</category>
      <source url="http://wifinetnews.com/archives/008444.html">In-Flight VoIP Ban: Against FCC Rules? Highly Desirable?</source>
    </item>
    <item>
      <title><![CDATA[Secret Military Technology]]></title>
      <link>http://securityratty.com/article/ae8517ec5993912e6996ae981acd5cc7</link>
      <guid>http://securityratty.com/article/ae8517ec5993912e6996ae981acd5cc7</guid>
      <description><![CDATA[On 60 Minutes , in an interview with Scott Pelley, reporter Bob Woodward claimed that the U.S. military has a new secret technique that's so revolutionary, it's on par with the tank and the airplane:...]]></description>
      <content:encoded><![CDATA[<p>On <i>60 Minutes</i>, in an interview with Scott Pelley, reporter Bob Woodward claimed that the U.S. military has a new secret technique that's so revolutionary, it's on par with the tank and the airplane:</p>

<blockquote>Woodward: This is very sensitive and very top secret, but there are secret operational capabilities that have been developed by the military to locate, target, and kill leaders of al Qaeda in Iraq, insurgent leaders, renegade militia leaders, that is one of the true breakthroughs.

<p>Pelley: What are we talking about here? Some kind of surveillance, some kind of targeted way of taking out just the people that you're looking for, the leadership of the enemy?<br />
 <br />
[...]</p>

<p>Woodward: It is the stuff of which military novels are written.</p>

<p>Pelley: Do you mean to say that this special capability is such an advance in military technique and technology that it reminds you of the advent of the tank and the airplane?</p>

<p>Woodward: Yeah.</blockquote></p>

<p>It's <a href="http://www.cbsnews.com/stories/2008/09/04/60minutes/main4415771.shtml">here</a>, 7 minutes and 55 seconds in.</p>

<p>Anyone have any ideas?</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=1ALNL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=1ALNL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=DDhiL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=DDhiL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 07:35:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/military">military</category>
      <category domain="http://securityratty.com/tag/woodward">woodward</category>
      <category domain="http://securityratty.com/tag/reporter bob woodward">reporter bob woodward</category>
      <category domain="http://securityratty.com/tag/military novels">military novels</category>
      <category domain="http://securityratty.com/tag/scott pelley">scott pelley</category>
      <category domain="http://securityratty.com/tag/pelley">pelley</category>
      <category domain="http://securityratty.com/tag/military technique">military technique</category>
      <category domain="http://securityratty.com/tag/renegade militia leaders">renegade militia leaders</category>
      <category domain="http://securityratty.com/tag/secret operational capabilities">secret operational capabilities</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/secret_military.html">Secret Military Technology</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hack shows security hasnt improved in 10 years]]></title>
      <link>http://securityratty.com/article/ee3aa28f50e375a8f21a3a812bc96c25</link>
      <guid>http://securityratty.com/article/ee3aa28f50e375a8f21a3a812bc96c25</guid>
      <description><![CDATA[One of my old L0pht collegues, Peiter Mudge Zatko, is featured in Mass High Tech today in anarticle titled Bay State hackers find security holes in defibrillators, RFID
Hackers getting a free T pass...]]></description>
      <content:encoded><![CDATA[<p>One of my old L0pht collegues, Peiter &#8220;Mudge&#8221; Zatko, is featured in Mass High Tech today in an article titled <a href="http://www.masshightech.com/stories/2008/08/18/weekly15-Bay-State-hackers-find-security-holes-in-defibrillators-RFID.html">Bay State hackers find security holes in defibrillators, RFID.</a></p>
<blockquote><p>Hackers getting a free T pass may be the least of our worries — local hackers-turned-security experts suggest RFID keycards, wireless networks and medical devices implanted in the body are also vulnerable to hacks.</p>
<p>At last week’s Defcon hacker convention in Las Vegas, a team of researchers showed it was possible to get information such as Social Security numbers and medical diagnoses, and change the settings on an implantable defibrillator by impersonating the computer it communicates with wirelessly. By doing so, a hacker could send a fatal shock to a patient’s heart, said <a href="http://www.masshightech.com/search.html?q=William%20Maisel&amp;t=2">William Maisel</a> of the <a href="http://www.masshightech.com/search.html?q=Beth%20Israel%20Deaconess%20Medical%20Center&amp;t=1">Beth Israel Deaconess Medical Center</a>.</p></blockquote>
<p>It is almost like things haven&#8217;t changed since the 90&#8217;s when the L0pht worked to change the mindset of security:</p>
<ol>
<li>Don&#8217;t trust vendor claims around security</li>
<li>Attacks aren&#8217;t &#8220;theoretical&#8221;</li>
<li>Security by obscurity is no security</li>
</ol>
<p>The L0pht worked as an independent security research think tank.  For us it was non-profit side job researching and publishing vulnerabilities in software and hardware.  We did it for our love of technology and published what we found out because purchasers and users of the vulnerable systems deserve to know.</p>
<p>It&#8217;s 10 years later and the situation hasn&#8217;t improved much.  Mudge talks about the vulnerabilities the L0pht found in highway transponder systems that are still in systems being fielded today.  But more important than the vulnerabilities themselves is the nature of how these vulnerabilities are coming to light.  They are being found by hobbyists, students, and IT people working in their spare time.  How can something as important as the security of public fare collection systems and medical equipment not have a standard process for security acceptance testing? </p>
<p>As we become more reliant on digital systems, with some even keeping us alive, it is high time for security testing to move beyond student papers and part time IT work.  Security testing needs to become a formal part of the process of purchasing and fielding digital systems.  Our lives are starting to depend on it.</p>
]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 16:46:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security holes">security holes</category>
      <category domain="http://securityratty.com/tag/security acceptance">security acceptance</category>
      <category domain="http://securityratty.com/tag/security testingneeds">security testingneeds</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/digital systems">digital systems</category>
      <category domain="http://securityratty.com/tag/independent security research">independent security research</category>
      <category domain="http://securityratty.com/tag/highway transponder systems">highway transponder systems</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <source url="http://www.veracode.com/blog/2008/08/mbta-hack-shows-security-hasnt-improved-in-10-years/">MBTA Hack shows security hasnt improved in 10 years</source>
    </item>
    <item>
      <title><![CDATA[ScienceLogics 5-Year Anniversary]]></title>
      <link>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</link>
      <guid>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</guid>
      <description><![CDATA[August 2003. The largest blackout in U.S. history darkens the Northeast and Midwest, the Blaster worm has been unleashed and Madonna and Britney create a stir at the 2003 MTV Music Video Awards . In...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="164" alt="B-day Cake" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/b-day-cake1.jpg" width="244" align="left" border="0"> August 2003. The largest <a href="http://blogs.wsj.com/biztech/2008/08/13/celebrating-the-anniversary-of-the-big-blackout/?mod=djemTECH" target="_blank">blackout</a> in U.S. history darkens the Northeast and Midwest, the <a href="http://news.cnet.com/2010-1001-5117862.html" target="_blank">Blaster worm</a> has been unleashed and Madonna and Britney create a stir at the <a href="http://en.wikipedia.org/wiki/2003_MTV_Video_Music_Awards" target="_blank">2003 MTV Music Video Awards</a>. In the midst of this <a href="http://www.grid.unep.ch/product/publication/download/ew_heat_wave.en.pdf" target="_blank">hot summer</a> madness, ScienceLogic was founded.
<p>To kick off our celebration of our first five years, we asked <a href="http://www.sciencelogic.com/leadership.htm" target="_blank">ScienceLogic founders</a> Dave Link, Richard Chart and Chris Cordray for their thoughts and memories on events leading to today’s milestone. How and why did they set out on this venture? What happened along the way – expected and unexpected? Why were they successful in times when other new (and established) businesses have come and <a href="http://en.wikipedia.org/wiki/Category:2003_disestablishments" target="_blank">gone</a>?
<p><b>How did you three put together this team?</b>
<p>We all worked together at a large Managed Service Provider for a couple of years before leaving to start ScienceLogic, so we all knew each other and knew our collective strengths. More importantly, each of us had worked with network management tools on some level (sales and marketing, engineering and product development), and knew first-hand all of the customer pain points, from every perspective. So we left and began rapidly figuring out how to build a better network management solution based upon our real world operational experience..
<p><strong>Dave:</strong> One interesting aspect is that our areas of expertise don’t overlap, which has contributed to our success. Chris is excellent with developing the product front-end and interface, Richard handled the backend architecture and engineering and I focused on the technical business side of sales and marketing. Our roles have been to build a product that works well and that provides real value to operations teams that experience the same day to day frustrations that we felt.<b></b>
<p><b>Whose idea was it to start the company?</b>
<p><strong>Dave:</strong> It was really a collective effort. We were all passionate about “getting it right” and not just starting a company. We knew the industry need and between us, we had the knowledge and skill sets to address all of the right aspects of developing a product and a building a business around it.
<p><b>What process did you go through to get started?</b>
<p><strong>Richard:</strong> From the beginning we knew the type of solution the market needed and we knew that we wanted to build it as an appliance. From different vantage points, we had each experienced the effects of long, difficult and expensive installations that still exist with traditional network tools. Every install has unique variations: there are always different server types, varying hardware and software versions, different patches installed, and on and on. Every installation was time consuming and unpredictable. We knew that an appliance model would address all of these variables and save a lot of time on how quickly customers could achieve immediate value.
<p>The harder decisions were around actually starting the business, assessing the market and of course determining the product pricing.
<p><b>EM7 completely flips the traditional model of complex, lengthy and expensive deployments. How did you convince others that the EM7 Meta-Appliance product was valid?</b>
<p><strong>Dave:</strong> Yes, EM7 totally disrupts the traditional model for network management. While others take a narrow approach, we intentionally designed EM7 to focus on the broad problem – managing the data center. How do you cover a variety of technologies and make sure they work seamlessly together? The vision was to make it easier, not harder, for customers.
<p><strong>Chris:</strong> I have to give it to Dave – very early on, he realized the power of a demo. If Dave could get in front of someone, he’d make them a believer. He’d use the Peter Falk/Columbo technique of “let me show you one more thing.” It was very effective. It’s getting easier, but even today people sometimes have to see EM7 in action before they become believers.
<p><b>Can you describe the early days of running a new business?</b>
<p><strong>Dave:</strong> ScienceLogic is a classic case of entrepreneurship. For the first year we worked out of our basements. We kept the costs low in every conceivable way and spent the first year developing the product before we even made a sale.
<p><strong>Chris:</strong> We stayed at lots of odd places when we were on the road, took cheap flights with multiple layovers and purchased lots of our first test equipment on eBay. This was during the dot-com bust so there was lots of equipment for sale on eBay, really cheap!
<p><strong>Richard:</strong> The amount of equipment I had in my house was absolutely crazy. Back then, servers were huge – I had a Cisco 6509 Catalyst, a Compaq Proliant DL380, Brocade switch, IBM Netfinity 4500R, and tons of other machines.
<p><strong>Chris:</strong> I had to install a new circuit box at home because I was blowing breakers. I remember when that 6509 crashed, we revived it and it died again. The second death was final.
<p><b>So you started in your houses – what was your first office space?</b>
<p><strong>Dave:</strong> My friend, the CEO at Ernst &amp; Young Technology had a few extra cubes and a data center in their office that they graciously allowed us to use. Their help was an important step in helping us really formalize the business. We started doing well and adding people, but ironically, their company was downsizing. Before long, many of their original YET people were gone and the ScienceLogic team kept growing in to the open cubes.
<p>Our first leased space was converted warehouse space in Chantilly, VA that once housed an internet radio station. It was cool – it had a large salt water fish tank, a loft, a spiral staircase and a Star Trek door that retracted into the walls with the customary lights and “whooshing” sound.
<p>We outgrew the Chantilly space, leading to our current office in Reston, VA.
<p><b>Who was the first ScienceLogic customer?</b>
<p>Our first paying customer was <a href="http://martinspoint.com/" target="_blank">Martins Point Health Care</a>. We deployed there in July 2004 and are pleased to say they continue to be a ScienceLogic customer. Other early (and still) EM7 <a href="http://www.sciencelogic.com/customers.htm" target="_blank">customers</a> include Navy Knowledge Online and the Department of Transportation. Nearly all of our customers are still actively using EM7 and renewing their maintenance.
<p><b>Where do you see the company in the next 5, 10 or 15 years?</b>
<p>Well, our revenue has doubled year-over-year in each of the last three years, so of course we’d like to continue to grow like that or even faster. In five years we’ve gone from three founders to the point where Dave does not know everyone’s fondest childhood memory. We’ll continue to scale our growth to cover the demands of our growing customer base.
<p><b>Where do you see the industry going over the coming years?</b>
<p><strong>Chris:</strong> IT is always moving and gaining in complexity, so network management is also becoming more complicated. There’s increasing diversity, new standards, virtualization and cloud computing. All of these are today’s technologies. Customers have a mix of the old and the new, so EM7 has to accommodate and support both.
<p><strong>Richard:</strong> Each generation of products has a new set of ways to monitor, but the “old” doesn’t go away. Even when a new, hot technology comes along, the old technologies still need to be supported. We work to ensure EM7 keeps up with both.
<p><strong>Dave:</strong> After five years we’re just hitting our stride and we’re just now reaching the tipping point in awareness of ScienceLogic and EM7. We’re all still passionate about the product and as Chris and Rich said, there’s still a lot do. We’ll continue disrupting the market with EM7. Our vision hasn’t changed, and with the increasing levels of automation that customers demand, the market needs are greater than ever. Our future is as bright, or brighter, than ever and we’ll continue to be looking for smart ways to automate traditionally manual IT Operations processes.
<p><b>What’s your advice for someone interested in starting their own business?</b>
<p><strong>Chris:</strong> Be passionate. That’s what has gotten me through the tough times. I didn’t really appreciate this thought when I heard others say it before. But it’s very true.
<p><strong>Richard:</strong> I agree. We met and talked with lots of people who told us, “That’s been done before.” But we kept going because we truly believed in what we were doing and we knew that while our approach was different, that it would be successful.
<p><strong>Richard:</strong> Be fearless. You can’t be too nervous and you need to be able to expect and handle the stress because it will be there. You have to learn to accept the stressful times as a necessary part of the process of starting out on your own.
<p><strong>Dave:</strong> Know your niche from the beginning and give potential customers a compelling reason to trust you and really benefit from your solution. You have to know the problem, see the gap and have a clear and consistent vision of how to solve the problem. Then you have to execute. If you don’t build your team with “doers” you won’t make it.
<p><strong>Chris:</strong> It helps to have friends. ScienceLogic was built on friendships and relationships, starting with the three of us. If you look at our team, most of our hires are referrals – people who developed and maintained great connections with other great people throughout their careers. Maintain your connections and keep in touch with your network of friends.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7 completely flips">em7 completely flips</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/network management tools">network management tools</category>
      <category domain="http://securityratty.com/tag/em7 meta-appliance product">em7 meta-appliance product</category>
      <category domain="http://securityratty.com/tag/sciencelogic team">sciencelogic team</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/product front-end">product front-end</category>
      <source url="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008">ScienceLogics 5-Year Anniversary</source>
    </item>
    <item>
      <title><![CDATA[Georgia cyberwar overblown]]></title>
      <link>http://securityratty.com/article/15e66d84ef2a025ed928e1eb169877ac</link>
      <guid>http://securityratty.com/article/15e66d84ef2a025ed928e1eb169877ac</guid>
      <description><![CDATA[Last week Russian tanks rolled into South Ossetia while Russian bombers were taking out critical communications infrastructure. But even before the first tank rolled across the disputed borders,...]]></description>
      <content:encoded><![CDATA[Last week Russian tanks rolled into South Ossetia while Russian bombers were taking out critical communications infrastructure. But even before the first tank rolled across the disputed borders, another war was brewing in cyberspace. ]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/critical communications infrastructure">critical communications infrastructure</category>
      <category domain="http://securityratty.com/tag/week russian tanks">week russian tanks</category>
      <category domain="http://securityratty.com/tag/south ossetia">south ossetia</category>
      <category domain="http://securityratty.com/tag/russian bombers">russian bombers</category>
      <category domain="http://securityratty.com/tag/cyberspace">cyberspace</category>
      <category domain="http://securityratty.com/tag/borders">borders</category>
      <category domain="http://securityratty.com/tag/war">war</category>
      <category domain="http://securityratty.com/tag/tank">tank</category>
      <source url="http://www.networkworld.com/columnists/2008/081908-andreas.html?fsrc=rss-security">Georgia cyberwar overblown</source>
    </item>
    <item>
      <title><![CDATA[Cyberattack Against Georgia Preceded Real Attack]]></title>
      <link>http://securityratty.com/article/05aa9f87510a1d42d2691aadc95f19a7</link>
      <guid>http://securityratty.com/article/05aa9f87510a1d42d2691aadc95f19a7</guid>
      <description><![CDATA[This is interesting: Exactly who was behind the cyberattack is not known. The Georgian government blamed Russia for the attacks, but the Russian government said it was not involved. In the end,...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.nytimes.com/2008/08/13/technology/13cyber.html">This</a> is interesting:</p>

<blockquote>Exactly who was behind the cyberattack is not known. The Georgian government blamed Russia for the attacks, but the Russian government said it was not involved. In the end, Georgia, with a population of just 4.6 million and a relative latecomer to the Internet, saw little effect beyond inaccessibility to many of its government Web sites, which limited the government's ability to spread its message online and to connect with sympathizers around the world during the fighting with Russia.

<p>[...]</p>

<p>In Georgia, media, communications and transportation companies were also attacked, according to security researchers. Shadowserver saw the attack against Georgia spread to computers throughout the government after Russian troops entered the Georgian province of South Ossetia. The National Bank of Georgia's Web site was defaced at one point. Images of 20th-century dictators as well as an image of Georgia's president, Mr. Saakashvili, were placed on the site. "Could this somehow be indirect Russian action? Yes, but considering Russia is past playing nice and uses real bombs, they could have attacked more strategic targets or eliminated the infrastructure kinetically," said Gadi Evron, an Israeli network security expert. "The nature of what's going on isn't clear," he said.</p>

<p>[...]</p>

<p>In addition to D.D.O.S. attacks that crippled Georgia's limited Internet infrastructure, researchers said there was evidence of redirection of Internet traffic through Russian telecommunications firms beginning last weekend. The attacks continued on Tuesday, controlled by software programs that were located in hosting centers controlled by a Russian telecommunications firms. A Russian-language Web site, stopgeorgia.ru, also continued to operate and offer software for download used for D.D.O.S. attacks.</blockquote></p>

<p>Welcome to 21st century warfare.</p>

<blockquote>"It costs about 4 cents per machine," Mr. Woodcock said. "You could fund an entire cyberwarfare campaign for the cost of replacing a tank tread, so you would be foolish not to."</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=FRnMDK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=FRnMDK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=O8aHKK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=O8aHKK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 09:11:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/indirect russian action">indirect russian action</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/georgian government">georgian government</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/russian troops">russian troops</category>
      <category domain="http://securityratty.com/tag/spread">spread</category>
      <category domain="http://securityratty.com/tag/georgia spread">georgia spread</category>
      <category domain="http://securityratty.com/tag/government web sites">government web sites</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/cyberattack_aga.html">Cyberattack Against Georgia Preceded Real Attack</source>
    </item>
    <item>
      <title><![CDATA[On TV Warfare]]></title>
      <link>http://securityratty.com/article/7aa61433eb4c92c880feff4e75ceeba8</link>
      <guid>http://securityratty.com/article/7aa61433eb4c92c880feff4e75ceeba8</guid>
      <description><![CDATA[It is simply amazing that all the countries now &quot;get it&quot; that war happens primarily on TV ( this vs this ; many other examples are around). It is also amazing that there is NO way to know where &quot;media...]]></description>
      <content:encoded><![CDATA[<p>It is simply amazing that all the countries now &quot;get it&quot; that war happens primarily on TV (<a href="http://www.nytimes.com/2008/08/12/world/europe/12georgia.html?_r=1&amp;pagewanted=2&amp;bl&amp;ei=5087&amp;en=b5bf8c5e2c630491&amp;ex=1218600000&amp;oref=slogin">this</a> vs <a href="http://www.themoscowtimes.com/article/600/42/369720.htm">this</a>; many other examples are around). It is also amazing that there is NO way to know where &quot;media reporting&quot; ends and &quot;psyops&quot; begin. So, a burning tank with no clear markings that you see on TV might be:</p>  <ol>   <li>Tank belonging to warring side A</li>    <li>Tank belonging to warring side B</li>    <li>Just a tank that was passing by and got hit by mistake :-)</li>    <li>Something that looks like a burning tank</li>    <li>An archive shot that reporter added for visual impact</li> </ol>  <p>Same applies to the &quot;primary weapon&quot; of a modern TV war: &quot;evidence of atrocities of the opposing side.&quot;</p>  <p>What's the truth? Who knows... progress brought us &quot;TV wars,&quot;&#160; is this the first <a href="http://www.defensetech.org/archives/004355.html">&quot;YouTube war&quot;?</a> But if we cannot believe the media coverage, how can we believe a random video online? Well ...&#160; maybe the same way we often believe Wikipedia over Britannica.&#160; </p>  <p>In any case, if there was a better time to turn off the TV (and tune off the web news...), it would be now. Also, time to get the dust off my <a href="http://www.amazon.com/War-Anti-War-Making-Todays-Global/dp/0446602590">copy of Toffler?</a></p>  <p>Rant mode off :-)</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=eQOSbK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=eQOSbK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=ZcEx8K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=ZcEx8K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=a86LNK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=a86LNK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/362457461" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 13:41:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tv">tv</category>
      <category domain="http://securityratty.com/tag/tv wars">tv wars</category>
      <category domain="http://securityratty.com/tag/modern tv war">modern tv war</category>
      <category domain="http://securityratty.com/tag/war">war</category>
      <category domain="http://securityratty.com/tag/youtube war">youtube war</category>
      <category domain="http://securityratty.com/tag/tank">tank</category>
      <category domain="http://securityratty.com/tag/media coverage">media coverage</category>
      <category domain="http://securityratty.com/tag/media">media</category>
      <category domain="http://securityratty.com/tag/random video online">random video online</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/362457461/on-tv-warfare.html">On TV Warfare</source>
    </item>
    <item>
      <title><![CDATA[World War II Deception Story]]></title>
      <link>http://securityratty.com/article/ffeef2b2ecdc9709d491f4a4c3ecd7f5</link>
      <guid>http://securityratty.com/article/ffeef2b2ecdc9709d491f4a4c3ecd7f5</guid>
      <description><![CDATA[Great security story from an obituary of former OSS agent Roger Hall: One of his favorite OSS stories involved a colleague sent to occupied France to destroy a seemingly impenetrable German tank at a...]]></description>
      <content:encoded><![CDATA[<p>Great <a href="http://www.philly.com/inquirer/obituaries/20080723_Roger_Hall___Poked_fun_at_spies__89.html">security story</a> from an obituary of former OSS agent Roger Hall:</p>

<blockquote>One of his favorite OSS stories involved a colleague sent to occupied France to destroy a seemingly impenetrable German tank at a key crossroads. The French resistance found that grenades were no use. 

<p>The OSS man, fluent in German and dressed like a French peasant, walked up to the tank and yelled, "Mail!" </p>

<p>The lid opened, and in went two grenades.</blockquote></p>

<p>Hall's book about his OSS days, <a href="http://www.amazon.com/Youre-Stepping-Cloak-Dagger-Bluejacket/dp/1591143535/ref=pd_bbs_sr_1"><i>You're Stepping on My Cloak and Dagger,</i></a> is a must read.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=urokhJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=urokhJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=TBL5AJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=TBL5AJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 09:50:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oss">oss</category>
      <category domain="http://securityratty.com/tag/oss days">oss days</category>
      <category domain="http://securityratty.com/tag/favorite oss stories">favorite oss stories</category>
      <category domain="http://securityratty.com/tag/grenades">grenades</category>
      <category domain="http://securityratty.com/tag/french resistance">french resistance</category>
      <category domain="http://securityratty.com/tag/french peasant">french peasant</category>
      <category domain="http://securityratty.com/tag/key crossroads">key crossroads</category>
      <category domain="http://securityratty.com/tag/security story">security story</category>
      <category domain="http://securityratty.com/tag/dagger">dagger</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/world_war_ii_de.html">World War II Deception Story</source>
    </item>
    <item>
      <title><![CDATA[Modelling Situations for Event Processing]]></title>
      <link>http://securityratty.com/article/eb41e60a6e175e4a75dbe8a59fa78ef8</link>
      <guid>http://securityratty.com/article/eb41e60a6e175e4a75dbe8a59fa78ef8</guid>
      <description><![CDATA[CEP, in a nutshell, is about the real-time detection of business opportunities and threats in cyberspace. Business opportunities and threats are often referred to as situations, so we can simply say...]]></description>
      <content:encoded><![CDATA[<p>CEP, in a nutshell, is about the real-time detection of business opportunities and threats in cyberspace.   Business opportunities and threats are often referred to as situations, so we can simply say that CEP is about the real-time situation detection.   </p>
<p>We represent situations in the domain of event processing by building and refining models of situations.  This means that one way to develop CEP applications or designing CEP architectures is to define situations of interest and build models that define the situation.  </p>
<p>After we have a working model of the situation we will generally have a hierarchical model of the situation composed of various components of the situation.    For purposes of discussion I refer to this as situation modelling.   </p>
<p>If a situation is modelled with 15 components then we need to detect these components of the situation.   In addition, it is generally not good enough to simply detect each one of these components of the situation.  We also have to hold the state of each one of the situational components.  </p>
<p>However, it is not good enough to simply observe the state of 15 components of a situation in the detection process; we also need to observe the relationship between the components.</p>
<p>So, let’s say the situation we are looking for is “commercial air plane collision” and we are building a model of this situation.      To keep the model simple we will limit the model to airplanes and omit objects like birds, buildings; but we will include wind, air speed, and direction.</p>
<p>Our situational model consists of primary objects, in this case an airplane.   Now we need a simple model of an airplane, which is modelled, in this overly simple example, as span, velocity, acceleration, altitude, orientation and relative wind speed and direction.  Generally, an object-oriented approach to model building is preferred so we can reuse the model and overload, morph, inherit and encapsulate as necessary.</p>
<p>One example would be when our boss comes to us and says, great job on the airplane collision model, but I also want to know how much jet fuel is on the planes at the moment of our projected situation, so we can estimate the intensity of the explosion.   So we need another model and our earlier very simple airplane model would inherit the jet fuel tank model our boss requires.</p>
<p>I hope from this simple example of model building that you will conclude that modelling is one of the most important aspects of CEP.   Without good models, situation detection impossible, and CEP engines are useless.    Situation modelling is critical to CEP.  </p>
<p>So, if a CEP vendor comes to you and says they have a very powerful CEP engine, ask them to show you a complex model of a situation that is important to you and explain to you how they represent the object.  If models are not represented using an object-oriented approach, I recommend you send the vendor back to their software development lab, because without an OO approach to modelling, you can only represent very simple situations. </p>
<p>Furthermore, let’s say you are leading a team building a large model.   If there are several teams working on various parts of the model, you need a common framework to integrate the work of the various teams.  I strongly recommend an OO approach to your model building systems architecture and work breakdown structure.</p>
<p>In a future post, I will write about the companion to modelling – simulation</p>
]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 01:04:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/model">model</category>
      <category domain="http://securityratty.com/tag/airplane collision model">airplane collision model</category>
      <category domain="http://securityratty.com/tag/simple model">simple model</category>
      <category domain="http://securityratty.com/tag/model simple">model simple</category>
      <category domain="http://securityratty.com/tag/situations">situations</category>
      <category domain="http://securityratty.com/tag/hierarchical model">hierarchical model</category>
      <category domain="http://securityratty.com/tag/complex model">complex model</category>
      <category domain="http://securityratty.com/tag/simple airplane model">simple airplane model</category>
      <category domain="http://securityratty.com/tag/real-time situation detection">real-time situation detection</category>
      <source url="http://www.thecepblog.com/2008/07/15/modelling-situations-for-event-processing/">Modelling Situations for Event Processing</source>
    </item>
    <item>
      <title><![CDATA[Ex-Congressmans Firm Made Defective Tank Deal With Iraq]]></title>
      <link>http://securityratty.com/article/d5620d460cb83698922787c6d59ffa8e</link>
      <guid>http://securityratty.com/article/d5620d460cb83698922787c6d59ffa8e</guid>
      <description><![CDATA[If, someday, there are T-shirts sold in Iraq that read, &quot;the United States invaded our country and all we got were these crappy tanks,&quot; you can thank former Rep. Curt Weldons arms-dealing firm,...]]></description>
      <content:encoded><![CDATA[If, someday, there are T-shirts sold in Iraq that read, "the United States invaded our country and all we got were these crappy tanks," you can thank former Rep. Curt Weldon’s arms-dealing firm, Defense Solutions, for the new outfits. The company got itself a contract to refurbish Soviet-era tanks for the Iraqi government under a deal with such lopsided terms it likely would have been illegal under U.S. law.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=d54f97d7ac81f2d5552501435ca66b85" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=d54f97d7ac81f2d5552501435ca66b85" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=rZUsRJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=rZUsRJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=gPU0yj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=gPU0yj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=piKBtj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=piKBtj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=eYrPWJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=eYrPWJ" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=qDKtNJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qDKtNJ" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=JIKrBj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=JIKrBj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Xcpydj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Xcpydj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=FCOERJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=FCOERJ" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/331734469" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/331734472" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 08:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/refurbish soviet-era tanks">refurbish soviet-era tanks</category>
      <category domain="http://securityratty.com/tag/defense solutions">defense solutions</category>
      <category domain="http://securityratty.com/tag/deal">deal</category>
      <category domain="http://securityratty.com/tag/iraqi government">iraqi government</category>
      <category domain="http://securityratty.com/tag/curt weldons">curt weldons</category>
      <category domain="http://securityratty.com/tag/crappy tanks">crappy tanks</category>
      <category domain="http://securityratty.com/tag/firm">firm</category>
      <category domain="http://securityratty.com/tag/iraq">iraq</category>
      <category domain="http://securityratty.com/tag/law">law</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/331734472/someday-there-w.html">Ex-Congressmans Firm Made Defective Tank Deal With Iraq</source>
    </item>
  </channel>
</rss>
