<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: top5]]></title>
    <link>http://securityratty.com/tag/top5</link>
    <description></description>
    <pubDate>Fri, 04 Jan 2008 10:16:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Monthly Blog Round-Up October 2008]]></title>
      <link>http://securityratty.com/article/425e8bb2014656857a1c215075620790</link>
      <guid>http://securityratty.com/article/425e8bb2014656857a1c215075620790</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>OF COURSE, the news of my “transition” is the item #1, by far. “<a href="http://chuvakin.blogspot.com/2008/10/change.html">Change!!!</a>” and “<a href="http://www.qualys.com/solutions/pci_compliance/">Qualys</a>” posts rule the list.</li>    <li>Last month I posted a bunch of my presentations on logs, security, etc on the blog.&#160; “<a href="http://www.slideshare.net/anton_chuvakin/logs-for-incident-response-and-forensics-key-issues-for-govcertnl-2008-presentation-620704">Presentation from GOVCERT.NL 2008: Log Forensics</a>” takes one of the tops spots; and so do “<a href="http://www.slideshare.net/anton_chuvakin/application-logging-good-bad-ugly-beautiful-presentation">Presentation on Application Logging, Done Wrong or Very Wrong</a>” and “<a href="http://www.slideshare.net/anton_chuvakin/logs-vs-insiders-presentation">Presentation on Optimizing Your Logging for Insider Attack Tracking</a>.”&#160; BTW, all the presentations are <a href="http://chuvakin.blogspot.com/search/label/presentation">here</a>.</li>    <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAIN</a> this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my poll</a>).&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a> and my other “top 11” lists.</li>    <li>SIEM bashing reached a new high (eh…“low”? :-)), now that Richard is <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">helping too</a>;&#160; my “<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a> is on the top list. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a> and <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">here</a>.)</li>    <li>Somewhat predictably, PCI compliance is obviously still all the rage: <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list.</li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in November.</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - September 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160; <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div></p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bZriN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bZriN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=8jskN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=8jskN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=haLRN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=haLRN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/448986147" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 13:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/monthly round-ups">monthly round-ups</category>
      <category domain="http://securityratty.com/tag/monthly top5 list">monthly top5 list</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/448986147/monthly-blog-round-up-october-2008.html">Monthly Blog Round-Up October 2008</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - August 2008]]></title>
      <link>http://securityratty.com/article/da35c1254d3a39679f5bed9406a6aded</link>
      <guid>http://securityratty.com/article/da35c1254d3a39679f5bed9406a6aded</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. This is an attempt to remind people of useful content!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>In a bizarre twist of fate (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my latest poll</a>), the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post in August.&#160; The analysis of said <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">log security poll</a> is coming up tomorrow. BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a>:&#160; <a href="http://chuvakin.blogspot.com/2008/05/poll-8-log-analysis-context.html">poll #8</a> that covered context data for log analysis <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">is analyzed here</a> and a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>)&#160; and <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually review and <a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">poll #5</a> about logging challenges. </li>    <li>Next up is my post &quot;<a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">Log Management - Day 1</a>,&quot; which talks about the very first thing you do when embarking on a journey to <a href="http://www.loglogic.com">log management</a>. </li>    <li>Still burning hot is a post with my irreverent comments on a Terry Childs saga. Namely, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">On Doomsaying (Terry Childs case)</a>&quot;, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">So ... Am I? Maybe I Am!</a>&quot; and &quot;<a href="http://chuvakin.blogspot.com/2008/07/admins-good-guys-or-am-not-idiot.html">Admins , Good Guys or &quot;I am NOT an Idiot!&quot;</a>&quot; </li>    <li>Somewhat predictably, PCI compliance is all the rage again with <a href="http://chuvakin.blogspot.com/2008/08/run-through-pci-dss-12-changes.html">1.2 coming out soon</a>. So, <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list. It discusses the fact that there is no &quot;easy list&quot; of what you MUST do to comply.</li>    <li>Finally, my post &quot;<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a>&quot;. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>)</li> </ol>  <p>See you in September,&#160; when .... ah, come on! I will tell you later :-)</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160;</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=uVPfyL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=uVPfyL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=NrADzL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=NrADzL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=njcwZL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=njcwZL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/383511875" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 08:22:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/log security poll">log security poll</category>
      <category domain="http://securityratty.com/tag/poll">poll</category>
      <category domain="http://securityratty.com/tag/popular post">popular post</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/383511875/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - June 2008]]></title>
      <link>http://securityratty.com/article/6bb7f76a5056f7584446e3423f3defba</link>
      <guid>http://securityratty.com/article/6bb7f76a5056f7584446e3423f3defba</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit "stateless" and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. This is what is driving an idiotic campaign of such "news" as "hackers increase hacking", "compliance is hard/easy/matters/doesn't" or "awareness of virtualization/SaaS/hacking/compliance grows."</p> <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">"Security Warrior" blog</a> </strong>round-up of top 5 popular posts and topics.</p> <ol> <li>Again this month, <a href="http://chuvakin.blogspot.com/search/label/poll">my logging polls</a> took the #1 spot!&nbsp; <a href="http://chuvakin.blogspot.com/2008/05/poll-8-log-analysis-context.html">Poll #8</a> that covered context data for log analysis <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">is analyzed here</a>. Other popular polls include a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>)&nbsp; and <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually look and <a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">poll #5</a> about logging challenges. Next poll is coming soon. <li>Not entirely surprising, my post/rant called "<a href="http://chuvakin.blogspot.com/2008/06/you-are-security-idiot-if.html">You Are "A Security Idiot" If ...</a>" takes the #2 spot after being live for only a few days. Yes, we all like to point out other people's problems, especially when they are epically huge :-) <li>Also not surprisingly, my post "<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or "Raffy, You Killed SIM!"</a>" is on the Top list. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>) <li>A curious subject of DLP or "data leak prevention" (specifically, the post called "<a href="http://chuvakin.blogspot.com/2008/06/so-can-we-have-dlp.html">So, CAN We Have DLP?</a>") also tops the charts. My previous post on data leak 'prevention' ("<a href="http://chuvakin.blogspot.com/2008/05/in-passing-on-dlp.html">In Passing on DLP</a>") is popular as well. <li>Again and again, people googling for "open source SIEM" have pushed this post (<a href="http://chuvakin.blogspot.com/2007/01/on-open-source-in-siem-and-log.html">this tiny old pathetic blurb</a>) to top5. This ancient post from years ago explains why an open source <a href="http://chuvakin.blogspot.com/search/label/SIEM">SIEM</a> will NOT emerge soon, if ever. </li></ol> <p>See you in July!</p> <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p> <ul> <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a>  <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a></li></ul> <p>&nbsp;</p> <p></p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>, <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>, <a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=vJkYeJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=vJkYeJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=jCmSaJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=jCmSaJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=U2B0xJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=U2B0xJ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/324237184" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 07:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/ancient post">ancient post</category>
      <category domain="http://securityratty.com/tag/popular posts">popular posts</category>
      <category domain="http://securityratty.com/tag/popular">popular</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/324237184/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - May 2008]]></title>
      <link>http://securityratty.com/article/7dbe2b9e432e7c2dd0077f7a580d13a9</link>
      <guid>http://securityratty.com/article/7dbe2b9e432e7c2dd0077f7a580d13a9</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit "stateless" and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. This is what is driving an idiotic campaign of such "news" as "hackers increase hacking", "compliance is hard" or "awareness of virtualization grows."</p> <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">"Security Warrior" blog</a> </strong>round-up of top 5 popular posts and topics.</p> <ol> <li>First time this month, <a href="http://chuvakin.blogspot.com/search/label/poll">my logging polls</a> took #1 spot!&nbsp; Specifically, a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>) sits highest among the Top5 posts (closely behind are <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually look at as well as <a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">poll #5</a> about logging challenges). <a href="http://chuvakin.blogspot.com/2008/05/poll-8-log-analysis-context.html">Poll #8 analysis</a> is coming up tomorrow, BTW... <li>As expected, the post called "<a href="http://chuvakin.blogspot.com/2008/05/reverse-compliance-or-as-proof-of.html">Reverse Compliance or "Logs as Proof of Incompetence?"</a>" tops the charts as well. It is about, <strong>"r</strong>everse compliance", which is a motivation to <em>purposefully</em> avoid technologies that have a chance of telling you that you are NOT in compliance. <li>My quick post on data leak 'prevention' ("<a href="http://chuvakin.blogspot.com/2008/05/in-passing-on-dlp.html">In Passing on DLP</a>") is popular as well. Indeed, DLP is a very interesting segment of security market and there is plenty of innovation happening there. <li>ISO17799/27002 might not be hot in the US, but discussing why it is not IS indeed hot. WTH? Well, <a href="http://chuvakin.blogspot.com/2008/05/why-is-iso2700x-hot-in-uk-but-not-in-us.html">"Why Is ISO2700x Hot in UK, but Not in US?"</a> is in Top5. <li>Again, people googling for "open source SIEM" have pushed this post (<a href="http://chuvakin.blogspot.com/2007/01/on-open-source-in-siem-and-log.html">this tiny blurb</a>) to top5. This ancient post from 2 years ago (!) years ago explains why an open source <a href="http://chuvakin.blogspot.com/search/label/SIEM">SIEM</a> will NOT emerge soon, if ever. </li></ol> <p>See you in June!</p> <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p> <ul> <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a>  <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a></li></ul> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:d616d4cf-aabb-415e-afd0-332828a25e0b" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>, <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>, <a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=lMueeI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=lMueeI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=61w2QI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=61w2QI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xCNdUI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xCNdUI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/303434819" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 02 Jun 2008 16:54:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/everse compliance">everse compliance</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/ancient post">ancient post</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/303434819/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - April 2008]]></title>
      <link>http://securityratty.com/article/03561cc94765b9761e7b27d9286fabf1</link>
      <guid>http://securityratty.com/article/03561cc94765b9761e7b27d9286fabf1</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit "stateless" and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>.</p> <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">"Security Warrior" blog</a> </strong>round-up of top 5 popular posts and topics.</p> <ol> <li>In a bizarre twist of fate, the #1 post this month is <u><a href="http://chuvakin.blogspot.com/2008/04/is-this-how-security-will-be-improved.html">this little blurb</a></u> on what will motivate the improvement of security in the future. So, is it lawsuits after all?  <li>Emerging from its well-deserved oblivion is the topic of anti-virus efficiency. Here are the posts: <a href="http://chuvakin.blogspot.com/2007/04/answer-to-my-antivirus-mystery-question.html">Answer to My Antivirus Mystery Question and a "Fun" Story</a>, <a href="http://chuvakin.blogspot.com/2007/04/more-on-anti-virus-and-anti-malware.html">More on Anti-virus and Anti-malware</a>, <a href="http://chuvakin.blogspot.com/2007/03/let-play-fun-game-here-scary-game.html">Let's Play a Fun Game Here ... A Scary Game</a>, <u><a href="http://chuvakin.blogspot.com/2007/04/original-anti-virus-test-paper-is-here.html">The Original Anti-Virus Test Paper is Here!</a></u>, <u><a href="http://chuvakin.blogspot.com/2007/04/protected-but-owned-my-little.html">Protected but Owned: My Little Investigation</a></u>, <a href="http://chuvakin.blogspot.com/2007/09/bit-more-on-av.html">A Bit More on AV</a>&nbsp; and <u><a href="http://chuvakin.blogspot.com/2007/05/closure-kind-of-to-anti-virus.html">Closure (Kind of) to the Anti-Virus Efficiency/Effectiveness Saga</a>.</u>  <li>Again this month, <a href="http://chuvakin.blogspot.com/search/label/poll">my logging polls</a> are super-hot: specifically, a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>) sits among the Top5 posts (closely behind is <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually look at).  <li>People, please stop googling for "open source SIEM." :-)&nbsp; Really! You are not going to find it, 'cause it doesn't exist (yes, <a href="http://www.ossim.net">OSSIM</a> exists, but I still doubt that it will gain <em>massive</em> adoption any time soon). In any case, <a href="http://chuvakin.blogspot.com/2007/01/on-open-source-in-siem-and-log.html">this tiny blurb</a> from 2 (!) years ago where I explain why an open source SIEM will NOT emerge soon&nbsp; is in Top5&nbsp; posts (weird indeed!). I have to tell you that the volume of google queries for "open source SIEM" that land on my blog has increased by a factor of 8 (!!!)&nbsp; over the course of last year.  <li>Finally, a Top5 item which did not surprise me this month: <a href="http://chuvakin.blogspot.com/search/label/RSA">my RSA impressions</a> are Top5 as well (<u><a href="http://chuvakin.blogspot.com/2008/04/rsa-2008-summary-and-reflections.html">this post</a></u> and <u><a href="http://chuvakin.blogspot.com/search/label/RSA">the whole&nbsp; RSA2008 coverage</a></u>)</li></ol> <p>See you in May!</p> <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p> <ul> <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a>  <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a></li></ul> <p>&nbsp;</p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:1ca1c5bc-da90-47c3-bff2-36ee830bba8b" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=r46GoH"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=r46GoH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=NzJG3H"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=NzJG3H" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/281891006" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 01 May 2008 18:17:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/top5">top5</category>
      <category domain="http://securityratty.com/tag/top5 posts">top5 posts</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/popular posts">popular posts</category>
      <category domain="http://securityratty.com/tag/source siem">source siem</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/281891006/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - March 2008]]></title>
      <link>http://securityratty.com/article/ebadef1c61c4668b955ab65c9a33f7f1</link>
      <guid>http://securityratty.com/article/ebadef1c61c4668b955ab65c9a33f7f1</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit "stateless" and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>.</p> <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">"Security Warrior" blog</a> </strong>round-up of top 5 popular posts and topics.</p> <ol> <li>This month <a href="http://chuvakin.blogspot.com/search/label/poll">my logging polls</a> are super-hot: specifically <a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">Logging Poll #6 "Which Logs Do You LOOK At?" Analysis</a> leads the Top5. Do people look at logs? Which ones? Check out <a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">the poll analysis</a>. <li>Somewhat predictably, PCI compliance is still all the rage. So, just like <a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">last month</a>, <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was propelled to a place in my Top5 popular posts list. It discusses the fact that there is no "easy list" of what you MUST do to comply.  <li>Also predictably, next up are again my Top11 logging lists:&nbsp; <a href="http://chuvakin.blogspot.com/2007/04/top-11-reasons-to-collect-and-preserve.html">Top 11 Reasons to Collect and Preserve Computer Logs</a> and&nbsp; <a href="http://chuvakin.blogspot.com/2007/07/top-11-reasons-to-look-at-your-logs.html">Top 11 Reasons to Look at Your Logs</a> (the third list, <a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a><u>, </u>was not quite that popular - I long argued that, sadly, few people care about log security <strong>yet</strong>). A new one was also added to the list: <a href="http://chuvakin.blogspot.com/2008/02/top-11-reasons-to-analyze-your-logs.html">Top 11 Reasons to Analyze Your Logs</a>.  <li>Surprisingly, my little impression from a <a href="http://www.cso-summit.ru/?page=program&amp;lang=eng">CSO Summit</a> (where I gave a <a href="http://www.slideshare.net/anton_chuvakin/1st-russian-cso-summit-trends-2008">keynote</a>) made it to Top5: <a href="http://chuvakin.blogspot.com/2008/03/data-theft-russian-style.html">Data Theft "Russian-Style"</a> Is your data stolen?&nbsp; Bad! Is it sold for $5 by the street vendors in Moscow? Super-bad! <li>Also surprisingly, one of my comments on a recent breach ("<a href="http://securosis.com/2008/03/18/picking-apart-the-hannaford-breach-what-might-have-happened/">On Hannaford Brothers Breach and PCI</a>") is in Top5. Newer comments are <a href="http://chuvakin.blogspot.com/2008/04/it-was-insider-sorry-we-are-idiots.html">here</a>.</li></ol> <p>See you in April!</p> <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p> <ul> <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a>  <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a></li></ul> <p>&nbsp;</p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:1ca1c5bc-da90-47c3-bff2-36ee830bba8b" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mjaTodG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mjaTodG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=BkRDF9G"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=BkRDF9G" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/262922921" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 02 Apr 2008 10:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/preserve computer logs">preserve computer logs</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/262922921/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - February 2008]]></title>
      <link>http://securityratty.com/article/365e5a14b0bfde16c26913f42ef9f999</link>
      <guid>http://securityratty.com/article/365e5a14b0bfde16c26913f42ef9f999</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p></p> <p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit "stateless" and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>.</p> <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">"Security Warrior" blog</a> </strong>round-up of top 5 popular posts and topics.</p> <ol> <li>Finally, one post I wrote this month bumped the "anti-virus saga" from the #1 popular spot: <a href="http://chuvakin.blogspot.com/2008/02/welcome-to-platform-club.html">Welcome to the Platform Club! :-)</a> post discusses requirements for a <a href="http://www.loglogic.com">log management platform</a> (and makes fun of some folks in the process ...) <li>Now pushed to the #2 spot, next is the topic of anti-virus efficiency. Here are the posts: <a href="http://chuvakin.blogspot.com/2007/04/answer-to-my-antivirus-mystery-question.html">Answer to My Antivirus Mystery Question and a "Fun" Story</a>, <a href="http://chuvakin.blogspot.com/2007/04/more-on-anti-virus-and-anti-malware.html">More on Anti-virus and Anti-malware</a>, <a href="http://chuvakin.blogspot.com/2007/03/let-play-fun-game-here-scary-game.html">Let's Play a Fun Game Here ... A Scary Game</a>, <u><a href="http://chuvakin.blogspot.com/2007/04/original-anti-virus-test-paper-is-here.html">The Original Anti-Virus Test Paper is Here!</a></u>, <u><a href="http://chuvakin.blogspot.com/2007/04/protected-but-owned-my-little.html">Protected but Owned: My Little Investigation</a></u>, <a href="http://chuvakin.blogspot.com/2007/09/bit-more-on-av.html">A Bit More on AV</a>&nbsp; and <u><a href="http://chuvakin.blogspot.com/2007/05/closure-kind-of-to-anti-virus.html">Closure (Kind of) to the Anti-Virus Efficiency/Effectiveness Saga</a></u>  <li>Next are again my Top11 logging lists:&nbsp; <a href="http://chuvakin.blogspot.com/2007/04/top-11-reasons-to-collect-and-preserve.html">Top 11 Reasons to Collect and Preserve Computer Logs</a> and&nbsp; <a href="http://chuvakin.blogspot.com/2007/07/top-11-reasons-to-look-at-your-logs.html">Top 11 Reasons to Look at Your Logs</a> (the third list, <a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a><u>, </u>was not quite that popular - I long argued that, sadly, few people care about log security <strong>yet</strong>). A new one was also added to the list: <a href="http://chuvakin.blogspot.com/2008/02/top-11-reasons-to-analyze-your-logs.html">Top 11 Reasons to Analyze Your Logs</a>. Check it out! <li>PCI compliance is still all the rage! So, <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was propelled to a place in my Top5 popular posts list. It discusses the fact that there is no "easy list" of what you MUST do to comply. <li><a href="http://chuvakin.blogspot.com/search/label/poll">My logging polls</a> are hot as well. Specifically, the analysis of my newest poll&nbsp; (<a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">Logging Poll #5 "Top Logging Challenges" Analysis</a>) is popular.</li></ol> <p>See you in March - I will continue to make logs popular, research new log analysis methods and make fun of some people (of course!) :-)&nbsp;&nbsp; </p> <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p> <ul> <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a>  <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a></li></ul> <p>&nbsp;</p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:5b30ed1b-eb44-41f5-bf0c-988acf65ebd8" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/monthly" rel="tag">monthly</a>, <a href="http://technorati.com/tags/chuvakin" rel="tag">chuvakin</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=N1j9NrF"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=N1j9NrF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=onUoXCF"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=onUoXCF" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/245047040" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 03 Mar 2008 08:50:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/logs popular">logs popular</category>
      <category domain="http://securityratty.com/tag/popular">popular</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/popular posts">popular posts</category>
      <category domain="http://securityratty.com/tag/anti-virus saga">anti-virus saga</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/245047040/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</source>
    </item>
    <item>
      <title><![CDATA[Annual Blog Round-Up - 2007]]></title>
      <link>http://securityratty.com/article/5a5b55d0c804c4fdd5966805f1417f69</link>
      <guid>http://securityratty.com/article/5a5b55d0c804c4fdd5966805f1417f69</guid>
      <description><![CDATA[If monthly, why not annual blog round-up? These are my top popular &quot;Security Warrior&quot; blog posts for 2007! To make this a competition of posts, I am removing the links to the main blog, search labels...]]></description>
      <content:encoded><![CDATA[<p>If monthly, why not annual blog round-up? These are my top popular <a href="http://www.securitywarrior.org">"Security Warrior" blog</a> posts for 2007! To make this a competition of posts, I am removing the links to the main blog, search labels (e.g. <a href="http://chuvakin.blogspot.com/search/label/log%20management">log management</a>, which was indeed one of the most popular resources on the blog) as well as grouping posts together in theme clusters.</p> <ol> <li>Same as during past few months, the "fallout" from being featured on a high-profile programming site continues to drive humongous loads of traffic which made this set of posts the most popular, even for the year.&nbsp; The topic that got such a huge boost was <strong>anti-virus efficiency</strong>. The posts are: <a href="http://chuvakin.blogspot.com/2007/04/answer-to-my-antivirus-mystery-question.html">Answer to My Antivirus Mystery Question and a "Fun" Story</a>, <a href="http://chuvakin.blogspot.com/2007/04/more-on-anti-virus-and-anti-malware.html">More on Anti-virus and Anti-malware</a>, <a href="http://chuvakin.blogspot.com/2007/03/let-play-fun-game-here-scary-game.html">Let's Play a Fun Game Here ... A Scary Game</a>, <u><a href="http://chuvakin.blogspot.com/2007/04/original-anti-virus-test-paper-is-here.html">The Original Anti-Virus Test Paper is Here!</a></u>, <u><a href="http://chuvakin.blogspot.com/2007/04/protected-but-owned-my-little.html">Protected but Owned: My Little Investigation</a> </u>as well as a final entry about my own switch away from mainstream major-vendor anti-virus tool: <a href="http://chuvakin.blogspot.com/2007/09/bit-more-on-av.html">A Bit More on AV</a>&nbsp; and <u><a href="http://chuvakin.blogspot.com/2007/05/closure-kind-of-to-anti-virus.html">Closure (Kind of) to the Anti-Virus Efficiency/Effectiveness Saga</a>.</u>  <li>Next by rank is a set of my <strong>Top11 lists</strong>:&nbsp; <a href="http://chuvakin.blogspot.com/2007/04/top-11-reasons-to-collect-and-preserve.html">Top 11 Reasons to Collect and Preserve Computer Logs</a> and&nbsp; <a href="http://chuvakin.blogspot.com/2007/07/top-11-reasons-to-look-at-your-logs.html">Top 11 Reasons to Look at Your Logs</a> (the third list, <a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a><u>, </u>was not quite that popular - I have long argued that, sadly, few people care about log security <strong>yet</strong>).  <li>Wow! I love, love, love the fact that my blog readers made my first <strong>Common Event Expression (CEE),</strong> post introducing this emerging log standard, (<a href="http://cee.mitre.org">official site</a> now live!) one of the most popular: <a href="http://chuvakin.blogspot.com/2007/04/finally-common-event-expression-cee-is.html">Finally, Common Event Expression (CEE) is Out!!!</a>. <a href="http://chuvakin.blogspot.com/search/label/CEE">My other CEE-related posts</a> are labeled <a href="http://chuvakin.blogspot.com/search/label/CEE">here</a>.  <li>Hurray to database logging (finally!) My posts related to <strong>database logging</strong> top the charts. Specifically, <a href="http://chuvakin.blogspot.com/2007/12/how-to-do-database-loggingmonitoring.html">How to Do Database Logging/Monitoring "Right"?</a> as well as its "prequels" :-) <a href="http://chuvakin.blogspot.com/2007/11/full-paper-on-database-log-management.html">Full Paper on Database Log Management Posted</a> and <a href="http://chuvakin.blogspot.com/2007/03/on-database-logging-and-auditing-teaser.html">On Database Logging and Auditing (Teaser + NOW Full Paper)</a>.  <li>Finally,<strong> security ROI</strong> saga that flared up mid-year is also among the most popular. Indeed, <a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">Security ROI Pile-Up!</a> post made it into Top5 (the related posts are: <a href="http://del.icio.us/anton18/security+ROI">The Entire Security ROI Blood Trail</a> and <a href="http://chuvakin.blogspot.com/2007/07/roi-rosi-rroi-and-harry-potter-tales.html">ROI, ROSI, RROI and Harry Potter Tales</a>). The rest of my ROI-related posts are labeled <a href="http://chuvakin.blogspot.com/search/label/ROI">here</a>.  <li>At the risk of destroying my math credibility, I will add an item #6 to my Top 5 list, again. This little post called <a href="http://chuvakin.blogspot.com/2007/01/on-open-source-in-siem-and-log.html">On Open Source in SIEM and Log Management</a> have also generated a lot of traffic and discussion. Indeed, <a href="http://www.loglogic.com/">log management</a> vs SIEM as well as reasons for a lack of a popular and complete open source <a href="http://www.loglogic.com/">log management</a> solution are fun topics!</li></ol> <p>See you in 2009! :-) </p> <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p> <ul> <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a>  <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a></li></ul> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:b7c234bd-6d80-45b8-a387-4620fead3c3a" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/annual" rel="tag">annual</a>, <a href="http://technorati.com/tags/2007" rel="tag">2007</a>, <a href="http://technorati.com/tags/review" rel="tag">review</a>, <a href="http://technorati.com/tags/round-up" rel="tag">round-up</a>, <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/chuvakin" rel="tag">chuvakin</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0PvfEFD"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0PvfEFD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=w3FqulD"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=w3FqulD" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/211319460" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 04 Jan 2008 10:16:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/round-up">round-up</category>
      <category domain="http://securityratty.com/tag/annual blog round-up">annual blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/security roi pile-up">security roi pile-up</category>
      <category domain="http://securityratty.com/tag/roi">roi</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/blog readers">blog readers</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/211319460/annual-blog-round-up-2007.html">Annual Blog Round-Up - 2007</source>
    </item>
  </channel>
</rss>
