<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: waters]]></title>
    <link>http://securityratty.com/tag/waters</link>
    <description></description>
    <pubDate>Mon, 05 May 2008 07:38:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Of Planes and Ships]]></title>
      <link>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</link>
      <guid>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</guid>
      <description><![CDATA[Tom Barnett is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.thomaspmbarnett.com/weblog/2008/09/column_121.html">Tom Barnett</a> is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the &quot;nail it to the wall&quot; quote at the end):</p><p><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">One of the main problems in counterterrorism today is that there are so many people and vehicles, and so much data and material, moving through globalization&#39;s myriad networks that it seems virtually impossible to track it all effectively. Nowhere has this problem been more acute than on the high seas.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">In 2006, Adm. Harry Ulrich, then U.S. commander of NATO Naval Forces Europe, decided to do something about it. Despite having virtually no resources, his dream was to transpose the global air-traffic control system onto sea traffic.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Worldwide, aircraft are transparent, because they&#39;re all required to carry an identification beacon that allows them to be tracked leaving and entering airports, and monitored between airports, by a global network of sensors. Act suspiciously and somebody&#39;s fighter aircraft will soon be on your tail.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">No such pervasive system currently exists globally for maritime traffic. While bigger ships carry an ID beacon similar to aircraft, without a shared monitoring network, that&#39;s like tracking only selected commercial jets and giving everyone else a pass.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">So Ulrich, upon taking command, asked a simple question: &quot;If we can do that in the air, why can&#39;t we do it on the sea?&quot; He made a point of pioneering his sea-traffic-control effort first inside the Mediterranean, where NATO&#39;s southern naval forces have historically been concentrated, but his real target was waters off Africa -- the most ungoverned maritime space in the world.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich knew the U. S. Navy couldn&#39;t do it alone, much less bring Africa&#39;s meager coast-guard-like navies up to snuff so they could do it on their own. So he quickly created a network of assets -- both public and private -- to manage that space, modeling his monitoring system on international air-traffic control.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich began stitching together a network of shore-based sensors ringing the Mediterranean. His naval command then began initial monitoring by tapping into the International Maritime Organization&#39;s existing Automated Identification System, transforming NATO&#39;s ability to track ship traffic in the Med.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Almost overnight, NATO went from tracking dozens of ships on the Mediterranean to thousands, and instead of getting the data sometimes up to 72 hours late, now the contacts were being tracked in one to five minutes -- to an accuracy within 50 feet on the earth&#39;s surface.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When the classic big-firm systems integrators told Ulrich it would be too costly to pull it off, the admiral turned to the Volpe Center in Cambridge, Massachusetts, a U.S. Department of Transportation research center. Instead of hundreds of millions of dollars, Ulrich&#39;s initial network cost $900,000. The shore-based receivers are small, roughly the size of a radar dish you might find on a pleasure craft.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The strength of the system is a function of its reach: the more countries join, the larger the shared operational picture. By the time Ulrich retired at the end of 2007, he had enlisted 32 countries throughout the Mediterranean, the North Atlantic, along the west coast of Africa, around the Black Sea, and in the Pacific. Today, the network continues to spread around the planet.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; font-size: 14px; line-height: 20px; "><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">With Ulrich&#39;s system in place, local police, coast guards, and border patrols catch most bad guys, obviating American military responses. As Harry told me for an article I wrote about his work in a fall 2007 issue of Esquire, </span><span style="font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;I don&#39;t do defense; I do security. When you talk defense, you talk containment and mutually assured destruction. When you talk security, you talk collaboration and networking. This is the future.&quot;</span></span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The admiral&#39;s legacy program, the Maritime Safety and Security Information System, earned the Volpe Center a prestigious &quot;Innovations in American Government&quot; award this month from Harvard University&#39;s Ash Institute for Democratic Governance and Innovation.</span></p></blockquote><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Security Collaboration + Networking &#160;= Federation. This is indeed the future - SAML came along just at the nick of time.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When you assume that to do access control you must have &quot;Complete Mediation&quot; in Saltzer and Schroeder&#39;s terms of the subject (users), the objects (data), the session, and the roles, then you are going to have an interesting life trying to deliver anything. And if you do it will mucho expensive.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">if you take the federated autonomous nodes approach, agree upon an attribute schema plus a protection model for same, and basic protocol, you are then free to move about the country. Security doesn&#39;t have to equal centralization or high cost. Get the attributes from point a to point b securely.</span></div>]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 19:04:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security architect">security architect</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/identification system">identification system</category>
      <category domain="http://securityratty.com/tag/initial network cost">initial network cost</category>
      <category domain="http://securityratty.com/tag/initial">initial</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/ulrich">ulrich</category>
      <category domain="http://securityratty.com/tag/time ulrich">time ulrich</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/of-planes-and-ships.html">Of Planes and Ships</source>
    </item>
    <item>
      <title><![CDATA[Wakeup Call for Risk Management]]></title>
      <link>http://securityratty.com/article/5c961827ce1d8ef57419fb5d2d847236</link>
      <guid>http://securityratty.com/article/5c961827ce1d8ef57419fb5d2d847236</guid>
      <description><![CDATA[Blogger: Dan Blum
With the crisis in financial markets still unfolding, it is important to draw what lessons we can from the experience. Since the roots of the crisis lie in a monumental failure of...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>With the crisis in financial markets still unfolding, it is important to draw what lessons we can from the experience. Since the roots of the crisis lie in a monumental failure of risk management, it’s important to understand more about what happened, and then draw some parallels to our business risk management and&nbsp; IT risk management situations.</p>

<p>The risk management failure in the housing market and on Wall Street had multiple interdependent dimensions:</p>

<ul><li><strong>Mortgage lenders abandoned long standing prudent loan practices</strong>. They made too many loans that buyers might not be able to repay. Exotic instruments like ARMs, option ARMs, and interest only loans proliferated. In many cases, all pretense of lending standards were abandoned, so-called “liar loans” approved.</li>

<li><strong>Capital was grossly over-leveraged</strong>. Mortgage lenders and other financial services packaged loans into securities, which they sold to raise capital to support more lending. Real capital reserve requirements to back loans were reduced. Of course, if borrowers could not repay loans, all or parts of the derivative securities would become worthless.</li>

<li><strong>Risk was aggregated at Fannie Mae, Freddie Mac, and mortgage loan insurance companies</strong>. These companies bought or insured some mortgage loans, providing something of a backstop should loans fail. Government sponsored enterprises (GSEs) Fannie and Freddie in turn became over-leveraged and securities that they sold were in turn repackaged in the murky brew of mortgage-backed securities called collateralized debt obligations (CDOs) and other exotic instruments returning generous yields. </li>

<li><strong>Non-Caveat Emptor.</strong> Institutional wealth funds and financial services firms who should have known better bought securities that had been deliberately structured to obfuscate risk. They bought securities they didn’t understand with buried tranches of toxic subprime loans..</li></ul>

<p>It was a great Ponzi scheme – one that kept working as long as housing prices were going up; the recipients of subprime loans could always flip that house to the next buyer. Everyone made money. As Chuck Prince of Citigroup famously put it during <a href="http://search.ft.com/ftArticle?sortBy=gadatearticle&amp;queryText=chuck+prince+dancing&amp;y=0&amp;aje=true&amp;x=0&amp;id=070710000610&amp;ct=0&amp;page=6&amp;nclick_check=1">a July, 2007 interview</a>: “So long as the music is playing, you’ve got to keep dancing. We’re still dancing.” But one month later, the music stopped. Since then, Citigroup and other financial institutions have taken massive writeoffs with more to come. Wall Street titans like Bear Sterns, Lehman Brothers, Merrill Lynch, and AIG have fallen or been bought out.</p>

<p>What can we learn from this risk management debacle?</p>

<p>As business risk managers and investors, we should ask questions like these:</p>

<ul><li><strong>Does the executive incentive structure of the company encourage managers to dance around risk?</strong> Many Wall Street firms paid senior managers 5 times their salary in bonuses tied to annual growth alone.</li>

<li><strong>Is the company over-leveraged?</strong> Is it borrowing too much money and betting it on ventures with uncertain outcomes?</li>

<li><strong>Are financial models used for risk management realistic?</strong> Earlier, I described the mortgage market of the past few years as a Ponzi scheme, where risk management models must have assumed prices would keep rising. Unlike the dotcom boom whose demise many predicted, very few in the industry foresaw the sharp declines to come in housing prices and sales volumes. Historically, the U.S. housing market has been a steadily rising one, but on the other hand the 2000s saw unprecedented rates of price increases. In reality, what goes up must come down. </li>

<li><strong>Has your company’s risk council ever performed worst case scenario analysis and built adequate reserves?</strong> In the days before economics emerged as a would-be “hard” deterministic science, business leaders may have been more cautious, more aware of and more accepting of uncertainty. Events like the Great Tulip Bubble came once in decades or centuries – not every few years. Note that legendary investor George Soros has proposed a Theory of Reflexivity that, if true, helps explain the recent extremes of boom and bust cycles. This theory holds that market participants model market behaviors based on self-interest, and for a time, their manipulations change the reality of the market – until gravitational forces bring it back to earth. Has the music of ephemeral success played to the backbeat of deterministic-sounding economic models gone to your heads and infected your risk management models? </li>

<li><strong>Are cost cutting efforts pursued blindly?</strong> Outsourcing and other forays into treacherous global waters may be giving away the crown jewels. Smart companies cut costs, but they do it in smart ways. Smart companies think like intelligence agencies as they parcel out work to different partners with varying levels of dependability, and they check on those partners.</li></ul>

<p>Risk management failures can also occur at the more technical level of IT security. As IT risk managers, we might ask questions like these:</p>

<ul><li><strong>Are the accounting and financial systems your IT department supports under adequate control?</strong> As Fred Cohen wrote in <a href="http://www.burtongroup.com/Client/Research/Document.aspx?cid=750">one of our documents</a>: “Many companies use computers to manage financial systems, and despite the Sarbanes-Oxley Act (SOX) claims about accounts being properly kept, there are many attacks on financial systems that remain. For example, most of the largest financial systems in the world running on common financial databases do not use <a href="http://en.wikipedia.org/wiki/Double-entry_bookkeeping">double-entry bookkeeping</a> and are thus susceptible to all manner of frauds by insiders.” We find it troubling that a prudent control dating back to the 12th century is going out of style in the name of convenience and cost cutting. Kind of like credit checking became anachronistic during the housing bubble, eh?</li>

<li><strong>Is the “separation” in your “separation of duty” (SoD) for real?</strong> Sure the SOX auditors are looking for SoD, and maybe you have different administrators with different accounts maintaining different systems or functions. But when they say Western civilization may be but one weak password from collapse they’re not lying. Look what happened to Sarah Palin’s email account! Weak and straggly SoD is a problem across all critical IT systems where deperimiterization and server consolidation may be bringing down protective barriers, identity management is weak, and strong process controls (e.g., where two people must sign on, one perform a critical operation such as backbone router reconfiguration, and the second observe) abandoned in the name of expediency. </li>

<li><strong>Are risks being aggregated to unacceptable levels in centralized control systems?</strong> There are many ways that risks aggregate within enterprise IT infrastructures as we pursue automation and cost cutting. Network risks aggregate when centralized domain name system control is implemented. Application risks aggregate when common infrastructure is shared among applications. And enterprises aggregate platform risks when they use low-assurance endpoints, authentication, and directory systems with single sign-on to access large numbers of resources and don’t separate high consequence systems. </li>

<li><strong>Non-caveat emptor:</strong> Has IT security really done the worst case consequence analysis, attack graphs, and vulnerability analysis to know when putting more eggs in a supposedly stronger basket aggregates risks to an unacceptable level? Or are you depending only on vendor claims about some black box appliance equivalent of a risk-obfuscated CDO security? Caveat emptor (buyer beware) again! (The good news is we’ll keep talking about promoting vendor and product rating systems so you don’t have to do all the detailed product analysis yourself, but that’s another post.)</li></ul>

<p>There are many parallels between the monumental risk management failure in the financial markets, and the probable weaknesses in our day to day business risk management and IT risk management. Abandonment of prudent practices for profit; excessive leverage and centralization; ill-constructed risk analysis models; risk obfuscation; and a failure of caveat emptor seem to be common problems. Please take this as a wakeup call to sharpen up the risk management thinking, process, and execution.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/397240912" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 06:11:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management debacle">risk management debacle</category>
      <category domain="http://securityratty.com/tag/risk management failure">risk management failure</category>
      <category domain="http://securityratty.com/tag/failure">failure</category>
      <category domain="http://securityratty.com/tag/risk management realistic">risk management realistic</category>
      <category domain="http://securityratty.com/tag/business risk management">business risk management</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management situations">risk management situations</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/397240912/wakeup-call-for.html">Wakeup Call for Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Magic Quadrant for IT Event Correlation and Analysis, 2007]]></title>
      <link>http://securityratty.com/article/73190514b58f80fbdcadffdaf0c59673</link>
      <guid>http://securityratty.com/article/73190514b58f80fbdcadffdaf0c59673</guid>
      <description><![CDATA[I often get asked that if the current self-decribed CEP vendors are not doing real CEP, in my opinon, who are the vendors in the CEP space
At the moment, event correlation and event analysisis...]]></description>
      <content:encoded><![CDATA[<p>I often get asked that if the current self-decribed CEP vendors are not doing &#8220;real CEP,&#8221; in my opinon, who are the vendors in the CEP space?</p>
<p>At the moment, event correlation and event analysis is Gartner&#8217;s closest magic quadrant (MQ)  that relates directly to complex event processing (and event processing in general).    </p>
<p style="text-align: center;"><a href="http://mediaproducts.gartner.com/reprints/microsoft/vol4/article6/153661_0001.png" target="_blank"><img class="aligncenter" style="vertical-align: middle;" src="http://mediaproducts.gartner.com/reprints/microsoft/vol4/article6/153661_0001.png" alt="" width="432" height="468" /></a></p>
<p>A number of our friends and colleagues would like to position CEP as BRE, BRMS, BPM, SOA, algo trading and just about every other technology under the sun, except event correlation!</p>
<p>In a nutshell, the state-of-the-state of CEP/EP is that a number of firms in the software industry have found some &#8220;uncharted magic quadrant waters&#8221; and are positioning themselves to be &#8220;chart worthy&#8221;. Instead of competing head on with the experienced players (event correlation and analysis) that have been in the event processing field for many years.   </p>
<p>As I have mentioned a few times here on The CEP Blog, if the current generation self-described CEP engines were leading the industry in event correlation and analysis (CEP&#8217;s core technology domain) they would be either be on Gartner&#8217;s Magic Quadrant for IT Event Correlation and Analysis, or possibly acquired by a one of these large giants in event processing to solve complex event processing and event correlation problems that remain, for the most part, still unsolved!</p>
]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 11:04:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/event correlation">event correlation</category>
      <category domain="http://securityratty.com/tag/solve complex event">solve complex event</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/analysis">analysis</category>
      <category domain="http://securityratty.com/tag/cep vendors">cep vendors</category>
      <category domain="http://securityratty.com/tag/current generation">current generation</category>
      <category domain="http://securityratty.com/tag/ongartners magic quadrant">ongartners magic quadrant</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <source url="http://www.thecepblog.com/2008/08/26/magic-quadrant-for-it-event-correlation-and-analysis-2007/">Magic Quadrant for IT Event Correlation and Analysis, 2007</source>
    </item>
    <item>
      <title><![CDATA[Follow the Yellow Brick Road]]></title>
      <link>http://securityratty.com/article/887593779bb99c69b570648c6cdcc8d6</link>
      <guid>http://securityratty.com/article/887593779bb99c69b570648c6cdcc8d6</guid>
      <description><![CDATA[Marc Adlerfollows on from Muddy Waters to The First Annual Fluffies for CEP where Marc also calls into question the transparency, credibility and accuracy of the various fluffy awards we see from...]]></description>
      <content:encoded><![CDATA[<p>Marc Adler follows on from <a title="Muddy Waters" rel="bookmark" href="http://www.thecepblog.com/2008/07/16/muddy-waters/"><span style="color: #105cb6;">Muddy Waters</span></a> to <a href="http://magmasystems.blogspot.com/2008/07/first-annual-fluffies-for-cep.html" target="_blank">The First Annual Fluffies for CEP</a> where Marc also calls into question the transparency, credibility and accuracy of the various fluffy &#8220;awards&#8221; we see from time-to-time.</p>
<p>When I discussed this openly with Waters in <a title="Muddy Waters" rel="bookmark" href="http://www.thecepblog.com/2008/07/16/muddy-waters/"><span style="color: #105cb6;">Muddy Waters</span></a> comments they kindly replied that &#8220;customers are loath to be a reference client for a vendor,&#8221;  like this fact somehow justifies having 600 people, most who have never actually used the software in practice, vote on how great it is.  </p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>Or, as Mark Adler pointed out in his well written blog post <a href="http://magmasystems.blogspot.com/2008/07/first-annual-fluffies-for-cep.html" target="_blank">The First Annual Fluffies for CEP</a> , a secretive &#8220;panel of renowned judge&#8221; is going to tell us, via Jolt, who has the better solution?  Holy Cow Batman!   Let me buy a nice layout in your magazine  or web site,  please, so &#8220;my software company&#8221; will be on the short list for the &#8220;the awards&#8221;.  </p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>All this smoke-and-mirrors. share-the-love, marketing reminds me of The Matrix a bit, where the world as we observe it, is a complete artificial construction, where most people in the Matrix believe they are &#8220;real&#8221; because they do not know that they really just a computer generated program designed to keep humans happy as they sleep in some cold goop with electrodes stuck up their you-know-what, really just bio-batteries insuring the light bill is paid.</p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>Or better yet, these fluffies are similar to most of the Webinars we see where there are questions from &#8220;the audience&#8221; but we know that most of these questions did not come from the &#8220;audience&#8221; - yet we all seem to continue &#8221;the  audience&#8221; myth just like Santa Claus and the Easter Bunny! </p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>The Easter Bunny, Santa Claus, the Tooth Fairy and the Fluffy Awards are real, if you want them to be real.  Just close your eyes and click your heels three times&#8230;.</p>
<blockquote><p>Follow the Yellow Brick Road. Follow the Yellow Brick Road.<br />
Follow, follow, follow, follow,<br />
Follow the Yellow Brick Road.<br />
Follow the Yellow Brick, Follow the Yellow Brick,<br />
Follow the Yellow Brick Road.</p></blockquote>
<blockquote><p>We&#8217;re off to see the Wizard, The Wonderful Wizard of Oz.<br />
You&#8217;ll find he is a whiz of a Wiz! If ever a Wiz! there was.<br />
If ever oh ever a Wiz! there was The Wizard of Oz is one because,<br />
Because, because, because, because, because.<br />
Because of the wonderful things he does.<br />
We&#8217;re off to see the Wizard. The Wonderful Wizard of Oz</p></blockquote>
]]></content:encoded>
      <pubDate>Sat, 19 Jul 2008 15:57:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/yellow brick">yellow brick</category>
      <category domain="http://securityratty.com/tag/yellow brick road">yellow brick road</category>
      <category domain="http://securityratty.com/tag/follow">follow</category>
      <category domain="http://securityratty.com/tag/wonderful wizard">wonderful wizard</category>
      <category domain="http://securityratty.com/tag/wizard">wizard</category>
      <category domain="http://securityratty.com/tag/awards">awards</category>
      <category domain="http://securityratty.com/tag/fluffy awards">fluffy awards</category>
      <category domain="http://securityratty.com/tag/wonderful">wonderful</category>
      <category domain="http://securityratty.com/tag/audience">audience</category>
      <source url="http://www.thecepblog.com/2008/07/19/follow-the-yellow-brick-road/">Follow the Yellow Brick Road</source>
    </item>
    <item>
      <title><![CDATA[NAPA Shows How the Government is Using Web 2.0]]></title>
      <link>http://securityratty.com/article/c2382eef0b0cdb073ef226ac74ecee5b</link>
      <guid>http://securityratty.com/article/c2382eef0b0cdb073ef226ac74ecee5b</guid>
      <description><![CDATA[Back in April, we attended a session at the FOSE conference that highlighted Web 2.0 usage in the public sector . We also found through a survey of government workers that 65% of government IT workers...]]></description>
      <content:encoded><![CDATA[<p>Back in April, we attended a session at the <a href="http://blog.sciencelogic.com/fose-session-web-20-for-the-public-sector/04/2008" target="_blank">FOSE conference that highlighted Web 2.0 usage in the public sector</a>. We also found <a href="http://blog.sciencelogic.com/web-20-adoption-by-the-federal-government-shouldnt-be-a-surprise/06/2008" target="_blank">through a survey of government workers</a> that 65% of government IT workers surveyed said that Web 2.0 tools are important to their operations. The overall message was that all IT, government included, have too many projects they could be taking on for the amount of resources they have. For much of the IT topics we covered in the survey, importance was high but actual deployment was lower.
<p>Dan Munz, project manager of the <a href="http://www.collaborationproject.org/" target="_blank">Collaboration Project</a> commented on <a href="http://www.collaborationproject.org/display/home/Collaboration+Project+Blog" target="_blank">the unique work</a> that the National Academy of Public Administration (NAPA) is doing to bring together government leaders. The Collaboration Project seeks to innovate across government not just down the silos and create a safe place for leaders to have discussions around innovation.
<p><strong><em>ScienceLogic:</em></strong> What is the National Academy of Public Administration?
<p><strong><em>Dan Munz:</em></strong> The Academy is an independent, non-partisan, non-profit organization dedicated to tackling government&#8217;s most complex challenges. We were founded in 1967 by James Webb, the NASA administrator who took us to the moon – he saw that he could consult the National Academy of Sciences for expert technical advice, but had no counterpart in government for expert management advice. That&#8217;s been our mission ever since.
<p><strong><em>ScienceLogic:</em></strong> What is the Collaboration Project? How long has it been around?
<p><strong><em>Dan Munz:</em></strong> The Collaboration Project is the Academy&#8217;s response to two parallel trends we see in government. The first is the government’s need to transform the way it does business. There is a strong demand for change out there driven by a number of challenges that are forcing the government to rethink its mission and structure. Challenges include a public disconnected from government; a multi-sector workforce and increasing reliance on contractors; financial instability; and new types of security threats, just to name a few. More and more, the challenges facing government reach across the traditional boundaries of agency and mission. But government isn&#8217;t configured to work that way.
<p>The second trend is the unprecedented opportunity collaborative technology offers to drive transformational change in government. Tools like blogs, wikis, and mashups are changing the way leaders think about problems. They&#8217;re focusing not on what they can do just within their offices or agencies, but what voices they need to pull together across government, non-profits, the general citizenry, and other stakeholders to solve these problems. The Collaboration Project’s goal is to encourage this type of thinking and empower leaders committed to use collaborative technology to:
<ul>
<li>strengthen citizen civic engagement;</li>
<li>enhance government transparency;</li>
<li>improve service delivery and operational efficiency; and</li>
<li>facilitate coordination and innovation within and between agencies.</li>
</ul>
<p><strong><em>ScienceLogic:</em></strong> Why focus on Web 2.0 in the government?
<p><strong><em>Dan Munz:</em></strong> The question of how web 2.0 will impact federal IT departments is a critical one. Our view is that &#8220;the era of big systems&#8221; is basically over. Things like disk space, bandwidth, and computing power are basically shifting from being assets to being commodities.
<p>There&#8217;s also a shift in expectations. People both inside and outside government – especially Gen-X and Gen-Y – are incredibly frustrated by being able to use lightning-fast apps like Flickr, YouTube, and Facebook <i>that don&#8217;t even live on their hard drives</i> while the government and other large organizations still operate clunky PCs, space-limited e-mail accounts, and sluggish e-mail servers.
<p>So aside from the opportunity for transformative leadership, the idea of web 2.0 at a government level is very appealing in terms of getting the most out of the IT infrastructure we already have, rather than embarking on costly, large-scale projects in an era of diminishing budgets.
<p><strong><em>ScienceLogic:</em></strong> How do you build a sense of community at the Collaboration Project?
<p><strong><em>Dan Munz:</em></strong> Some community feel emerges naturally, from a sense that mass collaboration really is a tool for &#8220;doing government&#8221; in a whole new way.
<p>The more formal community building mechanisms we have include <a href="http://www.collaborationproject.org" target="_blank">our web page</a>, where we share insights, news, case studies, and other content – The virtual space serves as an anchor for people, whether they&#8217;re experts or beginners, to learn about what we do.
<p>Finally, we are conducting an ongoing series of in-person meetings, usually featuring a leader who has harnessed collaborative technology in what we think is a truly revolutionary new way.
<p><strong><em>ScienceLogic:</em></strong> How do you hear about cool new government Web 2.0 projects?
<p><strong><em>Dan Munz:</em></strong> That&#8217;s a key question, because part of our mission is to inspire action by finding leaders who have succeeded and highlight their accomplishments. We&#8217;ve done that with folks like Kip Hawley, TSA, Molly O&#8217;Neill, EPA, and Jim Walker, Alabama DHS.
<p>We also feel that the Academy&#8217;s position as a &#8220;safe space&#8221; for leaders means that we&#8217;re a place people can turn to when they hear about an emerging trend or project and want some help making sense of it.
<p><strong><em>ScienceLogic:</em></strong> What are the most innovative uses of Web 2.0 technology you&#8217;ve seen in the government?
<p><strong><em>Dan Munz:</em></strong> It&#8217;s important to distinguish between agencies that are simply adjusting to the reality of web 2.0, and those that are &#8220;using&#8221; it. Getting a YouTube account for your agency, or putting some photos on Flickr, is a great first step, but we want to inspire leaders to really transform their normal ways of doing business. At the moment a few that come to mind are the EPA Puget Sound Mashup, ODNI&#8217;s Intellipedia, TSA IdeaFactory, the PTO Peer-to-Patent Project, and Virtual Alabama, to name a few.
<p>The <a href="http://www.fcw.com/print/22_5/features/151791-1.html" target="_blank">TSA launched the IdeaFactory</a> in February 2008. TSA set up a collaboration platform with commenting, voting, etc. to form communities in a way to bring people to consensus and <a href="http://www.collaborationproject.org/pages/viewpage.action?pageId=5668923&amp;navigatingVersions=true" target="_blank">offer ways to improve the agency&#8217;s performance</a>.
<p><strong><em>ScienceLogic:</em></strong> Do you see a difference between state and local versus federal adoption of Web 2.0?
<p><strong><em>Dan Munz:</em></strong> That&#8217;s a hard generalization to make – at all levels you see leaders who recognize the potential in this technology to bring new voices into the governance process.
<p><strong><em>ScienceLogic:</em></strong> What are the obstacles to Web 2.0 adoption by government agencies?
<p><strong><em>Dan Munz:</em></strong> The three main challenges that we see are in the areas of technology, culture, and policy/governance.
<p>The technology issue is probably the simplest to solve – it&#8217;s important to choose a technology that fits the problem you&#8217;re trying to solve, but these technologies are usually inexpensive and almost never very complex.
<p>The question of culture is harder, particularly given the way that baby boomers, gen-xers, and millenials are beginning to interact in the workforce. How do you gain acceptance and buy-in among groups that have very different comfort levels with collaborative tools and environments?
<p>Finally, the most daunting challenge might be the questions of policy and governance, if only because those are the things that most commonly prevent leaders from even dipping a toe in the waters of collaboration. Most of the policies, regulations, and statutes governing the way government does business don&#8217;t anticipate things like wikis, blogs, or instant messaging. One of our most important missions is helping leaders who just want to get to action navigate these obstacles.
<p><strong><em>ScienceLogic:</em></strong> Is there any advice you can give to government employees getting started with Web 2.0? Or any places you would point them to for more info?
<p><strong><em>Dan Munz:</em></strong> It&#8217;s shameless plug time! I&#8217;d of course point them to our web page, <a href="http://collaborationproject.org/">collaborationproject.org</a>, where, among other things, we&#8217;ve collected a case library of over 40 instances of collaborative technology being used in the government and non-profit sectors. The library is growing every day and is a sort of &#8220;database of record&#8221; for what is and isn&#8217;t working in terms of collaborative government. I think that would be a great place to start for anyone looking to get started but not really knowing the way.
<p>In terms of advice, the best thing to say is that, once you&#8217;ve settled on a problem you want to solve and an audience you want to reach out to, <b>just do it</b>! We believe strongly that there are a lot of organizational and leadership issues that still need to be addressed regarding collaboration in government, but our biggest mantra is about getting leaders to action. The most successful projects we&#8217;ve seen are ones that try something daring and new, and discover the true power of what they&#8217;ve done as it catches on more and more widely.</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=NAPA+Shows+How+the+Government+is+Using+Web+2.0&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fnapa-shows-how-the-government-is-using-web-20%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 16:45:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/web page">web page</category>
      <category domain="http://securityratty.com/tag/government web">government web</category>
      <category domain="http://securityratty.com/tag/collaboration">collaboration</category>
      <category domain="http://securityratty.com/tag/mass collaboration">mass collaboration</category>
      <category domain="http://securityratty.com/tag/collaboration project seeks">collaboration project seeks</category>
      <category domain="http://securityratty.com/tag/government employees">government employees</category>
      <category domain="http://securityratty.com/tag/enhance government transparency">enhance government transparency</category>
      <source url="http://blog.sciencelogic.com/napa-shows-how-the-government-is-using-web-20/07/2008">NAPA Shows How the Government is Using Web 2.0</source>
    </item>
    <item>
      <title><![CDATA[Muddy Waters]]></title>
      <link>http://securityratty.com/article/082c0b6d5773aacfab25e87aedd3737a</link>
      <guid>http://securityratty.com/article/082c0b6d5773aacfab25e87aedd3737a</guid>
      <description><![CDATA[In Waters Rankings 2008 , Waters stirs the mud and confusion in the CEP/EP community by having their constituents vote on both an ESP solution and an CEP solution set, but giving both awards to...]]></description>
      <content:encoded><![CDATA[<p>In <a href="http://www.watersonline.com/public/showPage.html?page=800767" target="_blank">Waters Rankings 2008</a>, Water&#8217;s stirs the mud and confusion in the CEP/EP community by having their constituents vote on both an ESP solution and an CEP solution set, but giving both awards to vendors with stream processing (ESP) engines.   </p>
<p>The two CEP/ESP related Water&#8217;s categories were, <em>Best Streaming Data Management Solution</em> and <em>Best Complex Event Processing Solution.    </em>Water&#8217;s awards <em>Best Streaming Data Management Solution </em>to data/event stream processing company StreamBase; and then awards <em>Best Complex Event Processing Solution </em>to Oracle&#8217;s BEA product, which is built on top of another data/event stream processing engine.  Confused?   </p>
<p>Alexander Alves,  currently employed by Oracle, previously having worked for BEA Systems, in <a title="Permanent Link: Best Complex Event Processing Solution" rel="bookmark" href="http://adcalves.wordpress.com/2008/07/15/best-complex-event-processing-solution/">Best Complex Event Processing Solution</a>, observes:</p>
<blockquote><p>&#8220;Regardless, I find it intriguing that Waters not only does not state the differences between the categories, but also uses the term CEP several times in the SDMS category.</p>
<p>I guess the verdict is that there is still confusion amongst the experts regarding event and stream processing… And that both products must be very good.&#8221;</p></blockquote>
<p>Of course, Alex must be politically correct, and rightly so, since he works for Oracle/BEA and Water&#8217;s gave them an award.  But on what tangible, objective basis for <em>Best Complex Event Processing Solution?</em></p>
<p>According to our 2007 survey, <a title="CEP/EP Reference Customers 2005-2007" rel="bookmark" href="http://www.thecepblog.com/2007/12/29/cepep-reference-customers-2005-2007/"><span style="color: #105cb6;">CEP/EP Reference Customers 2005-2007</span></a>, BEA was in last place based on public CEP/EP reference clients.  </p>
<p>Waters&#8217; award  for <em>Best Streaming Data Management Solution </em>to StreamBase is a much more credible.   Congratulations StreamBase.   Most would agree that StreamBase is a streaming data management solution (SDMS), but so are Apama and Coral8 (and BEA etc etc).   </p>
<p>Waters simply muddies the water, unfortunately.  </p>
]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 06:50:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/waters">waters</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/data management solution">data management solution</category>
      <category domain="http://securityratty.com/tag/awards">awards</category>
      <category domain="http://securityratty.com/tag/waters awards">waters awards</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/esp solution">esp solution</category>
      <category domain="http://securityratty.com/tag/waters rankings">waters rankings</category>
      <source url="http://www.thecepblog.com/2008/07/16/muddy-waters/">Muddy Waters</source>
    </item>
    <item>
      <title><![CDATA[Taking a second look at Rohati]]></title>
      <link>http://securityratty.com/article/6473a18d588db2e7115028a3818a3bea</link>
      <guid>http://securityratty.com/article/6473a18d588db2e7115028a3818a3bea</guid>
      <description><![CDATA[Last week in response to Richard Stiennon's glowing write up , I questioned what it is exactly that Rohati does. Well someone from Rohati must have seen it and I was contacted by the Rohati team and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Last week in response to<a href="http://www.networkworld.com/community/node/28837"> Richard Stiennon's glowing write up</a>, <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/if-rohati-is-ki.html">I questioned</a> what it is exactly that Rohati does. Well someone from Rohati must have seen it and I was contacted by the Rohati team and offered a peek and a deep explanation of exactly what Rohati does.&nbsp; So today I had a chance to speak with Shane Buckley, CEO, Prashant Ghandi VP of product management and strategy and Steven Wastie, VP of marketing.&nbsp; I was impressed that such a triumvirate of power players from the Rohati team took the time to speak to me.&nbsp; But I guess after I wrote what I did, it was followed up by <a href="http://securityuncorked.squarespace.com/security-uncorked/2008/6/15/network-based-entitlement-a-rose-by-any-other-name.html">JJ writing her article</a> on it and than <a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-june-17-2008">Rothman piling on</a> with his own two cents.&nbsp; </p>

<p><a onclick="window.open(this.href, '_blank', 'width=800,height=617,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/06/20/rohati_2.png"><img title="Rohati_2" height="231" alt="Rohati_2" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/06/20/rohati_2.png" width="300" border="0" style="FLOAT: right; MARGIN: 0px 0px 5px 5px" /></a> Give the Rohati team credit for recognizing the power of blogs to influence the influencer and reaching out to stem the tide.&nbsp; It just goes to show you how far blogging has come. But enough about the power of blogs, lets talk about Rohati.</p>

<p>The best way for me to describe Rohati is that it is layer 7 ACLs to control access to applications.&nbsp; Where we already have security at the perimeter and at the edge, Rohati is about controlling access at the server/application.&nbsp; The diagram on the left (click on it to get a bigger version), is a good illustration of how Rohati works. By integrating with LDAPs Rohati can assign you an access policy to any application.&nbsp; Based upon that Rohati gives a very fine grain level of access control at the application layer.&nbsp; It acts as a proxy to the app server for both regular and encrypted traffic.&nbsp; Because the ACLs are on the Rohati box itself, there really is not any integration with switches per say and so no integration worries.</p>

<p>The only problem is that the Rohati box has to be able to handle the traffic flow.&nbsp; Hence the box is a big honker.&nbsp; The cheap one is about 20k list I believe and the industrial size version is 80k. This product is aimed squarely at the data center space and is sold through channels. </p>

<p>Will Rohati succeed.&nbsp; Yes, I think it will.&nbsp; I think they have taken a unique approach to a security issue that will continue to grow in years to come.&nbsp; Application access is an area that I think is still up and coming.&nbsp; In a period of nothing is ever new in security, the Rohati team seems to have found something that has not been done before in a packaged dedicated way like this.&nbsp; If nothing else, with all of the ex-Cisco folks there, Cisco will eat its young and buy the technology back in.</p>

<p>We will watch Rohati's progress in the months to come.&nbsp; At the very least, it seems they are blog savvy enough to navigate the waters of social media.&nbsp; Maybe they will start their own blog soon. </p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/34d1a82e-ac7c-4b2a-93de-e36fb04203ba/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=34d1a82e-ac7c-4b2a-93de-e36fb04203ba" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Thu, 19 Jun 2008 20:33:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rohati">rohati</category>
      <category domain="http://securityratty.com/tag/rohati team credit">rohati team credit</category>
      <category domain="http://securityratty.com/tag/rohati team">rohati team</category>
      <category domain="http://securityratty.com/tag/describe rohati">describe rohati</category>
      <category domain="http://securityratty.com/tag/ldaps rohati">ldaps rohati</category>
      <category domain="http://securityratty.com/tag/rohati box">rohati box</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/application layer">application layer</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/taking-a-second.html">Taking a second look at Rohati</source>
    </item>
    <item>
      <title><![CDATA[Taking a second look at Rohati]]></title>
      <link>http://securityratty.com/article/8cd98e832330dcae9c2a3d41890525b1</link>
      <guid>http://securityratty.com/article/8cd98e832330dcae9c2a3d41890525b1</guid>
      <description><![CDATA[Last week in response to Richard Stiennon's glowing write up , I questioned what it is exactly that Rohati does. Well someone from Rohati must have seen it and I was contacted by the Rohati team and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Last week in response to<a href="http://www.networkworld.com/community/node/28837"> Richard Stiennon's glowing write up</a>, <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/if-rohati-is-ki.html">I questioned</a> what it is exactly that Rohati does. Well someone from Rohati must have seen it and I was contacted by the Rohati team and offered a peek and a deep explanation of exactly what Rohati does.&nbsp; So today I had a chance to speak with Shane Buckley, CEO, Prashant Ghandi VP of product management and strategy and Steven Wastie, VP of marketing.&nbsp; I was impressed that such a triumvirate of power players from the Rohati team took the time to speak to me.&nbsp; But I guess after I wrote what I did, it was followed up by <a href="http://securityuncorked.squarespace.com/security-uncorked/2008/6/15/network-based-entitlement-a-rose-by-any-other-name.html">JJ writing her article</a> on it and than <a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-june-17-2008">Rothman piling on</a> with his own two cents.&nbsp; </p>

<p><a href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/06/19/rohati.gif"><img title="Rohati" height="231" alt="Rohati" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/06/19/rohati.gif" width="300" border="0" style="FLOAT: right; MARGIN: 0px 0px 5px 5px" /></a> Give the Rohati team credit for recognizing the power of blogs to influence the influencer and reaching out to stem the tide.&nbsp; It just goes to show you how far blogging has come. But enough about the power of blogs, lets talk about Rohati.</p>

<p>The best way for me to describe Rohati is that it is layer 7 ACLs to control access to applications.&nbsp; Where we already have security at the perimeter and at the edge, Rohati is about controlling access at the server/application.&nbsp; The diagram on the left (click on it to get a bigger version), is a good illustration of how Rohati works. By integrating with LDAPs Rohati can assign you an access policy to any application.&nbsp; Based upon that Rohati gives a very fine grain level of access control at the application layer.&nbsp; It acts as a proxy to the app server for both regular and encrypted traffic.&nbsp; Because the ACLs are on the Rohati box itself, there really is not any integration with switches per say and so no integration worries.</p>

<p>The only problem is that the Rohati box has to be able to handle the traffic flow.&nbsp; Hence the box is a big honker.&nbsp; The cheap one is about 20k list I believe and the industrial size version is 80k. This product is aimed squarely at the data center space and is sold through channels. </p>

<p>Will Rohati succeed.&nbsp; Yes, I think it will.&nbsp; I think they have taken a unique approach to a security issue that will continue to grow in years to come.&nbsp; Application access is an area that I think is still up and coming.&nbsp; In a period of nothing is ever new in security, the Rohati team seems to have found something that has not been done before in a packaged dedicated way like this.&nbsp; If nothing else, with all of the ex-Cisco folks there, if nothing else Cisco will eat its young and buy the technology back in.</p>

<p>We will watch Rohati's progress in the months to come.&nbsp; At the very least, it seems they are blog savvy enough to navigate the waters of social media.&nbsp; Maybe they will start their own blog soon. </p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/34d1a82e-ac7c-4b2a-93de-e36fb04203ba/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=34d1a82e-ac7c-4b2a-93de-e36fb04203ba" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=kBt7Rt"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=kBt7Rt" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=h6I1RI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=h6I1RI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=QOyNKI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=QOyNKI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=AB2KYI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=AB2KYI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=BpPKxI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=BpPKxI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=t5Hrei"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=t5Hrei" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=96guNi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=96guNi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/315941778" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 19 Jun 2008 19:33:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rohati">rohati</category>
      <category domain="http://securityratty.com/tag/rohati team credit">rohati team credit</category>
      <category domain="http://securityratty.com/tag/rohati team">rohati team</category>
      <category domain="http://securityratty.com/tag/describe rohati">describe rohati</category>
      <category domain="http://securityratty.com/tag/ldaps rohati">ldaps rohati</category>
      <category domain="http://securityratty.com/tag/rohati box">rohati box</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/application layer">application layer</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/315941778/taking-a-second.html">Taking a second look at Rohati</source>
    </item>
    <item>
      <title><![CDATA[Contributing To Open Source Software Security]]></title>
      <link>http://securityratty.com/article/04630345d95c997a99d8d781a3b761d6</link>
      <guid>http://securityratty.com/article/04630345d95c997a99d8d781a3b761d6</guid>
      <description><![CDATA[Written by Will Drewry

From operating systems to web browsers , open source software plays a critical role in the operation of the Internet. The security of open source software is therefore quite...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Written by Will Drewry</span><br /><br />From <a id="t82-" title="operating systems" href="http://www.linux.org/" target="_blank">operating systems</a> to <a id="zafu" title="web browsers" href="http://www.mozilla.org/" target="_blank">web browsers</a>, open source software plays a critical role in the operation of the Internet. The security of open source software is therefore quite important, as it often interacts with personal information -- ranging from credit card numbers to medical records -- that needs to be kept safe. There has been a long-lived discussion on whether open source software is inherently more secure than closed source software.  While popular opinion has begun to tilt in favor of openness, there are still arguments for both sides.  Instead of diving into those treacherous waters (or giving weight to the idea of "inherent security"), I'd like to focus on the fruits of this extensive discussion.  In particular, David A. Wheeler laid out a "bottom line" in his <a id="ldw." href="http://www.dwheeler.com/secure-programs/Secure-Programs-HOWTO/open-source-security.html">Secure      Programming for Linux and Unix HOWTO</a> which applies to both open and closed source software. It predicates real security in software on three actions:<br /><ol><br /><li><i>people need to actually review the code</i></li><br /><li><i>developers/reviewers need to know how to write secure code<br /></i></li><br /><li><i>once found, security problems need to be fixed quickly, and their                                  fixes distributed quickly</i></li><br /></ol><br />While distilling anything down to three steps makes it seem easy, this isn't necessarily the case.  Given how important open source software is to Google, we've attempted to contribute to this bottom line.  As Chris <a title="post" href="http://googleonlinesecurity.blogspot.com/2007/10/auditing-open-source-software.html" id="u6ym">said before</a>, our engineers are encouraged to contribute both software and time to open source efforts.  We <a id="m0o9" href="http://www.google.com/search?hl=en&amp;q=%22Google+Security+Team%22+CVE&amp;btnG=Search">regularly submit</a> the results of our automated and manual security analysis of open source software back to the community, including related software engineering time. In addition, our engineering teams frequently release software under open source licenses. This software was written either with security in mind, such as with <a id="abc0" href="http://code.google.com/p/bunny-the-fuzzer/">security testing                                        <br />tools</a>, or by engineers well-versed in the <a id="ouhv" href="http://groups.google.com/group/Google-Web-Toolkit/web/security-for-gwt-applications">security        challenges</a> of their project.<br /><br />These efforts leave one area completely unaddressed -- getting security problems fixed quickly, and then getting those fixes distributed quickly.  It has been unclear how to best resolve this issue.  There is no centralized security authority for open source projects, and operating system distribution publishers are the best bet for getting updates to the highest number of users.  Even if users can get updates in this manner, how should a security researcher contact a particular project's author?  If there's a potential, security-related issue, who can help evaluate the risk for a project?  What resources are there for projects that have been compromised, but have no operational security background? <br /><br />I'm proud to announce that Google has sponsored participation in oCERT, the <a title="open source computer emergency response team" href="http://ocert.org/" id="xji8">open source computer emergency response team</a>.  oCERT is a volunteer workforce of security professionals from the open source community with the goal of providing security vulnerability mediation and incident response services to open source projects.  It will strive to contact software authors with all security reports and aid in debugging and patching, especially in cases where the author, or the reporter, doesn't have a background in security.  Reliable contacts for projects, publishers, and vendors will be maintained where possible and used for notification when issues arise and fixes are available for mediated issues.  Additionally, oCERT will aid projects of any size with responses to security incidents, such as server compromises. <br /><br />It is my hope that this initiative will not only aid in remediating security issues in a timely fashion, but also provide a means for additional security contributions to the open source community.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=BOlcTH"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=BOlcTH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=MUs7Dh"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=MUs7Dh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/284121180" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 05 May 2008 07:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/source software">source software</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/additional security contributions">additional security contributions</category>
      <category domain="http://securityratty.com/tag/background">background</category>
      <category domain="http://securityratty.com/tag/operational security background">operational security background</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/security vulnerability mediation">security vulnerability mediation</category>
      <category domain="http://securityratty.com/tag/manual security analysis">manual security analysis</category>
      <source url="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~3/284121180/contributing-to-open-source-software.html">Contributing To Open Source Software Security</source>
    </item>
    <item>
      <title><![CDATA[Contributing To Open Source Software Security]]></title>
      <link>http://securityratty.com/article/c49b09364dc4b70b5a0ef82c985b5547</link>
      <guid>http://securityratty.com/article/c49b09364dc4b70b5a0ef82c985b5547</guid>
      <description><![CDATA[Written by Will Drewry

From operating systems to web browsers , open source software plays a critical role in the operation of the Internet. The security of open source software is therefore quite...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Written by Will Drewry</span><br /><br />From <a id="t82-" title="operating systems" href="http://www.linux.org/" target="_blank">operating systems</a> to <a id="zafu" title="web browsers" href="http://www.mozilla.org/" target="_blank">web browsers</a>, open source software plays a critical role in the operation of the Internet. The security of open source software is therefore quite important, as it often interacts with personal information -- ranging from credit card numbers to medical records -- that needs to be kept safe. There has been a long-lived discussion on whether open source software is inherently more secure than closed source software.  While popular opinion has begun to tilt in favor of openness, there are still arguments for both sides.  Instead of diving into those treacherous waters (or giving weight to the idea of "inherent security"), I'd like to focus on the fruits of this extensive discussion.  In particular, David A. Wheeler laid out a "bottom line" in his <a id="ldw." href="http://www.dwheeler.com/secure-programs/Secure-Programs-HOWTO/open-source-security.html">Secure      Programming for Linux and Unix HOWTO</a> which applies to both open and closed source software. It predicates real security in software on three actions:<br /><ol><br /><li><i>people need to actually review the code</i></li><br /><li><i>developers/reviewers need to know how to write secure code<br /></i></li><br /><li><i>once found, security problems need to be fixed quickly, and their                                  fixes distributed quickly</i></li><br /></ol><br />While distilling anything down to three steps makes it seem easy, this isn't necessarily the case.  Given how important open source software is to Google, we've attempted to contribute to this bottom line.  As Chris <a title="post" href="http://googleonlinesecurity.blogspot.com/2007/10/auditing-open-source-software.html" id="u6ym">said before</a>, our engineers are encouraged to contribute both software and time to open source efforts.  We <a id="m0o9" href="http://www.google.com/search?hl=en&amp;q=%22Google+Security+Team%22+CVE&amp;btnG=Search">regularly submit</a> the results of our automated and manual security analysis of open source software back to the community, including related software engineering time. In addition, our engineering teams frequently release software under open source licenses. This software was written either with security in mind, such as with <a id="abc0" href="http://code.google.com/p/bunny-the-fuzzer/">security testing                                        tools</a>, or by engineers well-versed in the <a id="ouhv" href="http://groups.google.com/group/Google-Web-Toolkit/web/security-for-gwt-applications">security        challenges</a> of their project.<br /><br />These efforts leave one area completely unaddressed -- getting security problems fixed quickly, and then getting those fixes distributed quickly.  It has been unclear how to best resolve this issue.  There is no centralized security authority for open source projects, and operating system distribution publishers are the best bet for getting updates to the highest number of users.  Even if users can get updates in this manner, how should a security researcher contact a particular project's author?  If there's a potential, security-related issue, who can help evaluate the risk for a project?  What resources are there for projects that have been compromised, but have no operational security background? <br /><br />I'm proud to announce that Google has sponsored participation in oCERT, the <a title="open source computer emergency response team" href="http://ocert.org/" id="xji8">open source computer emergency response team</a>.  oCERT is a volunteer workforce of security professionals from the open source community with the goal of providing security vulnerability mediation and incident response services to open source projects.  It will strive to contact software authors with all security reports and aid in debugging and patching, especially in cases where the author, or the reporter, doesn't have a background in security.  Reliable contacts for projects, publishers, and vendors will be maintained where possible and used for notification when issues arise and fixes are available for mediated issues.  Additionally, oCERT will aid projects of any size with responses to security incidents, such as server compromises. <br /><br />It is my hope that this initiative will not only aid in remediating security issues in a timely fashion, but also provide a means for additional security contributions to the open source community.<div class="feedflare">
<a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=khctcBYr"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?d=41" border="0"></img></a> <a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=xXwmGswO"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?i=xXwmGswO" border="0"></img></a>
</div><img src="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~4/-DwFl8sEKd0" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 05 May 2008 07:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/source software">source software</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/additional security contributions">additional security contributions</category>
      <category domain="http://securityratty.com/tag/background">background</category>
      <category domain="http://securityratty.com/tag/operational security background">operational security background</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/security vulnerability mediation">security vulnerability mediation</category>
      <category domain="http://securityratty.com/tag/manual security analysis">manual security analysis</category>
      <source url="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/-DwFl8sEKd0/contributing-to-open-source-software.html">Contributing To Open Source Software Security</source>
    </item>
  </channel>
</rss>
