<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: optimal]]></title>
    <link>http://www.securityratty.com/tag/optimal</link>
    <description></description>
    <pubDate>Fri, 11 Apr 2008 09:44:59 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Hosting Meets the Cloud Debate Part II]]></title>
      <link>http://www.securityratty.com/article/3a3393b304f09ea17d212e2f5b730d65</link>
      <guid>http://www.securityratty.com/article/3a3393b304f09ea17d212e2f5b730d65</guid>
      <description><![CDATA[I have to say that Part II of this session was much anticipated after the lively interaction yesterday. It turned out to be less of a debate and more like a fireside chat. (image from pro.corbis.com...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="220" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/11/clip-image0024.jpg" width="323" align="left" border="0" />I have to say that Part II of this session was much anticipated after the lively interaction yesterday. It turned out to be less of a debate and more like a fireside chat. <a href="http://pro.corbis.com/images/CB042667.jpg?size=572&amp;uid=%7bDA13F798-FDA1-4B54-BFA9-4B15492E024F%7d" target="_blank">(image from pro.corbis.com)</a></p>
<p>The analysts paired up today:   <br />Antonio Piraino (<a href="http://www.t1r.com/" target="_blank">Tier1 Research</a>)    <br /><a href="http://the451group.com/about/bio_detail.php?eid=113" target="_blank">William Fellows</a> (<a href="http://the451group.com/" target="_blank">The 451 Group</a>)</p>
<p><em>My usual disclaimers on live-blogging: doesn&#8217;t include everything covered (just what was most interesting to me) and had to paraphrase some answers because I simply cannot type that fast. </em></p>
<p><strong>Quick definition of Cloud Computing     <br /></strong><strong>WF:</strong> The cloud is a continuum of grid, virtualization and utility done right. It is about provisioning services instead of servers; flexible computing instead of fixed assets. Done right, the cloud abstracts users from the complexity of grid. <a href="http://www.the451group.com/images/content/ice/ice_iceberg.jpg">Cloud computing is IT as a service</a>. Cloud computing is the Third Way &#8211; not entirely in-house or outsourced, but an optimized hybridized version of both. In light of the Goldman Sachs report out resetting IT spending forecast from up 6% to down 1%, don&#8217;t underestimate the ability for enterprises to move from capex to opex by buying cloud computing instead of building it themselves.</p>
<p>The 451 Group conducted a survey on cloud computing in March, and then revisited it a month ago. Some interesting results:</p>
<ul>
<li>84% have no plans to develop an internal cloud. 5% had no answer to this question. And for the 10% who did answer &#8211; the uses for a private/internal cloud were the same as those for a public cloud. </li>
<li>Top 6 vendors they look to help them develop an internal cloud: <a href="http://www.alleyinsider.com/2008/11/microsoft-s-smart-cloud-catch-up-plan-three-years-of-free-software-msft-" target="_blank">Microsoft</a>, <a href="http://topnews.in/ibm-expand-its-cloud-computing-efforts-285364" target="_blank">IBM</a>, Cisco, HP, Oracle, VMware </li>
</ul>
<p><strong><em>Is it all &#8220;upside&#8221; when it comes to cloud computing?       <br /></em></strong><strong>     <br />WF:</strong> Watch out for the Trojan horse, the red flag. What about the software needed to manage all this stuff? Any management software needs to take a holistic approach to solve the problem.</p>
<p><strong>AP:</strong> Increased management requirements and capability &#8211; this is actually a great story for managed hosters who can hold your hand while getting you up into the cloud. Hosters alleviate the pain points, and this is why we&#8217;re going to see continued growth and focus in the managed hosting sector.</p>
<p><strong>WF:</strong> I would argue that they&#8217;re too expensive. <a href="http://tech.blorge.com/Structure:%20/2008/10/25/amazons-ec2-cloud-moves-into-production/" target="_blank">Look at Amazon</a> &#8211; 10 cents a hit adds up.</p>
<p><strong>AP:</strong> It&#8217;s almost impossible to do an apples-to-apples comparison between cloud providers. One reason is that they charge differently. I&#8217;d say that when you&#8217;re talking about the big cloud providers, you are right &#8211; that they are expensive over the long-term, but for use in the short-term, they can be optimal.</p>
<p><strong>WF:</strong> The cloud is setting big expectations. Can IT deliver? It&#8217;s nice to talk about &#8220;shared resources for the greater good&#8221; but in any organization, you will still run into issues of power and control! Plus it&#8217;s still early days for resolution of regulatory issues and compliance around the cloud.</p>
<p><strong>Final Thoughts</strong></p>
<p><strong>AP:</strong> Think of the opportunities of using cloud computing resources in the areas of testing and pre-production &#8211; short-term use/environment (quick up/quick down), inexpensive, opex not capex. We&#8217;re already seeing the cloud fostering much innovation.</p>
<p><strong>WF:</strong> &#8220;It&#8217;s okay to fall in love with the term.&#8221; It is real but keep the expectations lower and realistic.</p>
<p><strong>AP:</strong> I agree with you. The reality is that the cloud is driving a very fundamental underlying platform change. This is not just a term or something that will fall out of fashion. There&#8217;s a real need to build trust in the cloud and leveraging shared resources in this way &#8211; so use the cloud computing term cautiously; don&#8217;t abuse it and make the cloud seem like IT&#8217;s new toy.</p>
]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 18:35:55 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/cloud">cloud</category>
      <category domain="http://www.securityratty.com/tag/public cloud">public cloud</category>
      <category domain="http://www.securityratty.com/tag/cloud providers">cloud providers</category>
      <category domain="http://www.securityratty.com/tag/cloud abstracts users">cloud abstracts users</category>
      <category domain="http://www.securityratty.com/tag/privateinternal cloud">privateinternal cloud</category>
      <category domain="http://www.securityratty.com/tag/internal cloud">internal cloud</category>
      <category domain="http://www.securityratty.com/tag/term">term</category>
      <category domain="http://www.securityratty.com/tag/pre-production short-term useenvironment">pre-production short-term useenvironment</category>
      <category domain="http://www.securityratty.com/tag/short-term">short-term</category>
      <source url="http://blog.sciencelogic.com/hosting-meets-the-cloud-debate-part-ii/11/2008">Hosting Meets the Cloud Debate Part II</source>
    </item>
    <item>
      <title><![CDATA[Does Risk Management Make Sense?]]></title>
      <link>http://www.securityratty.com/article/1c474a0ca5e46c2d82ff6187ee46f0eb</link>
      <guid>http://www.securityratty.com/article/1c474a0ca5e46c2d82ff6187ee46f0eb</guid>
      <description><![CDATA[We engage in risk management all the time, but it only makes sense if we do it right
Risk management&quot; is just a fancy term for the cost-benefit tradeoff associated with any security decision. It's...]]></description>
      <content:encoded><![CDATA[<p>We engage in risk management all the time, but it only makes sense if we do it right. </p>

<p>"Risk management" is just a fancy term for the cost-benefit tradeoff associated with any security decision. It's what we do when we react to fear, or try to make ourselves feel secure. It's the fight-or-flight reflex that evolved in primitive fish and remains in all vertebrates. It's instinctual, intuitive and fundamental to life, and one of the brain's primary functions. </p>

<p>Some have hypothesized that humans have a "risk thermostat" that tries to maintain some optimal risk level. It explains why we drive our motorcycles faster when we wear a helmet, or are more likely to take up smoking during wartime. It's our natural risk management in action. </p>

<p>The problem is our brains are intuitively suited to the sorts of risk management decisions endemic to living in small family groups in the East African highlands in 100,000 BC, and not to living in the New York City of 2008. We make </p>

<p>systematic risk management mistakes -- miscalculating the probability of rare events, reacting more to stories than data, responding to the feeling of security rather than reality, and making decisions based on irrelevant context. And that risk cockpit of ours? It's not nearly as finely tuned as we might like it to be. </p>

<p>Like a rabbit that responds to an oncoming car with its default predator avoidance behavior -- dart left, dart right, dart left, and at the last moment jump -- instead of just getting out of the way, our Stone Age intuition doesn't serve us well in a modern technological society. So when we in the security industry use the term "risk management," we don't want you to do it by trusting your gut. We want you to do risk management consciously and intelligently, to analyze the tradeoff and make the best decision. </p>

<p>This means balancing the costs and benefits of any security decision -- buying and installing a new technology, implementing a new procedure or forgoing a common precaution. It means allocating a security budget to mitigate different risks by different amounts. It means buying insurance to transfer some risks to others. It's what businesses do, all the time, about everything. IT security has its own risk management decisions, based on the threats and the technologies. </p>

<p>There's never just one risk, of course, and bad risk management decisions often carry an underlying tradeoff. Terrorism policy in the U.S. is based more on politics than actual security risk, but the politicians who make these decisions are concerned about the risks of not being re-elected. </p>

<p>Many corporate security decisions are made to mitigate the risk of lawsuits rather than address the risk of any actual security breach. And individuals make risk management decisions that consider not only the risks to the corporation, but the risks to their departments' budgets, and to their careers. </p>

<p>You can't completely remove emotion from risk management decisions, but the best way to keep risk management focused on the data is to formalize the methodology. That's what companies that manage risk for a living -- insurance companies, financial trading firms and arbitrageurs -- try to do. They try to replace intuition with models, and hunches with mathematics. </p>

<p>The problem in the security world is we often lack the data to do risk management well. Technological risks are complicated and subtle. We don't know how well our network security will keep the bad guys out, and we don't know the cost to the company if we don't keep them out. And the risks change all the time, making the calculations even harder. But this doesn't mean we shouldn't try. </p>

<p>You can't avoid risk management; it's fundamental to business just as to life. The question is whether you're going to try to use data or whether you're going to just react based on emotions, hunches and anecdotes. </p>

<p>This essay appeared as the first half of a <a href="http://searchsecurity.techtarget.com/loginMembersOnly/1,289498,sid14_gci1332745,00.html?">point-counterpoint</a> with Marcus Ranum in <i>Information Security</i> magazine.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=etFHM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=etFHM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=KYvhM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=KYvhM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 14 Oct 2008 09:25:09 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/risk management">risk management</category>
      <category domain="http://www.securityratty.com/tag/risk management decisions">risk management decisions</category>
      <category domain="http://www.securityratty.com/tag/risk">risk</category>
      <category domain="http://www.securityratty.com/tag/avoid risk management">avoid risk management</category>
      <category domain="http://www.securityratty.com/tag/natural risk management">natural risk management</category>
      <category domain="http://www.securityratty.com/tag/risk management consciously">risk management consciously</category>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/security world">security world</category>
      <category domain="http://www.securityratty.com/tag/information security magazine">information security magazine</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/does_risk_manag.html">Does Risk Management Make Sense?</source>
    </item>
    <item>
      <title><![CDATA[Plan-based Complex Event Detection across Distributed Sources]]></title>
      <link>http://www.securityratty.com/article/7f2d9ec37ddd235b47e10e69a8a18a32</link>
      <guid>http://www.securityratty.com/article/7f2d9ec37ddd235b47e10e69a8a18a32</guid>
      <description><![CDATA[Here is an interesting 2008 paper, Plan-based Complex Event Detection across Distributed Sources
Abstract
Complex Event Detection (CED) is emerging as a key capability for many monitoring applications...]]></description>
      <content:encoded><![CDATA[<p>Here is an interesting 2008 paper, <a class="l" onmousedown="return clk(this.href,'','','res','4','')" href="http://www.cs.brown.edu/%7Eugur/ced.pdf">Plan-based Complex Event Detection across Distributed Sources.</a></p>
<p><strong>Abstract</strong></p>
<blockquote><p><em>Complex Event Detection (CED) is emerging as a key capability for many monitoring applications such as intrusion detection, sensorbased activity &amp; phenomena tracking, and network monitoring. Existing CED solutions commonly assume centralized availability and processing of all relevant events, and thus incur significant overhead in distributed settings. In this paper, we present and evaluate communication efficient techniques that can efficiently perform CED across distributed event sources.</em></p>
<p><em>Our techniques are plan-based: we generate multi-step event acquisition and processing plans that leverage temporal relationships among events and event occurrence statistics to minimize event transmission costs, while meeting application-specific latency expectations. We present an optimal but exponential-time dynamic programming algorithm and two polynomial-time heuristic algorithms, as well as their extensions for detecting multiple complex events with common sub-expressions. We characterize the behavior and performance of our solutions via extensive experimentation on synthetic and real-world data sets using our prototype implementation.</em></p></blockquote>
]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 12:49:02 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/complex event detection">complex event detection</category>
      <category domain="http://www.securityratty.com/tag/sources">sources</category>
      <category domain="http://www.securityratty.com/tag/multiple complex events">multiple complex events</category>
      <category domain="http://www.securityratty.com/tag/events">events</category>
      <category domain="http://www.securityratty.com/tag/communication efficient techniques">communication efficient techniques</category>
      <category domain="http://www.securityratty.com/tag/efficiently perform ced">efficiently perform ced</category>
      <category domain="http://www.securityratty.com/tag/ced">ced</category>
      <category domain="http://www.securityratty.com/tag/techniques">techniques</category>
      <category domain="http://www.securityratty.com/tag/event sources">event sources</category>
      <source url="http://www.thecepblog.com/2008/09/25/plan-based-complex-event-detection-across-distributed-sources/">Plan-based Complex Event Detection across Distributed Sources</source>
    </item>
    <item>
      <title><![CDATA[CEP and Analytics]]></title>
      <link>http://www.securityratty.com/article/7167551d00ca26f4a0df8a91ba7a3054</link>
      <guid>http://www.securityratty.com/article/7167551d00ca26f4a0df8a91ba7a3054</guid>
      <description><![CDATA[Peter Lin comments in A Complex Event = Sum (Events) + Situational Knowledge ,continuingthe discussion by asking What is the definition of analytics? Is it purely a calculation, or something else
A...]]></description>
      <content:encoded><![CDATA[<p>Peter Lin <a href="http://www.thecepblog.com/2008/08/16/a-complex-event-sum-events-knowledge/#comment-1079" target="_blank">comments</a> in <a title="A Complex Event = Sum (Events) + Situational Knowledge" rel="bookmark" href="http://www.thecepblog.com/2008/08/16/a-complex-event-sum-events-knowledge/"><span style="color: #105cb6;">A Complex Event = Sum (Events) + Situational Knowledge</span></a>, continuing the discussion by asking &#8221;<em>What is the definition of analytics? Is it purely a calculation, or something else?&#8221;</em></p>
<p>A good place to being to look for clues to an answer is <a href="http://en.wikipedia.org/wiki/Analytics" target="_blank">Wikipedia</a>, where the opinion of the author there is,</p>
<blockquote><p><em> &#8221;A simple and practical definition, however, would be how an entity (i.e., business) arrives at an optimal or realistic decision based on existing data.&#8221;</em></p></blockquote>
<p>Quoting the Wikipedia author(s) further,</p>
<blockquote><p><em>&#8220;Common applications of Analytics include the study of business data using statistical analysis in order to discover and understand historical patterns with an eye to predicting and improving business performance in the future. Also, some people use the term to denote the use of mathematics in business. Others hold that field of analytics include the use of Operations Research, Statistics and Probability. However, it would be erroneous to limit the field of analytics to only statistics and mathematics.&#8221;</em></p></blockquote>
<p>The Wikipedia author(s) continue their discussion of analytics, as follows;</p>
<blockquote><p><em>&#8220;Analytics closely resembles </em><a class="mw-redirect" title="Statistical analysis" href="http://www.thecepblog.com/wiki/Statistical_analysis"><em>statistical analysis</em></a><em> and </em><a title="Data mining" href="http://www.thecepblog.com/wiki/Data_mining"><em>data mining</em></a><em>, but tends to be based on modeling involving extensive computation. Some fields within the area of analytics are </em><a class="new" title="Enterprise decision management (page does not exist)" href="http://www.thecepblog.com/w/index.php?title=Enterprise_decision_management&amp;action=edit&amp;redlink=1"><em>enterprise decision management</em></a><em>, marketing analytics, predictive science, strategy science, credit risk analysis and fraud analytics.&#8221;</em></p></blockquote>
<p>All of these topics above are CEP-related areas involving complex events and situations based on the need for optimal and reliable real-time capabilities to make meaningful (business) decisions. </p>
<p>Simple pattern matching, event mediation and routing, and basic mathematical calculations do not really fall into the realm of complex event processing.  Instead, CEP is real-time decision support based on modeling and &#8220;extensive&#8221; computation.  In a nutshell, complex events and situations require analytical models that are non-trivial and that is why without analytics, there is no true &#8220;complex event processing.&#8221;</p>
<p>See also:</p>
<p><a href="http://en.wikipedia.org/wiki/Predictive_analytics" target="_self">WIkipedia on Predictive Analytics</a></p>
<p><a href="http://en.wikipedia.org/wiki/Predictive_analytics"></a></p>
]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 10:09:59 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/analytics">analytics</category>
      <category domain="http://www.securityratty.com/tag/wikipedia author">wikipedia author</category>
      <category domain="http://www.securityratty.com/tag/quotingthe wikipedia author">quotingthe wikipedia author</category>
      <category domain="http://www.securityratty.com/tag/fraud analytics">fraud analytics</category>
      <category domain="http://www.securityratty.com/tag/author">author</category>
      <category domain="http://www.securityratty.com/tag/predictive analytics">predictive analytics</category>
      <category domain="http://www.securityratty.com/tag/analytics include">analytics include</category>
      <category domain="http://www.securityratty.com/tag/business data">business data</category>
      <category domain="http://www.securityratty.com/tag/business">business</category>
      <source url="http://www.thecepblog.com/2008/08/19/cep-and-analytics/">CEP and Analytics</source>
    </item>
    <item>
      <title><![CDATA[Gallery: Images From the 16th Annual DefCon]]></title>
      <link>http://www.securityratty.com/article/fb7d8c7afe69bef6c3f3ee2131da03a6</link>
      <guid>http://www.securityratty.com/article/fb7d8c7afe69bef6c3f3ee2131da03a6</guid>
      <description><![CDATA[Photo: Dave Bullock/Wired.com
LAS VEGAS -- Last weekend, more than 9,000 hackers, freaks, feds and geeks gathered for the 16th annual DefCon, the world's largest computer security convention
Wired.com...]]></description>
      <content:encoded><![CDATA[<img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_2_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>LAS VEGAS -- Last weekend, more than 9,000 hackers, freaks, feds and geeks gathered for the 16th annual DefCon, the world's largest computer security convention. </p>

<p>Wired.com brought you <a href="http://blog.wired.com/27bstroke6/defcon/index.html">live coverage</a> of the most newsworthy events at DefCon 16. Here are some photos from the lighter side of the conference.</p>

<p><strong>Left:</strong> South Korean hackers compete in the Capture the Flag competition. The goal is to hack into and keep control of targeted servers.</p>
<img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_3_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>Mr. Sinister and Dragon Cracker battle it out in a round of <cite>Guitar Hero</cite> -- one of DefCon's newest competitions.</p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_1_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>Bringing-your-own-booze supply ensures optimal buzz at DefCon. Shortly after this picture was taken, hotel security escorted this backpack-hacker to his room.</p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_4_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>Computer geeks from the National Institute of Standards and Technology set up a network secured with quantum encryption in a conference room at DefCon. The quantum-entangled photons are being used to encrypt a video stream across a line-of-site network.</p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_5_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>A compact optical bench and an atomic clock (left) are used to secure a network with quantum encryption.   </p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_6_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>In the Lock Pick Pavilion, DefCon attendees Dustin, Jennalynn and Kunfoozball practice their lock-picking skills. </p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_7_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>DefCon founder and organizer Jeff Moss, aka Dark Tangent, at the conference's closing ceremony Sunday.</p>

<img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_9_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>A collection of black badges awaits the winners of the various competitions. These badges give their holders lifetime entry to DefCon.</p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_11_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>One of DefCon's logos, the smiley-faced skull and crossbones, is welded inside a yellow sphere. The sphere is the primary stage of one of the most difficult competitions at DefCon: <a href="http://blog.wired.com/27bstroke6/2008/08/the-defcon-16-m.html">The Mystery Challenge</a>. </p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_15_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>Unbeknownst to attendees, this laptop is sniffing RFID tags and taking photos of their owners when they pass in front of the detectors. RFID tags are used in everything from building access to some credit cards.</p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_12_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>At the closing ceremony, DefCon organizers turn off the lights while the attendees wave their <a href="http://blog.wired.com/27bstroke6/2008/08/exclusive-defco.html">high-tech badges</a> back and forth.</p><br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=68dd26e52adb5b467e7c3e6137cda635"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=68dd26e52adb5b467e7c3e6137cda635"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=68dd26e52adb5b467e7c3e6137cda635" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=5LS6EK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=5LS6EK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=K4FTfk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=K4FTfk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=IRLAWk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=IRLAWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=NFFkrK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=NFFkrK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=oS38eK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=oS38eK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=qIurlk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qIurlk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=TG21wk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=TG21wk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=n3oFWK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=n3oFWK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/362249101" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/362249108" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 14:30:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/defcon">defcon</category>
      <category domain="http://www.securityratty.com/tag/16th annual defcon">16th annual defcon</category>
      <category domain="http://www.securityratty.com/tag/defcon founder">defcon founder</category>
      <category domain="http://www.securityratty.com/tag/attendees wave">attendees wave</category>
      <category domain="http://www.securityratty.com/tag/attendees">attendees</category>
      <category domain="http://www.securityratty.com/tag/defcon organizers">defcon organizers</category>
      <category domain="http://www.securityratty.com/tag/defcon attendees dustin">defcon attendees dustin</category>
      <category domain="http://www.securityratty.com/tag/photo">photo</category>
      <category domain="http://www.securityratty.com/tag/dave">dave</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/362249108/gallery_defcon16">Gallery: Images From the 16th Annual DefCon</source>
    </item>
    <item>
      <title><![CDATA[Compromised Web Servers Serving Fake Flash Players]]></title>
      <link>http://www.securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</link>
      <guid>http://www.securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</guid>
      <description><![CDATA[The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/SSFpGnP3wvA/s1600-h/fake_flash1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/qKqvrWeAN3s/s200-R/fake_flash1.png" style="border: 0pt none ;" /></a>The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so much confidence in this risk-forwarding process of hosting their campaigns, that they would start actively spamming the links residing within low-profile legitimate sites across the web.<br />
<br />
This campaign serving fake flash players is getting so prevalent these days due to the multiple spamming approaches used, that it's hard not to notice it - and expose it. From a strategic perspective, having a legitimate low-profile site -- of course with the obvious exceptions being on purposely registered for malicious purposes within the participating sites -- hosting your malicious campaign is pretty creative in terms of forwarding the responsibility, and the eventual blocking of a legitimate site to the its owner. As far as the owner's are concerned, it appears that some of them are already seeing the malware page popping-up on the top of their daily traffic stats, and have taken measures to remove it.<br />
<br />
Moreover, <a href="http://blogs.adobe.com/psirt/2008/08/verifying_installers.html">Adobe's Product Security Incident Response Team (PSIRT) issued a warning notice about the attack yesterday</a>, which could come handy if the <a href="http://www.infoworld.com/article/08/08/05/Adobe_warns_of_bogus_Flash_Player_installers_1.html">attackers weren't taking advantage of client-side vulnerabilities</a>, putting the unware end user is a situation where he <a href="http://blogs.stopbadware.org/articles/2008/08/05/same-dogs-new-tricks">wouldn't even receive a download dialog</a> :<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/LuFjz3rFLAc/s1600-h/fake_flash3_exploit.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/GXwA3Ai1LLY/s200-R/fake_flash3_exploit.jpg" style="border: 0pt none ;" /></a>"<i>We have seen coverage from the security community of a worm on popular social networking sites that is using social engineering lures to get users to install a piece of malware. According to the reports, the worm posts comments on these sites that include links to a fake site. If the link is followed, users are told they need to update their Flash Player. The installer, posted on a malicious site, of course installs malware instead of Flash Player.We’d like to take this opportunity to reiterate the importance of validating installers and updates before installing them. First off, do not download Flash Player from a site other than adobe.com – you can find the link for downloading Flash Player here. This goes for any piece of software (Reader, Windows Media Player, Quicktime, etc.) – if you get a notice to update, it’s not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/6PfKZxTNQao/s1600-h/fake_flash2.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/ADBheDs2hkk/s200-R/fake_flash2.png" style="border: 0pt none ;" /></a>The structure of the malware campaign is pretty static, with several exceptions where they also take advange of client-side vulnerabilities (Real player exploit) attempting to automatically deliver the fake flash update or player depending on the campaign. On each and every site, there are <b>dnd.js</b> and <b>master.js</b> scripts shich serve the rogue download window, and another .html file, where an IFRAME attempts to access the traffic management command and control, in a random URL it was <b>207.10.234.217/cgi-bin/index.cgi?user200</b>. A sample list of participating URLs, most of which are still active and running :<br />
<br />
<div style="text-align: left;"><b>joseantoniobaltanas .com</b></div><b>automoviliaria .es/hotnews.html<br />
risasnc .it/fresh.html<br />
carpe-diem .com.mx/fresh.html<br />
kotilogullari .com.tr/hotnews.html<br />
ferrariclubpesaro .it/hotnews.html<br />
imobiliariacom .com.br/default.html<br />
misoares .com<br />
osniehus .de/fresh.html<br />
mydirecttube .com/1/5098/<br />
madosma .com/default.html<br />
tutotic .com/checkit.html<br />
veit-team .si/default.html<br />
antigewaltkurse .de/stream.html<br />
kwhgs .ca/topnews.html<br />
vorgo .com/stream.html<br />
ankaraspor .com.tr/default.html<br />
xxxdnn0314 .locaweb.com.br/watchit.html<br />
ossuzio .com/watchit.html<br />
cit-inc .net/default.html<br />
negocioindependiente .biz/default.html<br />
ambermarketing .com/topnews.html<br />
web27 .login-7.loginserver.ch/stream.html<br />
moretewebdesign .br-web.com/stream.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/hotnews.html<br />
campodifiori .it/topnews.html<br />
212.50.55.81 /stream.html<br />
logisigns .net/fresh.html<br />
intimaescorts .com/default.html<br />
ghioautotre .it/live.html<br />
geckert .de/stream.html<br />
yuricardinali .com/watchit.html<br />
retder .com/fresh.html<br />
valdaran .es/default.html<br />
getadultaccess .com/movie/?aff=5274<br />
bauelemente-giering .de/stream.html<br />
newyork-hebergement .com/watchit.html<br />
allevatoritrotto .it/live.html<br />
exoss2 .com/hotnews.html<br />
soundandlightkaraoke .com/stream.html<br />
land-kan .com/stream.html<br />
grimaldi.nexenservices .com/watchit.html<br />
inconstancia .com.br/watchit.html <br />
gretelstudio .com/stream.html<br />
sumacyl .com/watchit.html<br />
mysna .net/fresh.html<br />
gimnasioyx .com.ar/watchit.html<br />
lagalbana .com/watchit.html<br />
bielizna.tgory .pl/topnews.html<br />
bcs92.imingo .net/stream.html<br />
lapiramidecoslada .es/topnews.html<br />
raulortega .com/stream.html<br />
go-art-morelli .de/hotnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
dianagraf .es/default.html<br />
komma10-thueringen .de/hotnews.html<br />
miavassilev .com/stream.html<br />
swampgiants .com/watchit.html<br />
compagniedephalsbourg .com/fresh.html<br />
arla-rc .net/hotnews.html<br />
salacopernico .es/watchit.html<br />
drfinster .de/checkit.html<br />
healthylifehypnotherapy .com/stream.html<br />
ecotrike-bg .com/fresh.html<br />
paoepalavra .org/watchit.html<br />
jureplaninc-sp .com/topnews.html<br />
fichte-lintfort .de/default.html<br />
hergert-band .de/checkit.html<br />
izliyorum .org/topnews.html<br />
lideka .com/stream.html<br />
athena-digitaldesign .com.tw/hotnews.html<br />
e-paso .pl/stream.html<br />
colombeblanche .org/stream.html<br />
teatromalasa .es/watchit.html<br />
mesporte.digiweb.com .br/stream.html<br />
bistrodavila.com .br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
jbhumet .com/default.html<br />
gruppouni .com/hotnews.html<br />
francex .net/fresh.html<br />
galvatoledo .com/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
kroenert .name/default.html<br />
textilhogarnovadecor .com/topnews.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
neticon .pl/hotnews.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
easterstreet .de/fresh.html<br />
piogiovannini .com.ar/watchit.html<br />
ser-all .com/topnews.html<br />
petzold-dieter .de/checkit.html<br />
beatmung-brandenburg .de/checkit.html<br />
ossuzio .com/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
zelenaratolest .cz/pornotube/index1.htm<br />
ambulatoriovirtuale .it/topnews.html<br />
10a3 .ru/index1.php<br />
izliyorum .org/topnews.html<br />
collectedthoughts .co.uk/index12.html<br />
afg .es/topnews.html<br />
albertruiz .net/topnews.html<br />
bielizna.tgory .pl/topnews.html<br />
blueseven.com .br/topnews.html<br />
bollettinogiuridicosanitario .it/topnews.html<br />
caprilchamonix.com .br/topnews.html<br />
carlolongarini .it/topnews.html<br />
champimousse .com/topnews.html<br />
cheviot.org .nz/topnews.html<br />
contrapie .com/topnews.html<br />
gruppouni .com/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
herbatele .com/topnews.html<br />
houseincostaricaforsale .com/topnews.html<br />
alim.co .il/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
amafe .org/topnews.html<br />
ambulatoriovirtuale .it/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
automoviliaria .es/topnews.html<br />
autoreserve .fr/topnews.html<br />
izliyorum .org/topnews.html<br />
jureplaninc-sp .com/topnews.html<br />
kwhgs .ca/topnews.html<br />
lapiramidecoslada .es/topnews.html<br />
last-minute-reisen-4u .de/topnews.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
corradiproject .info/topnews.html<br />
dantealighieriasturias .es/topnews.html<br />
deliriuslaspalmas .com/topnews.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/topnews.html<br />
fonavistas .com/topnews.html<br />
fraemma .com/topnews.html<br />
fundmyira .com/topnews.html<br />
galvatoledo .com/topnews.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
markmaverick .com/topnews.html<br />
micela .info/topnews.html<br />
motoclubnosvamos .com/topnews.html<br />
nebottorrella .com/topnews.html<br />
negozistore .it/topnews.html<br />
neticon .pl/topnews.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
segelclub-honau .de/topnews.html<br />
snmobilya .com/topnews.html<br />
splashcor .com.br/topnews.html<br />
stephanmager .gmxhome.de/topnews.html<br />
svcanvas .com/topnews.html<br />
tautau.web .simplesnet.pt/topnews.html<br />
textilhogarnovadecor .com/topnews.html<br />
theflorist4u .com/topnews.html<br />
thewindsorhotel .it/topnews.html<br />
vuelosultimahora .com/topnews.html<br />
aliarzani .de/topnews.html<br />
ambermarketing .com/topnews.html<br />
arnold82.gmxhome .de/topnews.html<br />
ocoartefatos.com .br/topnews.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
projetsoft .net/topnews.html<br />
rbc.gmxhome .de/topnews.html<br />
beatmung-sachsen .eu/topnews.html<br />
campodifiori .it/topnews.html<br />
clickjava .net/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
dammer .info/topnews.html<br />
embedded-silicon .de/topnews.html<br />
ferrariclubpesaro .it/topnews.html<br />
fgwiese .de/topnews.html<br />
fswash.site .br.com/topnews.html<br />
fytema .es/topnews.html<br />
gildas-saliou. com/topnews.html<br />
go-art-morelli .de/topnews.html<br />
go-siegmund .de/topnews.html<br />
guerrero-tuning .com/topnews.html<br />
gut-barbarastein .de/topnews.html<br />
japansec .com/topnews.html<br />
komma10-thueringen .de/topnews.html<br />
koon-design .de/topnews.html<br />
lanz-volldiesel .de/topnews.html<br />
lauscher-staat .de/topnews.html<br />
losnaranjos.com .es/topnews.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
nepi.si/topnews .html<br />
radieschenhein. de/topnews.html<br />
residenceflora .it/topnews.html<br />
sabuha .de/topnews.html<br />
ser-all .com/topnews.html<br />
siemieniewicz .de/topnews.html<br />
viajesk .es/topnews.html<br />
allevatoritrotto .it/live.html<br />
bollettinogiuridicosanitario .it/live.html<br />
carlolongarini .it/topnews.html<br />
maremax .it/topnews.html<br />
negozistore .it/topnews.html<br />
parapendiolestreghe .it/live.html<br />
www.donlisander .it/stream.html<br />
aerogenesis .net/watchit.html<br />
allevatoritrotto .it/live.html<br />
atelier-de-loulou .fr/topnews.html<br />
bistrodavila.com .br/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
caprilchamonix.com .br/topnews.html<br />
cheviot.org .nz/live.html<br />
condorautocenter .com.br/watchit.html<br />
dantealighieriasturias .es/live.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/live.html<br />
fonavistas .com/topnews.html<br />
fundmyira .com/topnews.html<br />
g6esporte .com.br/stream.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
gretelstudio .com/stream.html<br />
gutierrezymoralo .com/watchit.html<br />
healthylifehypnotherapy .com/stream.html<br />
herbatele .com/live.html<br />
jureplaninc-sp .com/topnews.html<br />
lacomercialsrl .com.ar/stream.html<br />
lagalbana .com/watchit.html<br />
lapuertaestrecha .com.es/watchit.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
myadultcube .com/flash//aff=5176<br />
myadultcube .com/flash//aff=5810<br />
myadultcube .com/movie//aff=5155<br />
newyork-hebergement .com/watchit.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
omdconsulting .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
parapendiolestreghe .it/live.html<br />
regesh. co.il/watchit.html<br />
rikkeroenneberg .dk/watchit.html<br />
s215847279 .onlinehome.fr/stream.html<br />
salacopernico .es/watchit.html<br />
seekzones .com/watchit.html<br />
seicomsl .es/watchit.html<br />
sigma-lux .ro/watchit.html<br />
soundandlightkaraoke .com/stream.html<br />
stephanmager.gmxhome .de/topnews.html<br />
tartuinstituut .ca/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
aliarzani .de/topnews.html<br />
ambermarketing. com/live.html<br />
bilbondo .com/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
colombeblanche .org/stream.html<br />
donlisander .it/stream.html<br />
fgwiese .de/topnews.html<br />
geckert .de/stream.html<br />
helene-taucher .de/watchit.html<br />
lanz-volldiesel .de/topnews.html<br />
mairie-margnylescompiegne .fr/watchit.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
ossuzio .com/watchit.html<br />
piogiovannini .com.ar/watchit.html<br />
sabuha .de/topnews.html<br />
sumacyl .com/watchit.html<br />
swampgiants .com/watchit.html<br />
xn--glland-3ya .de/stream.html<br />
yuricardinali .com/watchit.html</b><br />
<b>nepi .si/topnews.html<br />
dammer .info/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
galvatoledo .com/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
micela .info/topnews.html<br />
bistrodavila .com.br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
gruppouni .com/hotnews.html<br />
galvatoledo .com/topnews.html<br />
kroenert .name/default.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
dantealighieriasturias .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
89.19.29 .13/stream.html<br />
slobodandjakovic .com/fresh.html<br />
cqcs.com .br/stream.html<br />
seekzones .com/watchit.html<br />
pascosa .it/stream.html<br />
caprilchamonix .com.br/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
ferien-urlaub-lastminute .de/default.html<br />
mueggelpark .info/watchit.html<br />
hillner-online .de/fresh.html<br />
guiasaojose .net/default.html<br />
deliriuslaspalmas .com/topnews.html<br />
fraemma .com/topnews.html<br />
morsbaby .net/default.html<br />
vickywhite .com/fresh.html<br />
micela .info/topnews.html<br />
corradiproject .info/topnews.html<br />
liguehavraise .com/live.html<br />
capacitacaoemlideranca .com.br/fresh.html<br />
materialesyacabados .com.mx/stream.html<br />
208.112.7.68 /checkit.html<br />
152.10.1.37 /1.html<br />
carlolongarini .it/topnews.html<br />
splashcor.com .br/topnews.html<br />
lobpreisstrasse .org/1.html<br />
motoclubnosvamos .com/hotnews.html<br />
hk-rc.com /1.html<br />
taaf.re /stream.html<br />
dulceysalao .com/default.html<br />
amafe .org/topnews.html <br />
</b><br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/MTxnF1XLDCw/s1600-h/fake_flash3_rogue_software.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/3Dgh4x23dRs/s200-R/fake_flash3_rogue_software.png" style="border: 0pt none ;" /></a>Sample detection rate : <span id="status_nombre">flashupdate.exe</span><br />
<span id="status_nombre"><b>Scanners Result</b>: 35/36 (97.23%)</span><br />
<span id="status_nombre">Trojan-Downloader.Win32.Exchanger.hk; Troj/Cbeplay-A</span><br />
<b>File size</b>: 78848 bytes<br />
<b>MD5</b>...: c81b29a3662b6083e3590939b6793bb8<br />
<b>SHA1</b>..: d513275c276840cb528ce11dd228eae46a74b4b4<br />
<br />
The downloader then "phones back home" at <b>72.9.98.234 port 443 </b>which is responding to the rogue security software AntiSpy Spider (<b>antispyspider.net</b>) :<br />
<br />
"<i>AntiSpy Spider is a cutting-edge anti-spyware solution.This revolutionary anti-spyware program was created by the industry's top spyware experts in order to protect your computer and your privacy.html, while ensuring optimal system performance.With the ability to locate, eliminate and prevent the widest range of spyware threats, AntispyStorm is able to offer its users a safe, spyware-free computing experience; and with it's convenient automatic update feature, AntispyStorm ensures continuous up-to-date protection.</i>" <br />
<br />
Sample detection rate : antispyspider.msi<br />
<b>Scanners Result</b>: 11/35 (31.43%)<br />
FraudTool.Win32.AntiSpySpider.b;&nbsp; <br />
<b>File size</b>: 1851904 bytes<br />
<b>MD5</b>...: 2f1389e445f65e8a9c1a648b42a23827<br />
<b>SHA1</b>..: e32aa6aa791e98fe6fdef451bd3b8a45bad0acd8<br />
<br />
The bottom line - over a thousand domains are participating, with many other apparently joining the party proportionally with the web site owner's actions to get rid of the malware campaign hosted on their servers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BvcTqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BvcTqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=onawHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=onawHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fa1ek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fa1ek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5nQAgk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5nQAgk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sqdHIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sqdHIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mq3LKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mq3LKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8zplkk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8zplkk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356677080" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 10:50:04 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/file">file</category>
      <category domain="http://www.securityratty.com/tag/html file">html file</category>
      <category domain="http://www.securityratty.com/tag/html">html</category>
      <category domain="http://www.securityratty.com/tag/comtopnews">comtopnews</category>
      <category domain="http://www.securityratty.com/tag/detopnews">detopnews</category>
      <category domain="http://www.securityratty.com/tag/windows media player">windows media player</category>
      <category domain="http://www.securityratty.com/tag/player">player</category>
      <category domain="http://www.securityratty.com/tag/web">web</category>
      <category domain="http://www.securityratty.com/tag/real player exploit">real player exploit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356677080/compromised-web-servers-serving-fake.html">Compromised Web Servers Serving Fake Flash Players</source>
    </item>
    <item>
      <title><![CDATA[Metrics for security and performance in low-latency anonymity systems]]></title>
      <link>http://www.securityratty.com/article/fad1cb42a51fdba1643f542416f2a5f3</link>
      <guid>http://www.securityratty.com/article/fad1cb42a51fdba1643f542416f2a5f3</guid>
      <description><![CDATA[In Tor , and in other similar anonymity systems, clients choose a random sequence of computers (nodes) to route their connections through. The intention is that, unless someone is watching the whole...]]></description>
      <content:encoded><![CDATA[<p>In <a href="https://www.torproject.org/">Tor</a>, and in other similar anonymity systems, clients choose a random sequence of computers (nodes) to route their connections through. The intention is that, unless someone is watching the whole network at the same time, the tracks of each user&#8217;s communication will become hidden amongst that of others. Exactly how a client chooses nodes varies between system to system, and is important for security.</p>
<p>If someone is simultaneously watching a user&#8217;s traffic as it enters and leaves the network, it is possible to de-anonymise the communication. This could occur if the first and last node for a connection is controlled by the same person. Tor takes some steps to avoid this possibility e.g. no two computers on the same /16 network may be chosen for each connection. However, someone with access to several networks could circumvent this measure.</p>
<p>Not only is route selection critical for security, but it&#8217;s also a significant performance factor. Tor nodes vary dramatically in their capacity, mainly due to their network connections. If all nodes were chosen with equal likelihood, the slower ones would cripple the network. This is why Tor weights the selection probability for a node proportional to its contribution to the network bandwidth.</p>
<p>Because of the dual importance of route selection, there are a number of proposals which offer an alternative to Tor&#8217;s bandwidth-weighted algorithm. Later this week at <a href="http://petsymposium.org/2008/">PETS</a> I&#8217;ll be presenting my paper, co-authored with <a href="http://www.cl.cam.ac.uk/~rnw24">Robert N.M. Watson</a>, &#8220;<a href="http://www.cl.cam.ac.uk/~sjm217/papers/pets08metrics.pdf">Metrics for security and performance in low-latency anonymity systems</a>&#8221;.  In this paper, we examine several route selection algorithms and evaluate their security and performance.</p>
<p>Intuitively, a route selection algorithm which weights all nodes equally appears the most secure because an attacker can&#8217;t make their node count any more than the others. This has been formalized by two measures: <a href="http://en.wikipedia.org/wiki/Gini_coefficient">Gini coefficient</a> and <a href="http://en.wikipedia.org/wiki/Information_entropy">entropy</a>. In fact the reality is more complex &#8212; uniform node selection resists attackers with lots of bandwidth, whereas bandwidth-weighting is better against attackers with lots of nodes.</p>
<p>Our paper explores the probability of path compromise of different route selection algorithms, when under attack by a range of different adversaries. We find that none of the proposals are optimal against all adversaries, and so summarizing effective security in terms of a single figure is not feasible. We also model the performance of the schemes and show that bandwidth-weighting offers both low latency and high resistance to attack by bandwidth-constrained adversaries.</p>
]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 04:16:12 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/route selection">route selection</category>
      <category domain="http://www.securityratty.com/tag/route selection critical">route selection critical</category>
      <category domain="http://www.securityratty.com/tag/route selection algorithms">route selection algorithms</category>
      <category domain="http://www.securityratty.com/tag/route">route</category>
      <category domain="http://www.securityratty.com/tag/nodes">nodes</category>
      <category domain="http://www.securityratty.com/tag/tor nodes vary">tor nodes vary</category>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/performance">performance</category>
      <category domain="http://www.securityratty.com/tag/route selection algorithm">route selection algorithm</category>
      <source url="http://www.lightbluetouchpaper.org/2008/07/21/metrics-for-security-and-performance/">Metrics for security and performance in low-latency anonymity systems</source>
    </item>
    <item>
      <title><![CDATA[Free tool secures VMware servers]]></title>
      <link>http://www.securityratty.com/article/231224be19deafbacb2af7dbcd81c059</link>
      <guid>http://www.securityratty.com/article/231224be19deafbacb2af7dbcd81c059</guid>
      <description><![CDATA[ConfigCheck compares active virtual settings against best practices guidelines, and recommends ways of fixing less-than-optimal...]]></description>
      <content:encoded><![CDATA[ConfigCheck compares active virtual settings against best practices guidelines, and recommends ways of fixing less-than-optimal settings.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=nAjZtf"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=nAjZtf" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/308251491" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 09:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/practices guidelines">practices guidelines</category>
      <category domain="http://www.securityratty.com/tag/recommends">recommends</category>
      <category domain="http://www.securityratty.com/tag/settings">settings</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/308251491/article.do">Free tool secures VMware servers</source>
    </item>
    <item>
      <title><![CDATA[Cross-Device-Type Log Management vs Device-Specific Log Management]]></title>
      <link>http://www.securityratty.com/article/77726863efe81c8acbe240fb60a6740d</link>
      <guid>http://www.securityratty.com/article/77726863efe81c8acbe240fb60a6740d</guid>
      <description><![CDATA[Now, I have to first admit that, in general, dealing with logs on a device-specific basis is a cruel joke . What I mean here is when you gather Windows logs in one place, Linux logs in another place,...]]></description>
      <content:encoded><![CDATA[<p>Now, I have to first admit that, in general, <strong>dealing with logs on a device-specific basis is a cruel joke</strong>. What I mean here is when you gather Windows logs in one place, Linux logs in another place, database logs in yet another place; all in different formats, all in different systems not connected to each others, all managed by different people who don't talk to each other (and sometimes hate each other). Yuck! Basically, this situation is "logs at their worst": all different, all disjointed and, as a result, all next to useless.</p> <p>However, there are rare situations where you can choose device-specific log management approach (and still not look like a money- and time-wasting and idiot :-)). For example, you might be motivated by the fact that tools that can handle one specific type of log data (e.g. Windows-only, web server-only or Cisco PIX-only) are usually many times less expensive than <a href="http://www.loglogic.com">cross-device log management tools</a>. The table below clarifies it: </p> <table cellspacing="0" cellpadding="2" width="608" border="2"> <tbody> <tr> <td valign="top" width="150"><strong>Use Case vs Approach</strong></td> <td valign="top" width="140"><strong>No log consolidation - logs remain on systems they are produced</strong></td> <td valign="top" width="137"><strong>Device-specific log consolidation and analysis</strong></td> <td valign="top" width="174"><strong>Cross-device log consolidation and analysis from all log sources</strong></td></tr> <tr> <td valign="top" width="149">Alerting based on log strings (keywords) that indicate security or operational problems</td> <td valign="top" width="139"><strong>Impossible</strong> or tremendously hard to manage across many systems</td> <td valign="top" width="137"><strong>Acceptable</strong> - alerts on each log type are handled by different teams</td> <td valign="top" width="174"><strong>Superior</strong> - all logs are available for analysis when the alert is triggered</td></tr> <tr> <td valign="top" width="146">Reviewing logs for troubleshooting server problems </td> <td valign="top" width="140"><strong>Acceptable</strong> - server logs are sufficient for </td> <td valign="top" width="137"><strong>Better</strong> - one can also look at logs from other similar servers</td> <td valign="top" width="174"><strong>Better </strong>- but same as device-specific log analysis since only one type of logs needs to be reviewed</td></tr> <tr> <td valign="top" width="146">Log review for compliance with PCI DSS</td> <td valign="top" width="140"><strong>Not acceptable</strong> - log management is mandated by Req 10</td> <td valign="top" width="137"><strong>Impossible </strong>or very inefficient - as many types of log data needs to be collected and reviewed</td> <td valign="top" width="174"><strong>Optimal</strong> - all PCI relevant logs can be collected and reviewed in one system</td></tr> <tr> <td valign="top" width="146">Looking for records of a specific user activity</td> <td valign="top" width="140"><strong>Impossible</strong> or tremendously hard since hundreds of systems might need to be searched</td> <td valign="top" width="137"><strong>Inefficient</strong> - several different systems needs to be accessed to review all records of user's activities (and then data needs to be manually correlated)</td> <td valign="top" width="174"><strong>Optimal</strong> - one query gives all traces of the user activity</td></tr> <tr> <td valign="top" width="146">Log review for incident response or forensics investigation</td> <td valign="top" width="140"><strong>Impossible</strong> or tremendously hard since hundreds of systems might need to be searched for evidence</td> <td valign="top" width="137"><strong>Inefficient</strong> - several different systems needs to be searches for evidence and then data manually correlated</td> <td valign="top" width="174"><strong>Optimal</strong> - all log evidence can be found, reviewed and analyzed on one system, neither hundreds, nor several</td></tr></tbody></table> <p>Also, while looking at logging tools, one needs to make a distinction between tools that can collect all sorts of logs but only allow you to analyze one log type at a time (e.g. sawmill) vs tools that can collect all sorts of logs AND allow you to analyze all of them together (e.g. <a href="http://www.loglogic.com">LogLogic</a>). The former tools still fall under "device-specific log management" despite their ability to gather hundreds of different log types.</p> <p>The bottom line: in most cases, cross-device, uniform log management provides huge value, especially if your motivation for log management is compliance or incident response.</p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:1a074deb-adb0-4ee5-a29e-1814e11dfc2f" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/logs" rel="tag">logs</a>, <a href="http://technorati.com/tags/log%20management" rel="tag">log management</a>, <a href="http://technorati.com/tags/logging" rel="tag">logging</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=MGF8JI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=MGF8JI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=DMnW2I"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=DMnW2I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mfmrbI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mfmrbI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/303255226" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 02 Jun 2008 10:38:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/logs">logs</category>
      <category domain="http://www.securityratty.com/tag/pci relevant logs">pci relevant logs</category>
      <category domain="http://www.securityratty.com/tag/log management">log management</category>
      <category domain="http://www.securityratty.com/tag/database logs">database logs</category>
      <category domain="http://www.securityratty.com/tag/logs remain">logs remain</category>
      <category domain="http://www.securityratty.com/tag/gather windows logs">gather windows logs</category>
      <category domain="http://www.securityratty.com/tag/device-specific log management">device-specific log management</category>
      <category domain="http://www.securityratty.com/tag/server logs">server logs</category>
      <category domain="http://www.securityratty.com/tag/type">type</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/303255226/cross-device-type-log-management-vs.html">Cross-Device-Type Log Management vs Device-Specific Log Management</source>
    </item>
    <item>
      <title><![CDATA[Seat Belt Usage and Compensating Behavior]]></title>
      <link>http://www.securityratty.com/article/c290a277ba35690261126184154d7798</link>
      <guid>http://www.securityratty.com/article/c290a277ba35690261126184154d7798</guid>
      <description><![CDATA[There is a theory that people have an inherent risk thermostat that seeks out an optimal level of risk. When something becomes inherently safer -- a law is passed requiring motorcycle riders to wear...]]></description>
      <content:encoded><![CDATA[<p>There is a theory that people have an inherent risk thermostat that seeks out an optimal level of risk.  When something becomes inherently safer -- a law is passed requiring motorcycle riders to wear helmets, for example -- people compensate by riding more recklessly.  I first read this theory in a 1999 <a href="http://www.cato.org/pubs/pas/pa-335es.html">paper</a> by John Adams at the University of Reading, although it seems to have originated with Sam Peltzman.</p>

<p>In any case, <a href="http://www.stanford.edu/~leinav/pubs/RESTAT2003.pdf">this paper</a> presents data that contradicts that thesis:</p>

<blockquote>Abstract--This paper investigates the effects of mandatory seat belt laws on driver behavior and traffic fatalities. Using a unique panel data set on seat belt usage in all U.S. jurisdictions, we analyze how such laws, by influencing seat belt use, affect the incidence of traffic fatalities. Allowing for the endogeneity of seat belt usage, we find that such usage decreases overall traffic fatalities. The magnitude of this effect, however, is significantly smaller than the estimate used by the National Highway Traffic Safety Administration. In addition, we do not find significant support for the compensating-behavior theory, which suggests that seat belt use also has an indirect adverse effect on fatalities by encouraging careless driving. Finally, we identify factors, especially the type of enforcement used, that make seat belt laws more effective in increasing seat belt usage.</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=n5KCk3G"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=n5KCk3G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=1E7NlpG"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=1E7NlpG" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 11 Apr 2008 09:44:59 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/seat belt">seat belt</category>
      <category domain="http://www.securityratty.com/tag/seat belt usage">seat belt usage</category>
      <category domain="http://www.securityratty.com/tag/laws">laws</category>
      <category domain="http://www.securityratty.com/tag/seat belt laws">seat belt laws</category>
      <category domain="http://www.securityratty.com/tag/fatalities">fatalities</category>
      <category domain="http://www.securityratty.com/tag/traffic fatalities">traffic fatalities</category>
      <category domain="http://www.securityratty.com/tag/inherent risk thermostat">inherent risk thermostat</category>
      <category domain="http://www.securityratty.com/tag/risk">risk</category>
      <category domain="http://www.securityratty.com/tag/indirect adverse effect">indirect adverse effect</category>
      <source url="http://www.schneier.com/blog/archives/2008/04/seat_belt_usage.html">Seat Belt Usage and Compensating Behavior</source>
    </item>
  </channel>
</rss>
