<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Jabablog &#187; InfoSec</title>
	<atom:link href="http://blog.jabawoki.com/tag/infosec/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.jabawoki.com</link>
	<description>Nothing to see here, Move along...</description>
	<lastBuildDate>Fri, 05 Mar 2010 13:17:04 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<!-- podcast_generator="podPress/8.8" - maintenance_release="8.8.4" -->
		<copyright>2006-2010 </copyright>
		<managingEditor>jay@jabawoki.com (Jabawoki)</managingEditor>
		<webMaster>jay@jabawoki.com (Jabawoki)</webMaster>
		<category>music</category>
		<ttl>1440</ttl>
		<itunes:keywords>House,electro,hard,mix,dj,hardcore,hardstyle,trance, progressive, house, music, hardcore, handbag, happy, tech, deep, security, infosec, itsec, jay, abbott, jay abbott, jabawoki</itunes:keywords>
		<itunes:subtitle>Jabawoki Presents: </itunes:subtitle>
		<itunes:summary>House Music Mixes, everything from electro to hard, from 2000 onwards, courtesy of Jabawoki.</itunes:summary>
		<itunes:author>Jabawoki</itunes:author>
		<itunes:category text="Music"/>
<itunes:category text="Games &amp; Hobbies">
	<itunes:category text="Hobbies"/>
</itunes:category>
<itunes:category text="Technology"/>
		<itunes:owner>
			<itunes:name>Jabawoki</itunes:name>
			<itunes:email>jay@jabawoki.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://blog.jabawoki.com/wp-content/plugins/podpress/images/SubSide-Large.jpg" />
		<image>
			<url>http://blog.jabawoki.com/wp-content/plugins/podpress/images/SubSide-small.jpg</url>
			<title>Jabablog</title>
			<link>http://blog.jabawoki.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>Black, White or Grey? What colour hat do you wear?</title>
		<link>http://blog.jabawoki.com/2010/02/25/black-white-or-grey-what-colour-hat-do-you-wear/</link>
		<comments>http://blog.jabawoki.com/2010/02/25/black-white-or-grey-what-colour-hat-do-you-wear/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 09:57:08 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[attacker]]></category>
		<category><![CDATA[black hat]]></category>
		<category><![CDATA[ethical]]></category>
		<category><![CDATA[goals]]></category>
		<category><![CDATA[grey hat]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[intent]]></category>
		<category><![CDATA[itsec]]></category>
		<category><![CDATA[motivation]]></category>
		<category><![CDATA[PenTest]]></category>
		<category><![CDATA[white hat]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=1740</guid>
		<description><![CDATA[There is often a lot of talk about this concept, specifically in the white hat vs black hat debate that has gone on for what seems like forever now. I have, as you would expect, my own take on this. Lets start with a history lesson and the basics. White Hats are the &#8220;good guys&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>There is often a lot of talk about this concept, specifically in the white hat vs black hat debate that has gone on for what seems like forever now. I have, as you would expect, my own take on this. Lets start with a history lesson and the basics. White Hats are the &#8220;good guys&#8221; and Black Hats are the &#8220;bad guys&#8221;, why? because back in the good old days of spaghetti westerns, good guys always wore White Hats and the bad guys wore Black Hats, it&#8217;s that simple! Of course, in the scripted world of the western, it was that simple, the bad guy was that easy to spot and the good guys rode off into the sunset, but back in the real world it&#8217;s a little more difficult to identify.</p>
<p><span id="more-1740"></span>The line between Black and White is often understood to be the law itself, i.e. if you&#8217;re a hacker, cracker or even a &#8220;skidie&#8221;, your hat changes colour the minute you go from having permission to do something to not having permission.  I however wager that if we were to exact that understanding on every security expert in this field of expertise, today, it would be a near 100% perfect sea of Black Hats.</p>
<p>So the question becomes, if that&#8217;s the case, are we all really the &#8220;bad guys&#8221;? I put to you a different concept, I different way of thinking about this that, personally, I think fits much better.</p>
<p>First of all let&#8217;s forget about hats and the law and look at a couple of basic concepts. <a href="http://en.wikipedia.org/wiki/Motivation" target="_blank">Motivation</a> is the activation or energization of goal-oriented behaviour and  is defined as intrinsic or extrinsic. Intrinsic motivation comes from rewards inherent to a task or activity itself &#8211; the enjoyment of a puzzle or the love of playing whereas Extrinsic motivation comes from outside of the performer. Money is the most obvious example, but coercion and threat of punishment are also common extrinsic motivations.</p>
<p>Another point of consideration is <a href="http://en.wikipedia.org/wiki/Goal-oriented" target="_blank">Goal orientation</a>, often seen as an aspect of an individual&#8217;s motivation. An individual&#8217;s goal orientation describes the goals that they choose and the methods used to pursue those goals. One of the most common conceptualizations of goal orientation is the three factor model, that is, individuals can be described in terms of goal orientation based on three factors:</p>
<ul>
<li>mastery,</li>
<li>performance-approach, and</li>
<li>performance-avoid.</li>
</ul>
<p>Individuals with a mastery goal orientation seek challenging tasks and value learning. Highly performance-approach oriented individuals seek tasks that allow them to demonstrate the skills they already possess, and highly performance-avoidant tend to avoid tasks where they may fail and thus appear incompetent.</p>
<p>The final aspect to consider in this equation is an agent&#8217;s <a href="http://en.wikipedia.org/wiki/Intention" target="_blank">intention</a> in performing an action. In so much as his or her specific purpose in doing so, the end or goal that is aimed at, or intended to accomplish. In recent years, there has been a large amount of work done on the concept of intentional action in experimental philosophy. This work has aimed at illuminating and understanding the factors which influence people&#8217;s judgments of whether an action was done intentionally. For instance, research has shown that unintended side-effects are often considered to be done intentionally if the side-effect is considered bad and the person acting knew the side-effect would occur before acting. Yet when the side-effect is considered good, people generally don&#8217;t think it was done intentionally, even if the person knew it would occur before acting. The most well-known example involves a chairman who implements a new business program for the sole purpose to make money but ends up affecting the environment in the process. If he implements his business plan and in the process he ends up helping the environment, then people generally say he unintentionally helped the environment; if he implements his business plan and in the process he ends up harming the environment, then people generally say he intentionally harmed the environment. The important point is that in both cases his only goal was to make money. While there have been many explanations proposed for why the &#8220;side-effect effect&#8221; occurs, researchers on this topic have not yet reached a consensus.</p>
<p>So now we understand a little about motivation, goals &amp; Intentions, what really makes the &#8220;bad guy&#8221; bad? Well its worth adding into themix that the &#8220;good guys&#8221; and &#8220;bad guys&#8221; all have the same level of skill, they all learned it the same way and they all have the same aptitude (loosely speaking of course). In fact during the learning process its probably fair to wager that on occasion everyone ended up, purely through exploration, somewhere they shouldn&#8217;t have been.  Does this make us all &#8220;bag guys&#8221;?</p>
<p>I certainly do not think so. In my opinion, motivation, goals &amp; intent are what separate the good from the bad, and in this context the &#8220;White Hats&#8221; from the &#8220;Black Hats&#8221;. Let&#8217;s look at an example. the <a href="http://www.cert.org/" target="_blank">CERT Coordination Centre</a> came up with an interesting classification matrix, which I have provided below as a diagram:</p>
<p style="text-align: center;"><img class="size-full wp-image-1742   aligncenter" title="CERT-Attacker-Types" src="http://blog.jabawoki.com/wp-content/uploads/2010/02/CERT-Attacker-Types1.jpg" alt="" width="500" height="272" /></p>
<p style="text-align: center;">
<p>In the above diagram, we see six types of attacker (as well as a virtual 7th type that could be all 6 in a different context), six types of motivation and four goals.  It is assumed in  this classification, as insinuated by the word &#8220;Attacker&#8221;, that we are dealing with the &#8220;bag guys&#8221; or Black Hats here, however, I would argue that the first type, &#8220;Hacker&#8221; has a motivation and goal that is not negative or in fact malicious in any way, so should they also be considered a &#8220;bad guy&#8221;?  Its fair to say, someone hell bent on the quest for knowledge in that particular classification may take a devil may care approach that could have a negative impact on the systems they are exploring, but again, is this malicious intent, or just carelessness?</p>
<p>In summary I put it to you that there are no White Hats, or Black hats in the world today, just Shades of Grey, and that only motivation, goals and intent separate those of us trying to help from those who have a more nefarious purpose.</p>
<div class='wp_likes' id='wp_likes_post-1740'><a class='like' href="javascript:wp_likes.like(1740);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(1740);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F&amp;title=Black%2C+White+or+Grey%3F+What+colour+hat+do+you+wear%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F&amp;title=Black%2C+White+or+Grey%3F+What+colour+hat+do+you+wear%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F&amp;title=Black%2C+White+or+Grey%3F+What+colour+hat+do+you+wear%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F&amp;headline=Black%2C+White+or+Grey%3F+What+colour+hat+do+you+wear%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Black%2C+White+or+Grey%3F+What+colour+hat+do+you+wear%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Black%2C+White+or+Grey%3F+What+colour+hat+do+you+wear%3F&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Black%2C+White+or+Grey%3F+What+colour+hat+do+you+wear%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Black%2C+White+or+Grey%3F+What+colour+hat+do+you+wear%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Black%2C+White+or+Grey%3F+What+colour+hat+do+you+wear%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F&amp;title=Black%2C+White+or+Grey%3F+What+colour+hat+do+you+wear%3F&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F02%2F25%2Fblack-white-or-grey-what-colour-hat-do-you-wear%2F&amp;title=Black%2C+White+or+Grey%3F+What+colour+hat+do+you+wear%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/attacker/" title="attacker" rel="tag">attacker</a>, <a href="http://blog.jabawoki.com/tag/black-hat/" title="black hat" rel="tag">black hat</a>, <a href="http://blog.jabawoki.com/tag/ethical/" title="ethical" rel="tag">ethical</a>, <a href="http://blog.jabawoki.com/tag/goals/" title="goals" rel="tag">goals</a>, <a href="http://blog.jabawoki.com/tag/grey-hat/" title="grey hat" rel="tag">grey hat</a>, <a href="http://blog.jabawoki.com/tag/hackers/" title="hackers" rel="tag">hackers</a>, <a href="http://blog.jabawoki.com/tag/hacking/" title="hacking" rel="tag">hacking</a>, <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/intent/" title="intent" rel="tag">intent</a>, <a href="http://blog.jabawoki.com/tag/itsec/" title="itsec" rel="tag">itsec</a>, <a href="http://blog.jabawoki.com/tag/motivation/" title="motivation" rel="tag">motivation</a>, <a href="http://blog.jabawoki.com/tag/pentest/" title="PenTest" rel="tag">PenTest</a>, <a href="http://blog.jabawoki.com/tag/white-hat/" title="white hat" rel="tag">white hat</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/07/25/pentest-straw-poll/" title="PenTest Straw Poll (July 25, 2008)">PenTest Straw Poll</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2010/02/25/black-white-or-grey-what-colour-hat-do-you-wear/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Press Coverage &#8211; January 2010</title>
		<link>http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/</link>
		<comments>http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/#comments</comments>
		<pubDate>Sun, 17 Jan 2010 20:14:16 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[press]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=1726</guid>
		<description><![CDATA[Sunday Times &#8211; 17th January 2010 &#8211; Dark Pools / Hacking
Like
Unlike


	Tags: InfoSec, press

	Related posts
	
	The Asymmetry of Security (0)
	Snort Rocks! (2)
	Security as a Career (0)
	Press Coverage &#8211; March 2009 (0)
	Press Coverage &#8211; July 2009 (0)


]]></description>
			<content:encoded><![CDATA[<p><a href="http://business.timesonline.co.uk/tol/business/career_and_jobs/article6990623.ece" target="_blank">Sunday Times &#8211; 17th January 2010 &#8211; Dark Pools / Hacking</a></p>
<div class='wp_likes' id='wp_likes_post-1726'><a class='like' href="javascript:wp_likes.like(1726);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(1726);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F&amp;title=Press+Coverage+-+January+2010"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F&amp;title=Press+Coverage+-+January+2010"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F&amp;title=Press+Coverage+-+January+2010"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F&amp;headline=Press+Coverage+-+January+2010"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Press+Coverage+-+January+2010&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Press+Coverage+-+January+2010&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Press+Coverage+-+January+2010&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Press+Coverage+-+January+2010&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Press+Coverage+-+January+2010&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F&amp;title=Press+Coverage+-+January+2010&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2010%2F01%2F17%2Fpress-coverage-january-2010%2F&amp;title=Press+Coverage+-+January+2010"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/press/" title="press" rel="tag">press</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2009/08/26/press-coverage-march-2009/" title="Press Coverage &#8211; March 2009 (August 26, 2009)">Press Coverage &#8211; March 2009</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2009/08/26/press-coverage-july-2009/" title="Press Coverage &#8211; July 2009 (August 26, 2009)">Press Coverage &#8211; July 2009</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Computing</title>
		<link>http://blog.jabawoki.com/2009/11/08/cloud-computing/</link>
		<comments>http://blog.jabawoki.com/2009/11/08/cloud-computing/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 00:00:31 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[cloud]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=1716</guid>
		<description><![CDATA[I am getting a little annoyed with hearing people wax lyrical about &#8220;the cloud&#8221; and how its going to revolutionise the world. I have a news flash for you all, its not new and its not revolutionary!
First of all, lets define what we are talking about. There is a simple definition for Cloud Computing, and [...]]]></description>
			<content:encoded><![CDATA[<p>I am getting a little annoyed with hearing people wax lyrical about &#8220;the cloud&#8221; and how its going to revolutionise the world. I have a news flash for you all, its not new and its not revolutionary!<span id="more-1716"></span></p>
<p>First of all, lets define what we are talking about. There is a simple definition for Cloud Computing, and three models of operation as held by <a href="http://www.nist.gov/index.html" target="_blank">NIST</a>, these are:</p>
<p style="padding-left: 30px;"><strong>Definition:</strong></p>
<p style="padding-left: 30px;">Cloud computing is a model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model promotes availability and is composed of five essential <strong>characteristics,</strong> three <strong>service models</strong>, and four <strong>deployment models</strong>.</p>
<p style="padding-left: 30px;"><strong>Models of Operation:</strong></p>
<p style="padding-left: 30px;"><em>Cloud Software as a Service (SaaS).</em> The capability provided to the consumer is to use the provider’s applications running on a cloud infrastructure. The applications are accessible from various client devices through a thin client interface such as a web browser (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.</p>
<p style="padding-left: 30px;"><em>Cloud Platform as a Service (PaaS)</em>. The capability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage, but has control over the deployed applications and possibly application hosting environment configurations.</p>
<p style="padding-left: 30px;"><em>Cloud Infrastructure as a Service (IaaS). </em>The capability provided to the consumer is to provision processing, storage, networks, and other fundamental computing resources where the consumer is able to deploy and run arbitrary software, which can include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, deployed applications, and possibly limited control of select networking components (e.g., host firewalls).</p>
<p>Now, I am pretty sure that during my long career, I have seen a lot of companies doing IaaS and PaaS as a &#8220;Business as Usual&#8221; activity, haven&#8217;t you? In my experience, IaaS is nothing more than a traditional infrastructure outsourcing arrangement, as undertaken with IBM, HP/EDS or BT, while PaaS is just a simple hosting service offered by most ISP&#8217;s (I accept I am simplifying here). So what are we really talking about when the press pickup and pedal the term &#8220;cloud computing&#8221;. Looks to me like they are talking about SaaS, which again, has been around for a while, Hotmail anyone?, but not really taken off in the enterprise until it became &#8220;cloud computing&#8221;. So is this just a media spin to pedal Hotmail to the enterprise or just a natural progression from outsourcing boxes to apps? What is revolutionary here, I am yet to see.</p>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F&amp;title=Cloud+Computing"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F&amp;title=Cloud+Computing"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F&amp;title=Cloud+Computing"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F&amp;headline=Cloud+Computing"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Cloud+Computing&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Cloud+Computing&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Cloud+Computing&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Cloud+Computing&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Cloud+Computing&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F&amp;title=Cloud+Computing&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2009%2F11%2F08%2Fcloud-computing%2F&amp;title=Cloud+Computing"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/cloud/" title="cloud" rel="tag">cloud</a>, <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/25/pentest-straw-poll/" title="PenTest Straw Poll (July 25, 2008)">PenTest Straw Poll</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2009/11/08/cloud-computing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Asymmetry of Security</title>
		<link>http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/</link>
		<comments>http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/#comments</comments>
		<pubDate>Wed, 26 Nov 2008 19:24:14 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[IISP]]></category>
		<category><![CDATA[thoughts]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=1692</guid>
		<description><![CDATA[Personally, I think this is one of the most important concepts of today. Its simple enough to grasp and illustrates the point very well.
Consider these examples:

From an effort perspective, the effort required to secure a system is significantly less than that required to exploit it.
From a cost perspective, it is less expensive to prevent a [...]]]></description>
			<content:encoded><![CDATA[<p>Personally, I think this is one of the most important concepts of today. Its simple enough to grasp and illustrates the point very well.<span id="more-1692"></span></p>
<p>Consider these examples:</p>
<ol>
<li>From an effort perspective, the effort required to secure a system is significantly less than that required to exploit it.</li>
<li>From a cost perspective, it is less expensive to prevent a serious data breach than it is to clean up and recover from one.</li>
</ol>
<p>Point 1 above was illustrated very clearly to me on the <a href="http://blog.jabawoki.com/2008/08/01/iisp-top-gun-event-manchester-30-june-2008/" target="_self">IISP&#8217;s TopGun event</a> I attended recently, and is a scenario that you have to step back from to fully appreciate. Eg. If you have a smallish network, with most modern services such as web, email, mobile, databases, websites etc, then the effort to secure that is quite mammoth. You have to consider the perimeter, the information, how its stored and used, what services are on offer and the impacts etc. Then you have to consider every conceivable vulnerability, patching strategies and stay on top and at least up to speed with the curve of change. All of these efforts equate to a team of people, but all it takes to break in, is 1 person with a brain, motive, and a few freely available tools.</p>
<p>Point 2 of course, was illustrated very well by a <a href="http://www.vontu.com/downloads/ponemon_07_thankyou.asp" target="_blank">study </a>by the <a href="http://www.ponemon.org/" target="_blank">Pnemon Instutue LLC</a> in conjunction with <a href="http://www.pgp.com/" target="_blank">PGP</a> and <a href="http://www.vontu.com" target="_blank">Vontu (Symantec)</a>, this study evaluated the true cost of a breach of data security and considered factors such as direct and indirect costs, and has trended the data over the last few years with enlightening results.</p>
<p>Despite both of these points clearly illustrating that the best way to tackle the security conundrum is head on and proactively, those of us in the industry will all surely testify that getting the right backing, funding, and often, even the right audience with the business, is still a hard task. From my perspective, I will keep on trying, and keep on flying the flag in the hope that one day reality sets in and my job / life gets easier!</p>
<div class='wp_likes' id='wp_likes_post-1692'><a class='like' href="javascript:wp_likes.like(1692);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(1692);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;title=The+Asymmetry+of+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;title=The+Asymmetry+of+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;title=The+Asymmetry+of+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;headline=The+Asymmetry+of+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=The+Asymmetry+of+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=The+Asymmetry+of+Security&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=The+Asymmetry+of+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=The+Asymmetry+of+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=The+Asymmetry+of+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;title=The+Asymmetry+of+Security&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;title=The+Asymmetry+of+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/iisp/" title="IISP" rel="tag">IISP</a>, <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/thoughts/" title="thoughts" rel="tag">thoughts</a>, <a href="http://blog.jabawoki.com/tag/vulnerabilities/" title="Vulnerabilities" rel="tag">Vulnerabilities</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/06/30/iisp-topgun/" title="IISP Top Gun event, Manchester, 30 June 2008 (June 30, 2008)">IISP Top Gun event, Manchester, 30 June 2008</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/18/anything-that-can-be-engineered-by-mankind/" title="Anything that can be engineered by mankind&#8230;.. (November 18, 2008)">Anything that can be engineered by mankind&#8230;..</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/18/acme-supercomputing-inc-roadrunner-beware/" title="ACME Supercomputing Inc &#8211; Roadrunner Beware (November 18, 2008)">ACME Supercomputing Inc &#8211; Roadrunner Beware</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security as a Career</title>
		<link>http://blog.jabawoki.com/2008/11/19/security-as-a-career/</link>
		<comments>http://blog.jabawoki.com/2008/11/19/security-as-a-career/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 08:08:10 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=49</guid>
		<description><![CDATA[People often ask me whats the best way to get into security as a career. There are of course many views on this subject, but I don&#8217;t believe there is a clear answer. So rather than try and map out a path, lets look at some of the elements involved and some options.
The first thing [...]]]></description>
			<content:encoded><![CDATA[<p>People often ask me whats the best way to get into security as a career. There are of course many views on this subject, but I don&#8217;t believe there is a clear answer. So rather than try and map out a path, lets look at some of the elements involved and some options.</p>
<p><span id="more-49"></span>The first thing I want to say on the subject is that Security is more of a state of mind than anything else. I have a saying, to be good in security you need to be sceptical with a healthy dose of paranoia! This point of view will serve you well when it comes to security as it will allow you to be objective<!--more--> and not accept things at face value. Secondly, you need an inquisitive nature and a thirst for knowledge, To be the best at security you simply need to be able to hunt out the truth and learn the latest concepts and techniques very quickly. Finally, you need to be a good generalist, I realise this point is contentious, but I truly believe that you need to have a good general grasp of everything technology related as well as your preferred specialism in order to cover the breadth of security. Of course you can be an expert in your chosen specialism, but you must have a grasp of how &#8220;everything&#8221; fits together in order to be good.</p>
<p>OK, so where do you begin? Well, for starters, you need to have a long hard think about what you want out of life. What I mean by this is, are you a &#8220;techy&#8221; or are you a &#8220;manager&#8221;? I realise you can be both (as I am), but when your starting out, the subject is so broad you need a direction to head. If your a techy,  then you probably heading down the threat, vulnerability and controls path, with topics such as ethical hacking, intrusion detection and firewalls on your learning list. if however, your more of a manager, your probably heading down the opposite path towards topics such as strategy, assurance and governance. Once you have figured this out, you can start to look at the material, courses and support networks available for each road to help you get going.</p>
<p>One important factor that should always be included however is your own personal growth and development. What I mean by this are the softer skills such as communication, empathy, leadership, coaching etc. All of these skills are fundamental to your success and should be developed in equal measure with your chosen subject specialisms. The biggest issues I face as an employer in this sector is finding good security people with excellent soft skills. Its too easy in this game to get trapped in a world of regulations or bits &#8216;n&#8217; bytes, and forget that all your knowledge is pointless if you cannot make use of it and educate the world.</p>
<div class='wp_likes' id='wp_likes_post-49'><a class='like' href="javascript:wp_likes.like(49);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(49);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F&amp;title=Security+as+a+Career"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F&amp;title=Security+as+a+Career"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F&amp;title=Security+as+a+Career"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F&amp;headline=Security+as+a+Career"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Security+as+a+Career&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Security+as+a+Career&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Security+as+a+Career&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Security+as+a+Career&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Security+as+a+Career&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F&amp;title=Security+as+a+Career&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F19%2Fsecurity-as-a-career%2F&amp;title=Security+as+a+Career"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/25/pentest-straw-poll/" title="PenTest Straw Poll (July 25, 2008)">PenTest Straw Poll</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/01/pci-dss-is-it-dead/" title="PCI-DSS Is it dead? (July 1, 2008)">PCI-DSS Is it dead?</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/11/19/security-as-a-career/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ACME Supercomputing Inc &#8211; Roadrunner Beware</title>
		<link>http://blog.jabawoki.com/2008/11/18/acme-supercomputing-inc-roadrunner-beware/</link>
		<comments>http://blog.jabawoki.com/2008/11/18/acme-supercomputing-inc-roadrunner-beware/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 10:15:42 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[thoughts]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=1690</guid>
		<description><![CDATA[I read an interesting article the other day about the fact that Cray have toppled IBM of the top spot in the super computer race with a staggering 1.64 Petaflops of processing grunt from its XT Jaguar supercomputer. Of course, I expect this will be short lived given the Roadrunner has a theoretical 1.7 Petaflop [...]]]></description>
			<content:encoded><![CDATA[<p>I read an interesting article the other day about the fact that Cray have toppled IBM of the top spot in the super computer race with a staggering 1.64 Petaflops of processing grunt from its XT Jaguar supercomputer. Of course, I expect this will be short lived given the Roadrunner has a theoretical 1.7 Petaflop capacity.</p>
<p><span id="more-1690"></span><em>So what I hear you cry!</em></p>
<p>Well think of this, Cloud computing is here to stay and can yield some massive processing potential, but its still quite young and clouds tend to be privately owned and sold to the highest bidder. But what if we could all club together and build a cloud so big, so powerful it blew the Crays and IBMs of this world out of the water?</p>
<p><em>Again, I hear the crys of yeah right!</em></p>
<p>Well, ask yourself this, do I own a PS3? if the answer is yes, welcome to the &#8220;PSCloud&#8221;</p>
<p>The concept is simple, in a PS3 there is an IBM Cell Processor with 8 CPU cores, a very powerful CPU indeed! and guess what, IBM&#8217;s Roadrunner uses them too, yes, the Roadrunner has just short of 13,000 Cell Processors in it, of course it has quite a few AMD&#8217;s as well (6.4K), but the cells are the bulk of it.</p>
<p>So lets look at the facts, the same basic architecture used for the supercomputer market is in our homes, and cloud computing is here to stay, well I&#8217;m no rocket scientist but I reckon if we put these two concepts together, Roadrunner and Jaguar have a problem on their hands.</p>
<p>As of November 2008, over 16 million PS3&#8217;s have been sold around the world, of which we can assume by the design and nature of the unit, that nearly all of them are connected to the internet, so if we were able to join them into a single cloud, what sort of processing power could we achieve?</p>
<p>I ask you this&#8230;.. If 13,000 Cells and 6K AMD&#8217;s get you 1.6 Petaflops, what would 16million Cells get you?</p>
<p>All we need to make this happen is a software/firmware update to turn the PS3 into a cloud member and a peer based command and control mechanism, any programmers out there?</p>
<div class='wp_likes' id='wp_likes_post-1690'><a class='like' href="javascript:wp_likes.like(1690);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(1690);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F&amp;title=ACME+Supercomputing+Inc+-+Roadrunner+Beware"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F&amp;title=ACME+Supercomputing+Inc+-+Roadrunner+Beware"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F&amp;title=ACME+Supercomputing+Inc+-+Roadrunner+Beware"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F&amp;headline=ACME+Supercomputing+Inc+-+Roadrunner+Beware"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=ACME+Supercomputing+Inc+-+Roadrunner+Beware&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=ACME+Supercomputing+Inc+-+Roadrunner+Beware&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=ACME+Supercomputing+Inc+-+Roadrunner+Beware&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=ACME+Supercomputing+Inc+-+Roadrunner+Beware&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=ACME+Supercomputing+Inc+-+Roadrunner+Beware&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F&amp;title=ACME+Supercomputing+Inc+-+Roadrunner+Beware&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Facme-supercomputing-inc-roadrunner-beware%2F&amp;title=ACME+Supercomputing+Inc+-+Roadrunner+Beware"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/thoughts/" title="thoughts" rel="tag">thoughts</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/18/anything-that-can-be-engineered-by-mankind/" title="Anything that can be engineered by mankind&#8230;.. (November 18, 2008)">Anything that can be engineered by mankind&#8230;..</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/11/18/acme-supercomputing-inc-roadrunner-beware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anything that can be engineered by mankind&#8230;..</title>
		<link>http://blog.jabawoki.com/2008/11/18/anything-that-can-be-engineered-by-mankind/</link>
		<comments>http://blog.jabawoki.com/2008/11/18/anything-that-can-be-engineered-by-mankind/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 09:31:06 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[thoughts]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=1689</guid>
		<description><![CDATA[&#8230;&#8230;can be reverse engineered by mankind.
Its a simple mantra, but one that has served me well in security.
Think of of this way, it doesn&#8217;t matter how intelligent you are, someone, somewhere is more intelligent! When it comes to security this is never more true. As we all know, security is asymmetric, in so much that [...]]]></description>
			<content:encoded><![CDATA[<p>&#8230;&#8230;can be reverse engineered by mankind.</p>
<p>Its a simple mantra, but one that has served me well in security.</p>
<p><span id="more-1689"></span>Think of of this way, it doesn&#8217;t matter how intelligent you are, someone, somewhere is more intelligent! When it comes to security this is never more true. As we all know, security is asymmetric, in so much that the effort required to secure something is significantly more than that required to break into it. Given this point, it makes the mantra even more relevant! If security was symetrical, you would have a 1:1 effort relationship, however, as its not, (we will for the purposes of this article assume its 2:1, i.e. double the effort required to secure), it would theoretically take less brain power than it took to create the control to break it.</p>
<p>Obviously I accept that this is a very simplistic representation of the point, but one I think is valid.</p>
<div class='wp_likes' id='wp_likes_post-1689'><a class='like' href="javascript:wp_likes.like(1689);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(1689);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F&amp;title=Anything+that+can+be+engineered+by+mankind....."><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F&amp;title=Anything+that+can+be+engineered+by+mankind....."><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F&amp;title=Anything+that+can+be+engineered+by+mankind....."><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F&amp;headline=Anything+that+can+be+engineered+by+mankind....."><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Anything+that+can+be+engineered+by+mankind.....&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Anything+that+can+be+engineered+by+mankind.....&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Anything+that+can+be+engineered+by+mankind.....&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Anything+that+can+be+engineered+by+mankind.....&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Anything+that+can+be+engineered+by+mankind.....&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F&amp;title=Anything+that+can+be+engineered+by+mankind.....&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F18%2Fanything-that-can-be-engineered-by-mankind%2F&amp;title=Anything+that+can+be+engineered+by+mankind....."><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/thoughts/" title="thoughts" rel="tag">thoughts</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/18/acme-supercomputing-inc-roadrunner-beware/" title="ACME Supercomputing Inc &#8211; Roadrunner Beware (November 18, 2008)">ACME Supercomputing Inc &#8211; Roadrunner Beware</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/11/18/anything-that-can-be-engineered-by-mankind/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PenTest Straw Poll</title>
		<link>http://blog.jabawoki.com/2008/07/25/pentest-straw-poll/</link>
		<comments>http://blog.jabawoki.com/2008/07/25/pentest-straw-poll/#comments</comments>
		<pubDate>Fri, 25 Jul 2008 12:21:59 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[PenTest]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=98</guid>
		<description><![CDATA[Which Penetration Testing Qualification is best from a client perspective:
Which Penetration Testing Qualification is best from a Testing perspective:
(NB: I have deliberately excluded &#8220;accreditation schemes&#8221; such as CREST and CHECK)
Like
Unlike


	Tags: InfoSec, PenTest

	Related posts
	
	Black, White or Grey? What colour hat do you wear? (0)
	The Asymmetry of Security (0)
	Snort Rocks! (2)
	Security as a Career (0)
	Press Coverage &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p>Which Penetration Testing Qualification is best from a client perspective:<span id="more-98"></span><br />
Note: There is a poll embedded within this post, please visit the site to participate in this post's poll.</p>
<p>Which Penetration Testing Qualification is best from a Testing perspective:<br />
Note: There is a poll embedded within this post, please visit the site to participate in this post's poll.</p>
<p>(NB: I have deliberately excluded &#8220;accreditation schemes&#8221; such as CREST and CHECK)</p>
<div class='wp_likes' id='wp_likes_post-98'><a class='like' href="javascript:wp_likes.like(98);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(98);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F&amp;title=PenTest+Straw+Poll"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F&amp;title=PenTest+Straw+Poll"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F&amp;title=PenTest+Straw+Poll"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F&amp;headline=PenTest+Straw+Poll"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=PenTest+Straw+Poll&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=PenTest+Straw+Poll&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=PenTest+Straw+Poll&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=PenTest+Straw+Poll&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=PenTest+Straw+Poll&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F&amp;title=PenTest+Straw+Poll&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F25%2Fpentest-straw-poll%2F&amp;title=PenTest+Straw+Poll"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/pentest/" title="PenTest" rel="tag">PenTest</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2010/02/25/black-white-or-grey-what-colour-hat-do-you-wear/" title="Black, White or Grey? What colour hat do you wear? (February 25, 2010)">Black, White or Grey? What colour hat do you wear?</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/07/25/pentest-straw-poll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux Defence Tweaks</title>
		<link>http://blog.jabawoki.com/2008/07/06/linux-defence-tweaks/</link>
		<comments>http://blog.jabawoki.com/2008/07/06/linux-defence-tweaks/#comments</comments>
		<pubDate>Sun, 06 Jul 2008 19:13:11 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[InfoSec]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=52</guid>
		<description><![CDATA[If your planning on using Linux in a hostile environment, i.e. the Internet! then its worth thinking about some simple little tweaks to the TCP/IP stack in conjunction with some funky firewall madness to keep your box your own, and not end up &#8220;owned&#8221; too quickly!
Lets start with the TCP/IP stack. There are a number [...]]]></description>
			<content:encoded><![CDATA[<p>If your planning on using Linux in a hostile environment, i.e. the Internet! then its worth thinking about some simple little tweaks to the TCP/IP stack in conjunction with some funky firewall madness to keep your box your own, and not end up &#8220;owned&#8221; too quickly!</p>
<p>Lets start with the TCP/IP stack. There are a number of quick easy wins here that can help defend against attacks through making the default behaviours of the stack more in-line with what we would like:<span id="more-52"></span></p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>eth0<span style="color: #000000; font-weight: bold;">/</span>rp_filter
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>lo<span style="color: #000000; font-weight: bold;">/</span>rp_filter
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>all<span style="color: #000000; font-weight: bold;">/</span>log_martians
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>lo<span style="color: #000000; font-weight: bold;">/</span>log_martians
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>icmp_ignore_bogus_error_responses
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>icmp_echo_ignore_broadcasts
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>icmp_echo_ignore_all
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>all<span style="color: #000000; font-weight: bold;">/</span>accept_source_route
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>all<span style="color: #000000; font-weight: bold;">/</span>send_redirects
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>all<span style="color: #000000; font-weight: bold;">/</span>accept_redirects
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>all<span style="color: #000000; font-weight: bold;">/</span>secure_redirects
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>ip_dynaddr
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;10&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>tcp_fin_timeout
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1800&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>tcp_keepalive_time
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;15&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>ipfrag_time
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;2048&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>tcp_max_syn_backlog
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;32768 61000&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>ip_local_port_range
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;2&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>tcp_synack_retries</pre></div></div>

<p>Now, that little lot above needs some caveats. Firstly, use at your own risk! Secondly, As per usual, you often get a small performance hit when you start getting more secure, so test each tweak fully before you go into production. Once your happy with the ones you like, add then to your /etc/rc.local or other start up file of your choice.</p>
<p>The next step is to use iptables to help deal with dodgy looking traffic.</p>
<p><strong>Step 1</strong>, set-up a bunch of new chains:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-N</span> CHECK_FLAGS
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-N</span> ALLOW_ICMP
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-N</span> SRC_EGRESS
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-N</span> DST_EGRESS</pre></div></div>

<p><strong>Step 2</strong>, now lets get those chains to do something useful:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> ALL FIN,URG,PSH <span style="color: #660033;">-m</span> limit
        <span style="color: #660033;">--limit</span> <span style="color: #000000;">5</span><span style="color: #000000; font-weight: bold;">/</span>minute <span style="color: #660033;">-j</span> LOG <span style="color: #660033;">--log-level</span> <span style="color: #007800;">$LOG_LEVEL</span> <span style="color: #660033;">--log-prefix</span> <span style="color: #ff0000;">&quot;NMAP-XMAS:&quot;</span>
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> ALL FIN,URG,PSH <span style="color: #660033;">-j</span> DROP
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> SYN,RST SYN,RST <span style="color: #660033;">-m</span> limit
        <span style="color: #660033;">--limit</span> <span style="color: #000000;">5</span><span style="color: #000000; font-weight: bold;">/</span>minute <span style="color: #660033;">-j</span> LOG <span style="color: #660033;">--log-level</span> <span style="color: #007800;">$LOG_LEVEL</span> <span style="color: #660033;">--log-prefix</span> <span style="color: #ff0000;">&quot;SYN/RST:&quot;</span>
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> SYN,RST SYN,RST <span style="color: #660033;">-j</span> DROP
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> SYN,FIN SYN,FIN <span style="color: #660033;">-m</span> limit
        <span style="color: #660033;">--limit</span> <span style="color: #000000;">5</span><span style="color: #000000; font-weight: bold;">/</span>minute <span style="color: #660033;">-j</span> LOG <span style="color: #660033;">--log-level</span> <span style="color: #007800;">$LOG_LEVEL</span> <span style="color: #660033;">--log-prefix</span> <span style="color: #ff0000;">&quot;SYN/FIN:&quot;</span>
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> SYN,FIN SYN,FIN <span style="color: #660033;">-j</span> DROP
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> ALLOW_ICMP <span style="color: #660033;">-p</span> icmp <span style="color: #660033;">--icmp-type</span> echo-reply <span style="color: #660033;">-j</span> ACCEPT
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> ALLOW_ICMP <span style="color: #660033;">-p</span> icmp <span style="color: #660033;">--icmp-type</span> destination-unreachable
        <span style="color: #660033;">-j</span> ACCEPT
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> ALLOW_ICMP <span style="color: #660033;">-p</span> icmp <span style="color: #660033;">--icmp-type</span> echo-request <span style="color: #660033;">-j</span> ACCEPT
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> ALLOW_ICMP <span style="color: #660033;">-p</span> icmp <span style="color: #660033;">--icmp-type</span> time-exceeded <span style="color: #660033;">-j</span> ACCEPT
&nbsp;
        <span style="color: #000000; font-weight: bold;">for</span> SRCNET <span style="color: #000000; font-weight: bold;">in</span> <span style="color: #007800;">$EGRESS_NETS</span>; <span style="color: #000000; font-weight: bold;">do</span>
                <span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> SRC_EGRESS <span style="color: #660033;">-s</span> <span style="color: #007800;">$SRCNET</span> <span style="color: #660033;">-j</span> DROP
        <span style="color: #000000; font-weight: bold;">done</span>
&nbsp;
        <span style="color: #000000; font-weight: bold;">for</span> DSTNET <span style="color: #000000; font-weight: bold;">in</span> <span style="color: #007800;">$EGRESS_NETS</span>; <span style="color: #000000; font-weight: bold;">do</span>
                <span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> DST_EGRESS <span style="color: #660033;">-d</span> <span style="color: #007800;">$DSTNET</span> <span style="color: #660033;">-j</span> DROP
        <span style="color: #000000; font-weight: bold;">done</span></pre></div></div>

<p><strong>Step 3</strong>, Apply the prior two steps to your input, forward and output chains as needed:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> <span style="color: #007800;">$CHAIN</span> <span style="color: #660033;">-i</span> <span style="color: #007800;">$EXT_INT</span> <span style="color: #660033;">-j</span> SRC_EGRESS
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> <span style="color: #007800;">$CHAIN</span> <span style="color: #660033;">-i</span> <span style="color: #007800;">$EXT_INT</span> <span style="color: #660033;">-j</span> DST_EGRESS
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> <span style="color: #007800;">$CHAIN</span> <span style="color: #660033;">-i</span> <span style="color: #007800;">$EXT_INT</span> <span style="color: #660033;">-p</span> icmp <span style="color: #660033;">-j</span> ALLOW_ICMP
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> <span style="color: #007800;">$CHAIN</span> <span style="color: #660033;">-i</span> <span style="color: #007800;">$EXT_INT</span> <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">-j</span> CHECK_FLAGS</pre></div></div>

<p>Variables. In all of the above, variables are used to save typing!, here are some of the important variables, the rest are fairly self explanatory:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #007800;">EGRESS_NETS</span>=<span style="color: #ff0000;">&quot;
        172.16.0.0/12
        224.0.0.0/4
        240.0.0.0/5
        14.0.0.0/8
        169.254.0.0/16
        172.16.0.0/12
        192.0.2.0/24
        192.88.99.0/24
        192.18.0.0/15
        0.0.0.0/8
        &quot;</span></pre></div></div>

<p>What we have just done is setup some new chains, apply some filters that can identify dodgy looking traffic and do something useful with it (limit it rather than drop it, as we don&#8217;t want to arouse suspicion with our attackers). Then apply all that nice Packet Mangling to each of our primary chains.</p>
<p>I provide all of this advice for free, with no guarantees, any use of the above code should be with full testing prior to its use in a production environment. Enjoy!</p>
<div class='wp_likes' id='wp_likes_post-52'><a class='like' href="javascript:wp_likes.like(52);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(52);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F&amp;title=Linux+Defence+Tweaks"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F&amp;title=Linux+Defence+Tweaks"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F&amp;title=Linux+Defence+Tweaks"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F&amp;headline=Linux+Defence+Tweaks"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Linux+Defence+Tweaks&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Linux+Defence+Tweaks&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Linux+Defence+Tweaks&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Linux+Defence+Tweaks&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Linux+Defence+Tweaks&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F&amp;title=Linux+Defence+Tweaks&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F&amp;title=Linux+Defence+Tweaks"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/linux/" title="linux" rel="tag">linux</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/05/free-security-for-all/" title="Free Security for All! (July 5, 2008)">Free Security for All!</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/07/06/linux-defence-tweaks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Free Security for All!</title>
		<link>http://blog.jabawoki.com/2008/07/05/free-security-for-all/</link>
		<comments>http://blog.jabawoki.com/2008/07/05/free-security-for-all/#comments</comments>
		<pubDate>Sat, 05 Jul 2008 21:42:49 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=51</guid>
		<description><![CDATA[Its time for a small reality check. Security does not have to cost the earth. Just because your a large corporate with over a 1000 employees doesn&#8217;t mean you &#8220;have&#8221; to buy brand name security. In fact, I would argue quite the opposite, invest that money in some quality people, treat them well, and get [...]]]></description>
			<content:encoded><![CDATA[<p>Its time for a small reality check. <strong>Security does not have to cost the earth.</strong> Just because your a large corporate with over a 1000 employees doesn&#8217;t mean you &#8220;have&#8221; to buy brand name security. In fact, I would argue quite the opposite, invest that money in some quality people, treat them well, and get 10 times the return on investment you planned.<span id="more-51"></span></p>
<p>lets put it into perspective. First of all, you have to accept that open source software is your friend, then accept that just because it doesn&#8217;t have a &#8220;GUI&#8221; doesn&#8217;t mean its any more complex. Ok, now that you have accepted an alternate reality, it is time to look at some comparisons. Lets look at some good, typically expensive security controls, typically, usually reserved for Banks, because &#8220;they have the budget for it&#8221;.</p>
<p>We will start with IDS &#8220;Intrusion Detection System&#8221;, specifically, the network variety (NIDS), deployed across the infrastructure, and designed to spot malicious traffic flowing across your network and highlight suspicious activity that may be happening under the radar. If you were to buy one of the very excellent and very expensive commercial solutions, on a medium size network, you could be spending 6 figures before breakfast. That&#8217;s a serious hole in a security budget, so what other options exist? Well, for a start, &#8220;snort&#8221; an open source, well maintained and mature project that&#8217;s been around for years. Its 100% free, and will only cost you the physical hardware and some administrative overhead getting it up and running. Its very scalable, equally configurable and its signatures are maintained by a community of experts in the field. What more could you ask for? Ok, so the reality is, in our scenario of 6 figures for the commercial solution, the free one would likely cost you 10-20K in hardware and specialist labour, but whats 20K compared to £200,000K, I know which one I would prefer to sign off.</p>
<p>Next, lets look at another hot topic, SIMS &#8220;Security Information Management Solution&#8221;. This is another typically large investment to essentially, analyse logs generated by the infrastructure. Again, the concept has been available in open source for years. Syslog servers shipping logs to each other with some sort of Perl analysis scripting has been around forever, and again, its just the labour and hardware costs to consider.</p>
<p>What about Firewalls? The staple diet of all organisations of any size. Now, these can be quite cheap or ridiculously expensive. I have built, deployed and managed most of the top end ones, and can after a career of using them, I can happily say, I would deploy a well configured &#8220;iptables&#8221; firewall in Linux over a Cisco or Checkpoint any day of the week. Ok, so you don&#8217;t get the nice gui with all your 200 firewalls in, but, there are options&#8230;. Gui&#8217;s exist, and again, a specialist can easily make this whole concept easily manageable for any organisation. Now, if a key control for limiting the impact of a hack is through network segregation, then the ability to deploy low cost firewalls can only improve the overall security of the network</p>
<p>So, if I had a 1000 user network to protect, a budget of 500K and full autonomy. I would spend 100K on every open source solution available, home grow some of my own, contract a team of top class Linux / security gurus to get it all up and running, then sit back in my SOC &#8220;Security Operations Centre&#8221; and wait for the siren to go off! Of course, I would take the other 400K as my bonus <img src='http://blog.jabawoki.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div class='wp_likes' id='wp_likes_post-51'><a class='like' href="javascript:wp_likes.like(51);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(51);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F&amp;title=Free+Security+for+All%21"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F&amp;title=Free+Security+for+All%21"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F&amp;title=Free+Security+for+All%21"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F&amp;headline=Free+Security+for+All%21"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Free+Security+for+All%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Free+Security+for+All%21&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Free+Security+for+All%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Free+Security+for+All%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Free+Security+for+All%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F&amp;title=Free+Security+for+All%21&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F&amp;title=Free+Security+for+All%21"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/linux/" title="linux" rel="tag">linux</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/06/linux-defence-tweaks/" title="Linux Defence Tweaks (July 6, 2008)">Linux Defence Tweaks</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/07/05/free-security-for-all/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do Credentials equal Credibility?</title>
		<link>http://blog.jabawoki.com/2008/07/05/do-credentials-equal-credibility/</link>
		<comments>http://blog.jabawoki.com/2008/07/05/do-credentials-equal-credibility/#comments</comments>
		<pubDate>Sat, 05 Jul 2008 16:23:28 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=48</guid>
		<description><![CDATA[This is a debate I regularly get into with my team. Personally, I think that yes, credentials can bring credibility with an audience, or with a prospective employer. Lets look at how this works:
C&#124;EH (Certified Ethical Hacker). Anyone who has been in that area of work for a number of years will state that the [...]]]></description>
			<content:encoded><![CDATA[<p>This is a debate I regularly get into with my team. Personally, I think that yes, credentials can bring credibility with an audience, or with a prospective employer. Lets look at how this works:</p>
<p>C|EH (Certified Ethical Hacker). Anyone who has been in that area of work for a number of years will state that the C|EH is rubbish, and, of course, they are right. Having done the qualification, I can vouch for the fact that it is a tools based approach to hacking, with a heavy slant towards using windows as your <span id="more-48"></span>attacking platform (which is wrong for so many reasons). It does however, give you the basics, and teaches you about basic methodologies etc. &#8230;..So, you might ask, why do I say I am a C|EH, if I know its pointless? Simple. To a purist hacker, its a waste of time, but commercially it has value as it is recognised by clients and companies alike as the de facto standard for hacking. This difference in perception is a prime example of how a qualification can bring credibility with the audience you want. All of my team are C|EH, because, when I write a proposal for a client, I can say, all my team are &#8220;Certified Ethical Hackers&#8221;. They of course understand this and as a bonus, the first two words add a level of &#8220;comfort&#8221; to what sounds like a venture into the dark side!</p>
<p>Now, let&#8217;s look at another qualification (CISSP) &#8220;Certified Information Systems Security Professional&#8221;. This is about the best baseline security qualification in play today. It is very broad in it&#8217;s syllabus and well maintained through its CPE &#8220;Continual Professional Education&#8221; requirement. This qualification really does work on both sides of the fence. Clients like it and so do the professionals What it doesn&#8217;t do is guarantee that the holder of the qualification is a deep specialist in a given area, but what it does very well, is mandate a baseline of knowledge with real width in the subject of security.</p>
<p>Here are my views on how they pin together:</p>
<p>Some example credentials that mean something to your peers:</p>
<ul>
<li>GIAC&#8217;s (Any of them!)</li>
<li>CITP</li>
<li>OSCP</li>
</ul>
<p>Some example credentials That mean something to your clients or employers:</p>
<ul>
<li>ITiL</li>
<li>PRINCE2</li>
<li>C|EH</li>
<li>CCNA</li>
</ul>
<p>Some example credentials that mean something to everyone:</p>
<ul>
<li>CISSP</li>
<li>CCNP</li>
</ul>
<p>This is not the most exhaustive list, but is a start. The underlying piece of advice here is, when your picking a credential to study for and invest in, think how it will add value to you and your situation, and see if there is a better option available. Knowledge can be learned for free, credentials have to be bought!</p>
<div class='wp_likes' id='wp_likes_post-48'><a class='like' href="javascript:wp_likes.like(48);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(48);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F&amp;title=Do+Credentials+equal+Credibility%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F&amp;title=Do+Credentials+equal+Credibility%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F&amp;title=Do+Credentials+equal+Credibility%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F&amp;headline=Do+Credentials+equal+Credibility%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Do+Credentials+equal+Credibility%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Do+Credentials+equal+Credibility%3F&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Do+Credentials+equal+Credibility%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Do+Credentials+equal+Credibility%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Do+Credentials+equal+Credibility%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F&amp;title=Do+Credentials+equal+Credibility%3F&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Fdo-credentials-equal-credibility%2F&amp;title=Do+Credentials+equal+Credibility%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/25/pentest-straw-poll/" title="PenTest Straw Poll (July 25, 2008)">PenTest Straw Poll</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/07/05/do-credentials-equal-credibility/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Snort Rocks!</title>
		<link>http://blog.jabawoki.com/2008/07/02/snort-rocks/</link>
		<comments>http://blog.jabawoki.com/2008/07/02/snort-rocks/#comments</comments>
		<pubDate>Wed, 02 Jul 2008 16:21:36 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=28</guid>
		<description><![CDATA[Ok, its been ages since I actually had snort up and running, so long in fact that the last time I used it, ACID was still the best way to deal with the alerts! Well after a couple of days (well a couple of hours here and there at least) I have a fully functional [...]]]></description>
			<content:encoded><![CDATA[<p>Ok, its been ages since I actually had snort up and running, so long in fact that the last time I used it, ACID was still the best way to deal with the alerts! Well after a couple of days (well a couple of hours here and there at least) I have a fully functional set of snort sensors in place on public and private segments of my networks, all feeding to a centralised database with &#8220;BASE&#8221; handling the analysis! woohoo. small victories are the best!<span id="more-28"></span></p>
<p>I can definatley say its come a long way. It was much easier to install, and only took a small amount of syntax debugging to figure out the configs. During my research / re-learning curve though it would seem that version 2.8 with the stream5 processor is not as good as version 2.4 with the flow processor at detecting portscans. This was certainley the concensus of the community, and after a bit of playing I can agree. However, I now have sfPortscan running with stream5 and its seems pretty accurate to me, so I am certainly happy with the results.</p>
<p>BASE is also a welcome move onwards from what used to be a very clunky interface. It seems light and intuitive, with decent features. I think it could do with the addition of some basic graphs, rather than having to use the graph engine to define your graphs each time, but on the whole i think it is certainly a good alternative to spending a large amount of money on a commercial product. Certainly the ability to abstract the managemnet interface, data storage and sensors from each other gives you a highly scaleable model to use a basis for a large scale deployment.</p>
<p>Of course, if you don&#8217;t fancy the pain of compiling code from scratch, or your just dam lazy, check out <a title="EasyIDS" href="http://www.skynet-solutions.net/easyids/" target="_blank">EasyIDS</a> for a complete &#8220;IDS in a box&#8221; that gives you everything I just said with none of the hastle!</p>
<p>&#8230;.You just can&#8217;t ingore the momentum that opensource has gained <img src='http://blog.jabawoki.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div class='wp_likes' id='wp_likes_post-28'><a class='like' href="javascript:wp_likes.like(28);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(28);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F&amp;title=Snort+Rocks%21"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F&amp;title=Snort+Rocks%21"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F&amp;title=Snort+Rocks%21"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F&amp;headline=Snort+Rocks%21"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Snort+Rocks%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Snort+Rocks%21&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Snort+Rocks%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Snort+Rocks%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Snort+Rocks%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F&amp;title=Snort+Rocks%21&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F&amp;title=Snort+Rocks%21"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/linux/" title="linux" rel="tag">linux</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/07/06/linux-defence-tweaks/" title="Linux Defence Tweaks (July 6, 2008)">Linux Defence Tweaks</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/05/free-security-for-all/" title="Free Security for All! (July 5, 2008)">Free Security for All!</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/07/02/snort-rocks/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How Security Should Work</title>
		<link>http://blog.jabawoki.com/2008/07/01/how-security-should-work/</link>
		<comments>http://blog.jabawoki.com/2008/07/01/how-security-should-work/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 12:33:27 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=22</guid>
		<description><![CDATA[I work in a world of standards, opinions, controls and countermeasures, all encompassed in a foreign language of &#8220;InfoSec&#8221; and &#8220;ItSec&#8221;. This of course, while entertaining, is of little use to the world. I would like to propose a simple concept, probably high level, and I am sure my peers would argue is &#8220;inadequate&#8221;, that [...]]]></description>
			<content:encoded><![CDATA[<p>I work in a world of standards, opinions, controls and countermeasures, all encompassed in a foreign language of &#8220;InfoSec&#8221; and &#8220;ItSec&#8221;. This of course, while entertaining, is of little use to the world. I would like to propose a simple concept, probably high level, and I am sure my peers would argue is &#8220;inadequate&#8221;, that said however, hear me out:<span id="more-22"></span></p>
<p>Ok, so the basic concept is simple, setup three primary work streams or &#8220;functions&#8221;, 1 is a Risk Asssesment and Classifcation Function, 2 is a People / Process/ Awareness, and 3 is Controls, both protective and detective as needed.</p>
<p>The idea is that the risk assessment process runs in a cycle with inputs and outputs at the core of the system which serves as the engine for security. Its easier to explain in a diagram, take a look:</p>
<p><a href="http://blog.jabawoki.com/wp-content/uploads/2008/07/infosec2.jpg"><img class="alignnone size-medium wp-image-25" title="infosec2" src="http://blog.jabawoki.com/wp-content/uploads/2008/07/infosec2-197x300.jpg" alt="" width="197" height="300" /></a></p>
<p>Genious or Madness, its your decision, I like it because its simple and can be applied to any situation. Of course I agree with arguments such as &#8220;where is the governance?&#8221;, &#8220;what about strategy&#8221; etc, but quite simply, thats not what this is. This is a simple security process that allows you to feed information in and get solutions out.</p>
<div class='wp_likes' id='wp_likes_post-22'><a class='like' href="javascript:wp_likes.like(22);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(22);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F&amp;title=How+Security+Should+Work"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F&amp;title=How+Security+Should+Work"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F&amp;title=How+Security+Should+Work"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F&amp;headline=How+Security+Should+Work"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=How+Security+Should+Work&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=How+Security+Should+Work&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=How+Security+Should+Work&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=How+Security+Should+Work&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=How+Security+Should+Work&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F&amp;title=How+Security+Should+Work&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fhow-security-should-work%2F&amp;title=How+Security+Should+Work"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/25/pentest-straw-poll/" title="PenTest Straw Poll (July 25, 2008)">PenTest Straw Poll</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/07/01/how-security-should-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI-DSS Is it dead?</title>
		<link>http://blog.jabawoki.com/2008/07/01/pci-dss-is-it-dead/</link>
		<comments>http://blog.jabawoki.com/2008/07/01/pci-dss-is-it-dead/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 12:04:42 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[PCI-DSS]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=20</guid>
		<description><![CDATA[First of all, legislation doesn&#8217;t die, it just becomes BAU. PCI is still a pain for most, but as a race, us Humans are fickle creatures who like our topics and news to be current, so the latest and greatest will always be at the top of the agenda.
PCI on the other hand has a [...]]]></description>
			<content:encoded><![CDATA[<p>First of all, legislation doesn&#8217;t die, it just becomes BAU. PCI is still a pain for most, but as a race, us Humans are fickle creatures who like our topics and news to be current, so the latest and greatest will always be at the top of the agenda.<span id="more-20"></span></p>
<p>PCI on the other hand has a few cards left to play, first we see the move from 1.1 to 1.2, and although the content is still uncertain, it is likley to include calrifications of &#8220;what they actually meant&#8221; and additions. Aside from the revisions now and future to the PCI-DSS, PA-DSS, and other relevant standards are likeley to appear to help ensure that those organisations we entrust with our data, do the minimum to keep hold of it.</p>
<p>of course, we have seen some clarifications and &#8220;movement&#8221; on the existing standard, as well as finally, some teeth being displayed by the PCI through fines.</p>
<p>In my view, PCI is by no means dead, or even old news, its just part of the legislative landscape that is a part of business today, not to be ignored.</p>
<div class='wp_likes' id='wp_likes_post-20'><a class='like' href="javascript:wp_likes.like(20);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(20);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F&amp;title=PCI-DSS+Is+it+dead%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F&amp;title=PCI-DSS+Is+it+dead%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F&amp;title=PCI-DSS+Is+it+dead%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F&amp;headline=PCI-DSS+Is+it+dead%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=PCI-DSS+Is+it+dead%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=PCI-DSS+Is+it+dead%3F&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=PCI-DSS+Is+it+dead%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=PCI-DSS+Is+it+dead%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=PCI-DSS+Is+it+dead%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F&amp;title=PCI-DSS+Is+it+dead%3F&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F01%2Fpci-dss-is-it-dead%2F&amp;title=PCI-DSS+Is+it+dead%3F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/pci-dss/" title="PCI-DSS" rel="tag">PCI-DSS</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/25/pentest-straw-poll/" title="PenTest Straw Poll (July 25, 2008)">PenTest Straw Poll</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/07/01/pci-dss-is-it-dead/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IISP Top Gun event, Manchester, 30 June 2008</title>
		<link>http://blog.jabawoki.com/2008/06/30/iisp-topgun/</link>
		<comments>http://blog.jabawoki.com/2008/06/30/iisp-topgun/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 23:34:19 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[IISP]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=19</guid>
		<description><![CDATA[Courtesy of the Institute for Information Security Professionals
As I mentioned in the opening CEO article, the inaugural Top Gun event in Manchester was a great success on many fronts.  We had 20 participants, organised into the Red and Blue teams, plus 5 members of the Control Team, and the day just seemed to fly past, [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Courtesy of the <a href="https://www.instisp.org/" target="_blank">Institute for Information Security Professionals</a></p>
<p style="text-align: justify;">As I mentioned in the opening CEO article, the inaugural Top Gun event in Manchester was a great success on many fronts.  We had 20 participants, organised into the Red and Blue teams, plus 5 members of the Control Team, and the day just seemed to fly past, so intense was the concentration, interaction, ingenuity and fun.<span id="more-19"></span></p>
<p>We cannot give too much away as to the content of the case study or the processes we followed on the day, for fear that we might spoil some of the element of surprise for participants in future events.  Suffice to say that those who were there threw themselves into the exercise and, accordingly got the most out of it, as well as proposing a few additional suggestions for developing and improving it for future players.</p>
<p>Let us however, convey the particular views of a member of one of the teams, and let them tell you what they thought of the event.</p>
<p style="text-align: justify; padding-left: 30px;">“TopGun, The Blue View. (Jay Abbott, PwC)</p>
<p style="padding-left: 30px;">I have to admit, I was genuinely sceptical about the TopGun event as the idea of playing the Security equivalent of Battleships during one of my busiest times of the year was not one that featured far up the “to do” list, that said, I am genuinely pleased that I made the time to attend. We arrived with very little information about what was planned, and were immediately split into two teams, Red and Blue, The Red were of course the attackers, and Blue were the defenders and the teams split had been pre-planned by the organisers to ensure that a good cross section of skills rested in each team to keep things fair.</p>
<p style="padding-left: 30px;">The remit was simple, we each were given suitable pieces of a puzzle, i.e. some deliberately sketchy information related to the organisation, typical of that you would find on your first day of work or your first information gathering exercise. From there it was a case of building a better picture of what you have and figuring out the best way forward (sound familiar?). At this point, the teams were physically split and departed into adjacent “war rooms” to prepare their respective strategies. We each could communicate with our “control” staff, who acted as the coordination of the event and holders of information. The co-ordination role was pivotal in the success of the event as they were able to coordinate the virtual attack and defence strategies in real-time to keep the feeling of real-life and to ensure that the game was fair.</p>
<p style="padding-left: 30px;">From a blue perspective it was business as usual, we had a budget and an environment to protect, we had to evaluate the skills in our team, establish specialism’s that could work in key streams, and run the entire thing like a project.</p>
<p style="padding-left: 30px;">All in all it was a very worthwhile day that created a great deal of discussion and provoked much debate. What I personally took from the day was something that I see all too often, but is perhaps not as obvious to all, to quote Paul Dorey on the day it is summed up in the phrase “Security is Asymmetric”. Put simply this is the fact that someone attacking an organisation need only find one hole or vulnerability in order to succeed, while those protecting the organisation must try to plug every hole and mitigate every vulnerability to be secure.”</p>
<p style="text-align: center;"><img class="size-medium wp-image-104 aligncenter" style="border: 0pt none;" title="image002" src="http://blog.jabawoki.com/wp-content/uploads/2008/08/image002.jpg" alt="" width="490" height="367" /></p>
<p style="text-align: justify;"><em>Event wrap-up discussion and lessons learnt – great work everyone!</em></p>
<p>The participants captured their comments on an evaluation form and we are reviewing and acting on those comments.  They also scored the event out of a scale of 1 to 5, and rated the event at 4.3 overall, but with specific scores of 4.5 for facilitation and presentation, and 4.6 for opportunity to discuss and exchange ideas.  A great success by any measure.</p>
<p>Thanks to all involved, and to PwC, our hosts for the day.</p>
<p style="text-align: justify;">Courtesy of the <a href="https://www.instisp.org/" target="_blank">Institute for Information Security Professionals</a></p>
</p>
<div class='wp_likes' id='wp_likes_post-19'><a class='like' href="javascript:wp_likes.like(19);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(19);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F&amp;title=IISP+Top+Gun+event%2C+Manchester%2C+30+June+2008"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F&amp;title=IISP+Top+Gun+event%2C+Manchester%2C+30+June+2008"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F&amp;title=IISP+Top+Gun+event%2C+Manchester%2C+30+June+2008"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F&amp;headline=IISP+Top+Gun+event%2C+Manchester%2C+30+June+2008"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=IISP+Top+Gun+event%2C+Manchester%2C+30+June+2008&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=IISP+Top+Gun+event%2C+Manchester%2C+30+June+2008&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=IISP+Top+Gun+event%2C+Manchester%2C+30+June+2008&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=IISP+Top+Gun+event%2C+Manchester%2C+30+June+2008&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=IISP+Top+Gun+event%2C+Manchester%2C+30+June+2008&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F&amp;title=IISP+Top+Gun+event%2C+Manchester%2C+30+June+2008&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Fiisp-topgun%2F&amp;title=IISP+Top+Gun+event%2C+Manchester%2C+30+June+2008"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/iisp/" title="IISP" rel="tag">IISP</a>, <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/25/pentest-straw-poll/" title="PenTest Straw Poll (July 25, 2008)">PenTest Straw Poll</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/06/30/iisp-topgun/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Layered Security</title>
		<link>http://blog.jabawoki.com/2008/06/30/layered-security/</link>
		<comments>http://blog.jabawoki.com/2008/06/30/layered-security/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 22:30:42 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=18</guid>
		<description><![CDATA[The concept is simple, the more obstacles in the way the better. Let me abstract the concept for you&#8230;..
&#8230;..you put your file in a safe, I crack into the safe.
&#8230;&#8230;&#8230;you put your file in a safe, and lock the safe in a strong/secure room, I crack the room then the safe.
&#8230;&#8230;&#8230;..You put the file in [...]]]></description>
			<content:encoded><![CDATA[<p>The concept is simple, the more obstacles in the way the better. Let me abstract the concept for you&#8230;..</p>
<p>&#8230;..you put your file in a safe, I crack into the safe.</p>
<p>&#8230;&#8230;&#8230;you put your file in a safe, and lock the safe in a strong/secure room, I crack the room then the safe.<span id="more-18"></span></p>
<p>&#8230;&#8230;&#8230;..You put the file in the safe, in the room, at the bottom of the ocean, I go elsehere to get a different file!</p>
<p>People often talk to me about controls, and want to know which one is best. The answer typically is either all, none, or both. The more layers you have, the more security you have. But lest we foget the basics, understand the cost of the control vs the cost of the asset through a formal Risk Assessment Process.</p>
<div class='wp_likes' id='wp_likes_post-18'><a class='like' href="javascript:wp_likes.like(18);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(18);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F&amp;title=Layered+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F&amp;title=Layered+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F&amp;title=Layered+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F&amp;headline=Layered+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Layered+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Layered+Security&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Layered+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Layered+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Layered+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F&amp;title=Layered+Security&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F06%2F30%2Flayered-security%2F&amp;title=Layered+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/25/pentest-straw-poll/" title="PenTest Straw Poll (July 25, 2008)">PenTest Straw Poll</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/06/30/layered-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
