<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-34883581</id><updated>2012-02-16T22:27:48.266-05:00</updated><category term='Firewalls'/><category term='IDS'/><category term='Security'/><title type='text'>Security Data Mining</title><subtitle type='html'>If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle. - The Art of War - Sun Tzu</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://securitydatamining.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34883581/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://securitydatamining.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Araf Karsh</name><uri>http://www.blogger.com/profile/08692657964904569309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_1lItfk2Ab9o/SRLYy-SCQKI/AAAAAAAAAFU/Jj1CrPjWnn4/S220/Karsh_usa.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-34883581.post-115897949583050847</id><published>2007-01-29T10:34:00.052-05:00</published><updated>2010-03-29T14:18:44.016-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Firewalls'/><category scheme='http://www.blogger.com/atom/ns#' term='IDS'/><title type='text'>The Art of Digital War - [Part 4] Understanding the Threat and Normalization</title><content type='html'>&lt;span style="color: red; font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;span class="Apple-style-span" style="color: black; font-family: 'Times New Roman'; font-size: medium;"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span style="font-size: 16px;"&gt;&lt;a href="http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-part-1-digital.html" style="font-family: arial;"&gt;Part 1&lt;/a&gt;&lt;span style="font-family: arial;"&gt;&amp;nbsp;/&amp;nbsp;&lt;/span&gt;&lt;a href="http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-part-2-alarms-in.html" style="font-family: arial;"&gt;Part 2&lt;/a&gt;&lt;span style="font-family: arial;"&gt;&amp;nbsp;/&amp;nbsp;&lt;/span&gt;&lt;a href="http://securitydatamining.blogspot.com/2006/09/art-of-digital-war-part-3-abstract.html" style="font-family: arial;"&gt;Part 3&lt;/a&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&amp;nbsp;/ &lt;/span&gt;&lt;span class="Apple-style-span" style="color: black; font-size: medium;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://securitydatamining.blogspot.com/2006/08/art-of-digital-war-part-4-risk-and.html"&gt;Part 4&lt;/a&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: black; font-family: 'Times New Roman'; font-size: medium;"&gt;/&lt;span style="font-family: arial;"&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, sans-serif; font-size: 13px;"&gt;You have seen the abstract data types in the section 3 of this series. The most critical element in this is to understand the context of these atomic events, which brings in the next topic “Context based DNA – Data Normalization and Aggregation”. This modal moves away from the concept of static normalization and aggregation rules. Without data normalization in the security domain, the end user has to deal with 50,000 to 80,000 thousand different types of Alerts (this is not the number of alerts an analyst receives every second). Normalization process (across the vendors) reduces this to a manageable number (100 to 300 Normalized Alert).&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;These rules will be formed dynamically based on the network context, placement of the security devices, placement of important assets and the traffic flow.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;Normalizing the data across the vendors is the key to build vendor neutral correlation rules. Normalization helps to understand the digital attack patterns before diving deep into actual signature produced by the devices. Without Normalization linking events across the vendors will not be possible and writing rules per vendor will leads into rule management nightmares.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red; font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;span class="Apple-style-span" style="color: black; font-family: 'Times New Roman'; font-size: medium;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red; font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;span class="Apple-style-span" style="color: black; font-family: 'Times New Roman'; font-size: medium;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;&lt;b&gt;Current Normalization Pyramid&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red; font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;span class="Apple-style-span" style="color: black; font-family: 'Times New Roman'; font-size: medium;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_1lItfk2Ab9o/S7DIULH91dI/AAAAAAAAANY/oURGEqmaRZo/s1600-h/current_normalization.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="324" src="http://2.bp.blogspot.com/_1lItfk2Ab9o/S7DIULH91dI/AAAAAAAAANY/oURGEqmaRZo/s1600/current_normalization.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: arial; font-size: 14px;"&gt;Following data shows how the current pyramid works with vendor alarms.&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_1lItfk2Ab9o/S7DIzpFK80I/AAAAAAAAANc/jFRI9iZn_aw/s1600-h/sample_data_pyramid_normalization.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="318" src="http://2.bp.blogspot.com/_1lItfk2Ab9o/S7DIzpFK80I/AAAAAAAAANc/jFRI9iZn_aw/s640/sample_data_pyramid_normalization.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: arial; font-size: 14px;"&gt;&lt;b&gt;Breaking the Pyramid&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;The pyramid structure was definitely a good start. However, over a period of time the digital attacks were so sophisticated and complex, the pyramid structure become very rigid. However, this doesn’t mean that normalization is not right. Normalization is the key. The question over here is can we avoid this rigid pyramid like structure and can we have something very flexible and dynamic.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;Before we move onto the breaking the pyramid let us understand some of the sophisticated digital attacks and what makes them sophisticated and complex.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;b&gt;Analyzing the Attack by a Virus/Worms&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;In this section let us look at one of the sophisticated Virus “MyTob” and see its behaviors.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" height="640" src="http://3.bp.blogspot.com/_1lItfk2Ab9o/S7DJ5LHtICI/AAAAAAAAANg/YEJoOs2wqXU/s640/virus_anatomy.png" width="626" /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="-webkit-text-decorations-in-effect: none; color: black; font-family: Arial, sans-serif; font-size: 13px;"&gt;With the above data if you compare the behaviors of virus / worms you a see the new entrants are more sophisticated compare to the viruses of early 2000. For example, MyTob has a built in SMPT engine to send out Emails. It has a backdoor and virus author can send commands via IRC channels control the system remotely. It propagates using two completely different mechanisms (an application exploit on port 445 and using SMTP engine on port 25). Once infected its self defense mechanisms are more robust compare to the earlier ones. So, the sophistication of these worms clearly shows the need for breaking the pyramid model and come up with a more flexible and adaptive model for the data normalization.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="-webkit-text-decorations-in-effect: none; color: black; font-family: Arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;&lt;b&gt;Data Aggregation&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;Current set of products does aggregation based on a static aggregation rules based vendor alarms or normalized alarms. This needs to be changed and it should be based on network topology and the placement of the device. Most common fields for aggregation is based on device, device alarm, severity, source, destination, and destination port. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;Take the example of a firewall placed near the border router at the perimeter. This device logs lot of Access Denied device Alarm (which is based on the firewall rule) for the inbound traffic (traffic from internet to the enterprise). Over here based on the above rule which aggregates data on &lt;u&gt;device, device alarm, severity, source, destination and destination port&lt;/u&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;However, as the firewall has already blocked the inbound connection (at the perimeter) what’s more important is to aggregate the data based on &lt;u&gt;device, device alarm, and source and destination port&lt;/u&gt;. This will give a very good aggregation on firewall data as well as a good view on the attacker his modus of operandi. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;At the same time, if the firewall allows the (inbound) connection then the data needs to be aggregated based on &lt;u&gt;device, device alarm, source, source port, destination and destination port&lt;/u&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;Following tables shows the event aggregation based on different parameters which is specific to the context of the security device and the network traffic. The table shows different rules for the Firewall (placed at the perimeter) Device Alarm Network Access Denied and Network Access Allowed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_1lItfk2Ab9o/S7DKUtvivII/AAAAAAAAANk/B5xYWEPzzaQ/s1600-h/aggregation_rules.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="356" src="http://2.bp.blogspot.com/_1lItfk2Ab9o/S7DKUtvivII/AAAAAAAAANk/B5xYWEPzzaQ/s640/aggregation_rules.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;b&gt;Conclusion&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: arial; font-size: medium;"&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US" style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;The objective of this article is to show how the rigid pyramid fails handling sophisticated attacks by hackers as well as automated attacks by virus / worms. Next section follows up with an adaptive Normalization technique along with context sensitive aggregation rules.&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34883581-115897949583050847?l=securitydatamining.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitydatamining.blogspot.com/feeds/115897949583050847/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34883581&amp;postID=115897949583050847' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34883581/posts/default/115897949583050847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34883581/posts/default/115897949583050847'/><link rel='alternate' type='text/html' href='http://securitydatamining.blogspot.com/2006/08/art-of-digital-war-part-4-risk-and.html' title='The Art of Digital War - [Part 4] Understanding the Threat and Normalization'/><author><name>Araf Karsh</name><uri>http://www.blogger.com/profile/08692657964904569309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_1lItfk2Ab9o/SRLYy-SCQKI/AAAAAAAAAFU/Jj1CrPjWnn4/S220/Karsh_usa.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_1lItfk2Ab9o/S7DIULH91dI/AAAAAAAAANY/oURGEqmaRZo/s72-c/current_normalization.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34883581.post-115897964889598755</id><published>2006-09-21T05:30:00.001-04:00</published><updated>2010-03-29T11:52:16.215-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Firewalls'/><category scheme='http://www.blogger.com/atom/ns#' term='IDS'/><title type='text'>The Art of Digital War - [Part 3]  Abstract Data Types in the Security Domain</title><content type='html'>&lt;span style="font-family: Arial;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;a href="http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-part-1-digital.html" style="font-family: arial;"&gt;Part 1&lt;/a&gt;&lt;span style="font-family: arial;"&gt; / &lt;/span&gt;&lt;a href="http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-part-2-alarms-in.html" style="font-family: arial;"&gt;Part 2&lt;/a&gt;&lt;span style="font-family: arial;"&gt; / &lt;/span&gt;&lt;a href="http://securitydatamining.blogspot.com/2006/09/art-of-digital-war-part-3-abstract.html" style="font-family: arial;"&gt;Part 3&lt;/a&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&amp;nbsp;/ &lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://securitydatamining.blogspot.com/2006/08/art-of-digital-war-part-4-risk-and.html"&gt;Part 4&lt;/a&gt;&lt;/span&gt; /&amp;nbsp;&lt;span style="font-family: arial;"&gt;&lt;strong&gt;&lt;br /&gt;&lt;br /&gt;Abstract Data Types in the Security Domain&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;The objective of this section is to identify the key abstract data types required to handle any type of security related data to identify the Digital Intrus&lt;/span&gt;&lt;span style="font-family: arial;"&gt;ions / Extrusions and take necessary remediation process to mitigate thos&lt;/span&gt;&lt;span style="font-family: arial;"&gt;e attacks.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;Handling of millions of network events (generated by Routers, Firewalls, IDS/IPS etc) per day is one of the key elements of all the Security Management solutions. Other set of information collected for processing and mining the attack pattern in&lt;/span&gt;&lt;span style="font-family: arial;"&gt;volves OS logs, vulnerability information of an asset, network topology, Asset Database, Identity Management&lt;/span&gt;&lt;span style="font-family: arial;"&gt; systems and Application Logs. So you end up having lot of different data types. One of the biggest challenge&lt;/span&gt;&lt;span style="font-family: arial;"&gt;s is to normalize this information across the vendors. However, before the normalization process the&lt;/span&gt;&lt;span style="font-family: arial;"&gt; key element is to identify and classify the data types.&lt;/span&gt;&lt;a href="http://photos1.blogger.com/blogger/7894/789/1600/Abstract_Data_Type.0.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" src="http://photos1.blogger.com/blogger/7894/789/400/Abstract_Data_Type.0.png" style="cursor: pointer; display: block; margin: 0px auto 10px; text-align: center;" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family: arial;"&gt;So, let me start with two fundamental data types and let us &lt;/span&gt;&lt;span style="font-family: arial;"&gt;see how these data &lt;/span&gt;&lt;span style="font-family: arial;"&gt;fi&lt;/span&gt;&lt;span style="font-family: arial;"&gt;ts into all the data sources available from different vendors and creates Dig&lt;/span&gt;&lt;span style="font-family: arial;"&gt;ital ‘Conversations’. Following are the two abstract data types.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;1. Entities&lt;br /&gt;2. Atomic Events&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;&lt;strong&gt;Entity&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24725511&amp;amp;postID=115886650993181619#_ftn1" name="_ftnref1" title=""&gt;&lt;span style="font-family: arial;"&gt;[1]&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;An Entity is a ‘thing’ in &lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;the system with a certain pr&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;o&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;perties. For example An&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt; ‘Asset’ (a machine) with a set of serv&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;ices (applications) running (listening on a port)&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;&lt;a href="http://photos1.blogger.com/blogger/7894/789/1600/Entity_Asset_with_Attributes.3.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" src="http://photos1.blogger.com/blogger/7894/789/400/Entity_Asset_with_Attributes.0.png" style="cursor: pointer; float: right; margin: 0pt 0pt 10px 10px;" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;, or a ‘Us&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;er’ with one or more roles and privileges or an ‘Application’ which is&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt; farmed out on a server farm.&lt;/span&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; Attributes of an Entity usually remain static (for certain Entities&lt;/span&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; static attributes als&lt;/span&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;o changes frequently) while state of an Entity changes frequently.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt; &lt;/span&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;&lt;br /&gt;The first diagram shows the Attributes and States of an Asset (Financial Server) as an Entity. OS, Services and the CVE information is for illustration purposes only. Understanding an Asset and the services it supports is the key to figure out what needs to be protected on Network. Behind every Asset (or Services to be specific) you have very&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt; important data. &lt;span style="font-family: arial;"&gt;Services (any application listening&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;&lt;a href="http://photos1.blogger.com/blogger/7894/789/1600/Entity_User_with_Attributes.1.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" src="http://photos1.blogger.com/blogger/7894/789/400/Entity_User_with_Attributes.0.png" style="cursor: pointer; float: right; margin: 0pt 0pt 10px 10px;" /&gt;&lt;/a&gt;&lt;/span&gt; on a port) are the doors to the world. Any SOC (Security Operation Center) Analyst must have a clear understanding of the Key Assets and Services on the network.&lt;br /&gt;&lt;br /&gt;The second diagram shows&lt;span style="font-family: Arial; font-size: 100%;"&gt; the Attributes&lt;/span&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; and States of a User as an Entity. User, applications and CVE ID for illustration purposes only.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;&lt;br /&gt;In the same line you can create an Application as an Entity with vulnerability profiles and network&lt;/span&gt;&lt;span style="font-size: 100%;"&gt;&lt;a href="http://photos1.blogger.com/blogger/7894/789/1600/Entity_Intruder_with_Attributes.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" style="font-family: arial;"&gt;&lt;img alt="" border="0" src="http://photos1.blogger.com/blogger/7894/789/400/Entity_Intruder_with_Attributes.png" style="cursor: pointer; float: right; margin: 0pt 0pt 10px 10px;" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt; characteristics (like how does it communicates in the network and with what protocols and what kind of services it provides, impact of these protocols/services in the event&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt; of a failure etc). &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div class="MsoNormal" style="font-family: arial;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;span style="font-family: arial;"&gt;The third diagram illustrates an Intruder as an Entity with a certain characteristics like Intruder Classification (Internal / External or an Automated) impact of the attacks, Attack sophistication etc. All the these characteristics with Attack behaviors and recent  states of the Intruder&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-family: arial;"&gt; (which includes the recent attack history, damage caused, number of incident cases results in creating a normalized Threat Score for the Intruder which is on a scale of 1-10 with 10 as the Highest Threat. Threat modeling for an Intruder is the key to identify its (Intruder’s) threat to an &lt;st1:place st="on"&gt;&lt;st1:city st="on"&gt;Enterprise&lt;/st1:city&gt;&lt;/st1:place&gt;.&lt;/span&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: arial;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-family: arial;"&gt;The fourth diagram shows &lt;a href="http://arafkarsh.googlepages.com/Virus-Worm-Behaviours-Summary.pdf"&gt;Virus / Worm&lt;/a&gt; as an Entity and its potential attributes which&lt;/span&gt;&lt;a href="http://photos1.blogger.com/blogger/7894/789/1600/Entity_Virusr_with_Attributes.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" style="font-family: arial;"&gt;&lt;img alt="" border="0" src="http://photos1.blogger.com/blogger/7894/789/400/Entity_Virusr_with_Attributes.png" style="cursor: pointer; float: right; margin: 0pt 0pt 10px 10px;" /&gt;&lt;/a&gt; describes its Infection and Attack Behaviors and its ability to cause damages in th&lt;/span&gt;&lt;span style="font-size: 100%;"&gt;e enterprise. Classification of Virus and &lt;st1:city st="on" style="font-family: arial;"&gt;&lt;st1:place st="on"&gt;Worms&lt;/st1:place&gt;&lt;/st1:city&gt;&lt;span style="font-family: arial;"&gt; and creating a Virus Entity database helps in recognizing the similar patterns and do predictive analysis on the future Viruses and BOT threats.&lt;/span&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;So, the idea of an Entity is clear it’s identifying the ‘thing(s)’ internal / external to your enterprise with a certain set of characteristics. As I mentioned in the &lt;a href="http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-part-1-digital.html"&gt;first part&lt;/a&gt; of this series, the key is Identifying your Assets (Know yourself) and identifying&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt; the Intruders (Know your Enemy). Depends on the Enterprise Network size the types Entities will wary, however the key Entities identified in this section remains same (may be with more attributes and states). Now let us look at what’s an Atomic Event and how does it ties two entities together.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;Atomic Event&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;br /&gt;An Atomic Event is created when any of the two entities talks to each other. Atomic Events can’t be broken down further. For Example a Firewall Network Status Event (Connection open or Connection closed Event). Collecting millions of these Atomic Events from hundreds of security devices was a huge task in late 1990’s and early 2000. First generation of the Security Data Management Vendors concentrated on this task and did a pretty good job in collecting and centrally managing all the Atomic Events. Correlation technologies correlate these Atomic Events giving more value to the end users in identifying the internal or external threats. 90% of the Atomic Events are noise. However, these technologies need to move from Event Management to Entity Management resulting in creating environment specific context sensitive conversations. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;So, the bottom line is you can’t create Atomic Events without entities. Here are the some of the examples of Atomic Events by connecting two Entities.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt; &lt;br /&gt;&lt;div class="MsoNormal" face="arial" style="font-family: arial;"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;PIX Firewall Message&lt;/span&gt;&lt;span style="font-family: arial; font-size: 100%;"&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="color: maroon;"&gt;2004 21:19:23: %PIX-2-106001: Inbound TCP connection denied from 172.12.10.146/2493 to 172.169.110.21/80 flags SYN on interface outside&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;2004 21:19:23: %PIX-2-106001: Inbound TCP connection denied from 172.12.10.146/2494 to 172.169.110.22/80 flags SYN on interface outside&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;2004 21:19:23: %PIX-2-106001: Inbound TCP connection denied from 172.12.10.146/2495 to 172.169.110.23/80 flags SYN on interface outside&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;a href="http://photos1.blogger.com/blogger/7894/789/1600/Events_PIX_Messages.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" src="http://photos1.blogger.com/blogger/7894/789/400/Events_PIX_Messages.png" style="cursor: pointer; display: block; margin: 0px auto 10px; text-align: center;" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: arial;"&gt;&lt;strong&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-family: arial;"&gt;Conversation&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;Grouping of Atomic Events in a specific environment (Zones) and context creates a conversation. Read the &lt;/span&gt;&lt;a href="http://the-digital-security.blogspot.com/2006/03/art-of-digital-war-part-2-alarms-in.html"&gt;&lt;span style="font-family: arial;"&gt;Part 2&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: arial;"&gt; of this series to know more about various types of Conversations. Entities, Atomic Events, Context Sensitive Conversations will give more accurate Enterprise Security Posture to CSO / CISO.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: #000099; font-family: arial;"&gt;&lt;strong&gt;References&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24725511&amp;amp;postID=115886650993181619#_ftnref1" name="_ftn1" title=""&gt;&lt;span style="font-family: arial;"&gt;[1]&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: arial;"&gt; &lt;a href="http://webster.com/dictionary/Entity"&gt;The Merriam Webster &lt;/a&gt;definition for an Entity is&lt;br /&gt;independent, separate, or self-contained existence&lt;br /&gt;the existence of a thing as contrasted with its attributes&lt;br /&gt;something that has separate and distinct existence and objective or conceptual reality&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red; font-size: 85%;"&gt;&lt;span style="font-family: arial;"&gt;Work in Progress ......&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34883581-115897964889598755?l=securitydatamining.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitydatamining.blogspot.com/feeds/115897964889598755/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34883581&amp;postID=115897964889598755' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34883581/posts/default/115897964889598755'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34883581/posts/default/115897964889598755'/><link rel='alternate' type='text/html' href='http://securitydatamining.blogspot.com/2006/09/art-of-digital-war-part-3-abstract.html' title='The Art of Digital War - [Part 3]  Abstract Data Types in the Security Domain'/><author><name>Araf Karsh</name><uri>http://www.blogger.com/profile/08692657964904569309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_1lItfk2Ab9o/SRLYy-SCQKI/AAAAAAAAAFU/Jj1CrPjWnn4/S220/Karsh_usa.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34883581.post-115897932600071745</id><published>2006-03-23T00:05:00.001-05:00</published><updated>2010-03-29T11:50:52.530-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Firewalls'/><category scheme='http://www.blogger.com/atom/ns#' term='IDS'/><title type='text'>The Art of Digital War - [Part 1] Digital Intrusion Timeline</title><content type='html'>&lt;a href="http://photos1.blogger.com/blogger/7894/789/1600/Digital_Instrusion_Time_Line.0.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" src="http://photos1.blogger.com/blogger/7894/789/320/Digital_Instrusion_Time_Line.jpg" style="cursor: pointer; float: right; margin: 0pt 0pt 10px 10px;" /&gt;&lt;/a&gt;  &lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;a href="http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-part-1-digital.html"&gt;Part 1&lt;/a&gt; / &lt;a href="http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-part-2-alarms-in.html"&gt;Part 2&lt;/a&gt; / &lt;a href="http://securitydatamining.blogspot.com/2006/09/art-of-digital-war-part-3-abstract.html"&gt;Part 3&lt;/a&gt;&amp;nbsp;/ &lt;a href="http://securitydatamining.blogspot.com/2006/08/art-of-digital-war-part-4-risk-and.html"&gt;Part 4&lt;/a&gt; /&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;Digital Intrusion Time Line&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Arial;"&gt;&lt;br /&gt;The objective of this article is to identify the issues around a digital intrusion. The following diagram shows the picture of a digital intrusion time line (by an internal or external Intruder or an automated Intruder – virus / worm / bots etc) along with the Vulnerability time line and security monitoring tools with current features and future building blocks.&lt;/span&gt; &lt;span style="font-family: Arial;"&gt;The focus is on the fundamental problems, and it will not go into analyzing different digital attack patterns or any vulnerability analysis.&lt;/span&gt; &lt;span style="font-family: Arial;"&gt;&lt;br /&gt;&lt;br /&gt;Latest &lt;a href="http://www.cert.org/stats/cert_stats.html"&gt;CERT&lt;/a&gt; reports a total of 5990&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn1" name="_ftnref1" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[1]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; vulnerabilities for the year 2005 an increase of 58.5% from the year 2004 and a 3402% increase from the year 1995. Usually vulnerability in an application is due to un-identified bug in the code. However there are times when backdoors written explicitly in some application to get into a users machine. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-family: Arial;"&gt;&lt;br /&gt;&lt;br /&gt;An intentional backdoor into any system is more dangerous than an accidental bug due to an oversight or bad coding practices. Huge debate gone over the recent WMF&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn2" name="_ftnref2" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[2]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; (Windows Meta File) Vulnerability – &lt;a href="http://www.microsoft.com/technet/security/advisory/912840.mspx"&gt;Microsoft Security Advisory (912840)&lt;/a&gt; whether it’s an intentional backdoor or not. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt; &lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="color: blue; font-family: Arial;"&gt;“Speeding up the patch process is never going to solve the problem; it is never going to be fast enough. We need to be investing very heavily in zero-day defenses, because another zero-day will happen. There is a lot of talk about whether (the software vendor has) gotten the patch out in time, but the real conversation should be about risk removal, not risk mitigation.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;Richard Ford, associate professor of computer science, Florida Institute of Technology &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;strong&gt;&lt;i&gt;&lt;span style="color: blue; font-weight: normal;"&gt;“Application vulnerabilities propagate so rapidly today that the old methods of dealing with them no longer suffice. New standards like AVDL offer one of the best hopes of breaking this cycle by dramatically reducing the time between the discovery of a new vulnerability and the effective response at enterprise sites” &lt;/span&gt;&lt;/i&gt;&lt;/strong&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: right;"&gt;&lt;strong&gt;&lt;span style="font-weight: normal;"&gt;John Pescatore - &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-family: Arial;"&gt;Vice President of Security Research&lt;b&gt;, &lt;/b&gt;&lt;strong&gt;&lt;span style="font-weight: normal;"&gt;Gartner&lt;/span&gt;&lt;/strong&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;b&gt;&lt;span style="color: #993300; font-family: Arial;"&gt;Security Threat Modeling&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;Security Threat Modeling is an essential process to protect the Assets (or applications). It helps the organizations to determine the correct controls and produce effective counter measures within the budget. Effective management and understanding of the vulnerabilities is required to efficiently defend attacks against those (vulnerabilities). As the number vulnerabilities increases year by year the customer needs a mechanism to identify the most critical vulnerabilities in his enterprise. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;b&gt;&lt;span style="color: #993300; font-family: Arial;"&gt;The Core of Digital Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;The three key things in digital security for the enterprise are identifying and classifying the &lt;span style="color: #993300;"&gt;Intruder&lt;/span&gt; and their attacks on the &lt;span style="color: #993300;"&gt;Assets&lt;/span&gt; and the &lt;span style="color: #993300;"&gt;Damage&lt;/span&gt; it can cause on the enterprise or the potential damage on the similar attacks in the future. Regulatory compliance and other government regulations revolve around the core or rather monitoring the health of the core.&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;The above image shows the Intruder attack sophistication and the incident time line which starts when the intruder finds the vulnerability in the enterprise and the actual break-in and the damage he causes by information leakage, denial of service on critical systems, and attack on other systems etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;The Defense sections shows the 3 phases which is as follows; the Monitoring phase, Attack discovery on the assets and the Containment and the Remediation process. The key will be how efficiently we can correlate and provide relevant information back to the end user at the right time so that he/she (the analyst) can stop the attack (while in progress) before it wrecks havoc in the enterprise.&lt;span style="font-size: 0px;"&gt; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;The three core areas (&lt;u&gt;Intruder, Assets and Damage&lt;/u&gt;) will remain same today (2006) or even after 15 or 20 or 2000 years. What matters is how good we are at identifying these three key elements and build a robust Security Threat Model around it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;b&gt;&lt;span style="color: #993300; font-family: Arial;"&gt;Intruders and their Attacks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;Classification of an Intruder is critical in understanding the Threat the intruder posses. A good Security Threat Model needs to understand the strengths, weakness and the attack methodologies of any Intruder. The Intruders are classified into 3 – Internal, External and Automated (Robotic) Intruder. Classification of Intruders helps us to prioritize the incidents and focus on the relevant incident. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;b&gt;&lt;span style="color: #993300; font-family: Arial;"&gt;Assets&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;Security revolves around protecting the Assets (Behind every Asset there will be some applications). Asset oriented Security Monitoring will be the key in this evolution. Application infrastructure of the future will be heavily distributed in nature with SOA (Service Oriented Architecture). Protecting the business services will be the most important aspect in the service oriented world.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;Asset Oriented Security Monitoring will eventually move towards applications and in the future will lead to protecting the collection of web services&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn3" name="_ftnref3" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[3]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; which the applications published. Security will go down to the fabric of the distributed applications. According to Forrester the ERP&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn4" name="_ftnref4" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[4]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; Market will be $24 Billion by the end of 2008. SAP&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn5" name="_ftnref5" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[5]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; and Oracle the leading ERP Application providers will be moving to Service Oriented architecture by the end of 2008.&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;Classification of assets is important to protect the assets efficiently. Asset value will not yield this classification. For example an asset which contains blog and user forum data will be classified differently compared to assets with financial transaction databases. There will be assets which require protection while data at rest&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn6" name="_ftnref6" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[6]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; as well as protection of data on the wire.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;b&gt;&lt;span style="color: #993300; font-family: Arial;"&gt;Damage caused by Incidents and its impact&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;The above chart and depicts the damage impact if a break in happens. Today the users do the impact manually and lot of different software applications will be used in the complete process. Streamlining this business process and using this data to further improve process will help in quick remediation and containment.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;Tracking the cost of Incidents, resources required for containment and remediation, and the time spent will help in predicting the actual cost involved if the similar attacks happens in the future. This information can be used in the Security Threat Model to narrow down the attacks and vulnerabilities where the potential damage will be very high.&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;b&gt;&lt;span style="color: #993300; font-family: Arial;"&gt;Digital Security - Building Blocks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;The first generation of security management tools processed data from security devices like firewalls, intrusion detection systems, vulnerability scanners apart from network devices like routers and switches. Correlation technologies correlated the events across the systems. However, these systems focused more on handling the events. This model is an extension of log management systems which started of the Digital Security Management space.&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;The second generation Security Management tools focuses more on entities like Assets and its relevance, Network and its importance, Attacker (with classification) and threat levels, Vulnerability Severity relevant to the network. This model deviates from the first generation event based management as the focus is on the entity rather than the events. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;Entity model in the second generation simplifies the process of building a Security Threat Model compared to first generation event model based Risk or Threat Scores. The CSO&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn7" name="_ftnref7" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[7]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; / CISO are focused more on protecting their assets instead of worrying about how many events passed through the network.&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;The third generation of Security Management will move closer to where the real action in the enterprise digital world – ‘The Applications’. As per the Forrester and Gartner&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn8" name="_ftnref8" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[8]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; most of the enterprise applications will move towards SOA&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn9" name="_ftnref9" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[9]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; (Service Oriented Architecture) by the end of 2008-2009. Cisco already announced the Cisco AON (Application Oriented Network) Architecture where the focus is on routing the application specific traffic. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;End of the day security is all about protecting the data (information or knowledge) created by the applications (Assets in the enterprise) and the applications runs 24/7.&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;The Fourth generation of Security Management will see the convergence of physical security with information security. As per Forrester forecast&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn10" name="_ftnref10" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[10]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: 0px;"&gt; &lt;/span&gt;Security Convergence spending for Europe and &lt;st1:place st="on"&gt;North America&lt;/st1:place&gt; combined will be $11 Billion dollars in 2008 compare to $506 million in 2004.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;b&gt;&lt;span style="color: #993300; font-family: Arial;"&gt;Conclusion&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;The objective of this article is to highlight the core of digital security and the expectations around the core. Around 30-40 years ago we knew that the fundamentals of Atom&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn11" name="_ftnref11" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[11]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; are electron, proton and neutron. As the science progressed we realized that protons and neutrons were made up of quarks&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn12" name="_ftnref12" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[12]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; and discovered hundreds of sub atomic particles&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn13" name="_ftnref13" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[13]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; and then finally to ‘Strings’ and the String theory&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn14" name="_ftnref14" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[14]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;, However, electrons, protons and neutrons still remains as fundamental particles (at atomic level).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;So, let me re-instate the core (&lt;span style="color: red;"&gt;AID&lt;/span&gt;) again. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;span style="color: red;"&gt;Assets &lt;span style="color: black;"&gt;(Know yourself)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;Intruders &lt;span style="color: black;"&gt;(Know your enemy)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;Damage&lt;/span&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;Do we think the above three elements will change in the year 2131&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftn15" name="_ftnref15" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[15]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;. The answer is a big ‘NO’. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;There will never be a silver bullet which will solve all the problems. What you can do is to improve the probability of successfully defending any attack. After so much of advances in medical sciences the common cold still exists! &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="color: #cc0000;"&gt;&lt;em&gt;If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle. &lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;em&gt;&lt;span style="color: #990000;"&gt;The Art of War - Sun Tzu. &lt;/span&gt;&lt;span style="color: #990000; font-style: italic;"&gt;Lived: 500-320 BC&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black; font-family: Arial;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;hr align="left" size="1" style="height: 3px;" width="33%" /&gt;&lt;br /&gt;&lt;div id="ftn1"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref1" name="_ftn1" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[1]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;span style="font-size: 0px;"&gt; &lt;/span&gt;2005 Vulnerability List&lt;span style="font-size: 0px;"&gt; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;a href="http://www.cert.org/stats/cert_stats.html"&gt;http://www.cert.org/stats/cert_stats.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn2"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref2" name="_ftn2" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span class="MsoFootnoteReference" style="font-family: arial;"&gt;[2]&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;span style="font-size: 0px;"&gt; &lt;/span&gt;WMF Vulnerability – MS Advisory 912840 -&lt;span style="font-size: 0px;"&gt; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/912840.mspx"&gt;http://www.microsoft.com/technet/security/advisory/912840.mspx&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;Security Focus - &lt;span class="headline"&gt;Zero-day WMF flaw underscores patch problems by Robert Lemos – January 12, 2006&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial;"&gt;&lt;a href="http://www.securityfocus.com/news/11368"&gt;http://www.securityfocus.com/news/11368&lt;/a&gt; &lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn3"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref3" name="_ftn3" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[3]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; Forrester – Large Enterprises Pursue Strategic SOA by Randy Heffner - April 5, 2005&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;span class="hilite"&gt;&lt;a href="http://www.forrester.com/Research/Document/0,7211,36580,00.html"&gt;http://www.forrester.com/Research/Document/0,7211,36580,00.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn4"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref4" name="_ftn4" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[4]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; &lt;span class="hilite"&gt;ERP Apps – Technology and Industry Battle heats up by Paul Hamerman, R Wang – June 9, 2005&lt;span style="font-size: 0px;"&gt; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span class="hilite" style="font-size: 100%;"&gt;&lt;span style="font-family: Arial;"&gt;Site: &lt;a href="http://www.forrester.com/Research/Document/0,7211,37058,00.html"&gt;http://www.forrester.com/Research/Document/0,7211,37058,00.html&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn5"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref5" name="_ftn5" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[5]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; &lt;span class="hilite"&gt;SAPs&lt;/span&gt; &lt;span class="hilite"&gt;Big&lt;/span&gt; &lt;span class="hilite"&gt;Bet&lt;/span&gt; To Revolutionize App by Erin Kinikin – August 3, 2004&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;a href="http://www.forrester.com/Research/Document/0,7211,34739,00.html"&gt;http://www.forrester.com/Research/Document/0,7211,34739,00.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn6"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref6" name="_ftn6" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[6]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;span style="font-size: 0px;"&gt; &lt;/span&gt;Forrester Wave – Data Encryption Solutions Q3, 2005&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;a href="http://www.forrester.com/Research/Document/0,7211,36486,00.html"&gt;http://www.forrester.com/Research/Document/0,7211,36486,00.html&lt;/a&gt;&lt;span style="font-size: 0px;"&gt; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;Application Security – &lt;a href="http://www.appsecinc.com/"&gt;http://www.appsecinc.com/&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;Encryption of Data at Rest - &lt;a href="http://www.appsecinc.com/presentations/Encryption_of_Data_at_Rest.pdf"&gt;http://www.appsecinc.com/presentations/Encryption_of_Data_at_Rest.pdf&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;DMReview – Information Management: Encryption at Rest&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;a href="http://www.dmreview.com/article_sub.cfm?articleId=1033567"&gt;http://www.dmreview.com/article_sub.cfm?articleId=1033567&lt;/a&gt;&lt;span style="font-size: 0px;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn7"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref7" name="_ftn7" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[7]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial;"&gt; CSO Online - &lt;a href="http://www.csoonline.com/research/leadership/cso_role.html"&gt;http://www.csoonline.com/research/leadership/cso_role.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn8"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref8" name="_ftn8" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[8]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; Gartner – &lt;a href="http://www.gartner.com/"&gt;http://www.gartner.com/&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;Future of &lt;st1:place st="on"&gt;&lt;st1:city st="on"&gt;Enterprise&lt;/st1:city&gt;&lt;/st1:place&gt; Security – September 15, 2004&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;a href="http://www.gartner.com/DisplayDocument?ref=g_search&amp;amp;id=454567"&gt;http://www.gartner.com/DisplayDocument?ref=g_search&amp;amp;id=454567&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;Cool Vendors in Security and Privacy – March 28, 2005&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;a href="http://www.gartner.com/DisplayDocument?ref=g_search&amp;amp;id=475999"&gt;http://www.gartner.com/DisplayDocument?ref=g_search&amp;amp;id=475999&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn9"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref9" name="_ftn9" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[9]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; Forrester – Your Strategic SOA Platform Vision By Randy Heffner – March 29, 2005&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;Site:&lt;span style="font-size: 0px;"&gt; &lt;/span&gt;&lt;a href="http://www.forrester.com/Research/Document/0,7211,35951,00.html"&gt;http://www.forrester.com/Research/Document/0,7211,35951,00.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;Development Roles In The World Of Service-Oriented Architecture – January, 13, 2005&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;a href="http://www.forrester.com/Research/Document/0,7211,35822,00.html"&gt;http://www.forrester.com/Research/Document/0,7211,35822,00.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;SOAP Vs REST – A Comparison – By Randy Heffner, September 13, 2004&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;a href="http://www.forrester.com/Research/Document/0,7211,35361,00.html"&gt;http://www.forrester.com/Research/Document/0,7211,35361,00.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;Forrester Wave – &lt;st1:place st="on"&gt;&lt;st1:city st="on"&gt;Enterprise&lt;/st1:city&gt;&lt;/st1:place&gt; Service Bus Q4 2005&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;a href="http://www.forrester.com/Research/Document/0,7211,36162,00.html"&gt;http://www.forrester.com/Research/Document/0,7211,36162,00.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn10"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref10" name="_ftn10" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[10]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; Forrester - Trends 2005: Security Convergence Gets Real By Steve Hunt – January 11, 2005&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;a href="http://www.forrester.com/Research/Document/0,7211,36137,00.html"&gt;http://www.forrester.com/Research/Document/0,7211,36137,00.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;Converged &lt;span class="hilite"&gt;IT&lt;/span&gt; And Physical Security: Small But Real – By &lt;a href="http://www.forrester.com/ER/Research/List/Analyst/Personal/0,2237,607,00.html"&gt;Laura Koetzle&lt;/a&gt; April 15, 2005&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoFootnoteText"&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt;&lt;a href="http://www.forrester.com/Research/Document/0,7211,36680,00.html"&gt;http://www.forrester.com/Research/Document/0,7211,36680,00.html&lt;/a&gt; &lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn11"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref11" name="_ftn11" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[11]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial;"&gt; CERN – The worlds largest particle physics lab - &lt;a href="http://public.web.cern.ch/Public/Welcome.html"&gt;http://public.web.cern.ch/Public/Welcome.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn12"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref12" name="_ftn12" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[12]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; &lt;st1:place st="on"&gt;&lt;st1:placename st="on"&gt;Stanford&lt;/st1:placename&gt; &lt;st1:placetype st="on"&gt;University&lt;/st1:placetype&gt;&lt;/st1:place&gt; – Quarks Theory &lt;a href="http://www2.slac.stanford.edu/vvc/theory/quarks.html"&gt;http://www2.slac.stanford.edu/vvc/theory/quarks.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn13"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref13" name="_ftn13" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[13]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; Getting closer to the God Particle - &lt;a href="http://arafkarsh.blogspot.com/2005_02_01_arafkarsh_archive.html"&gt;http://arafkarsh.blogspot.com/2005_02_01_arafkarsh_archive.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn14"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref14" name="_ftn14" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[14]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: 100%;"&gt; String Theory - &lt;a href="http://www.superstringtheory.com/index.html"&gt;http://www.superstringtheory.com/index.html&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="ftn15"&gt;&lt;div class="MsoFootnoteText"&gt;&lt;a href="http://www2.blogger.com/post-edit.g?blogID=24218105&amp;amp;postID=114308792613341305#_ftnref15" name="_ftn15" title=""&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span class="MsoFootnoteReference"&gt;&lt;span style="font-family: Arial;"&gt;[15]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial;"&gt; What is so peculiar about this year?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34883581-115897932600071745?l=securitydatamining.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitydatamining.blogspot.com/feeds/115897932600071745/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34883581&amp;postID=115897932600071745' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34883581/posts/default/115897932600071745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34883581/posts/default/115897932600071745'/><link rel='alternate' type='text/html' href='http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-part-1-digital.html' title='The Art of Digital War - [Part 1] Digital Intrusion Timeline'/><author><name>Araf Karsh</name><uri>http://www.blogger.com/profile/08692657964904569309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_1lItfk2Ab9o/SRLYy-SCQKI/AAAAAAAAAFU/Jj1CrPjWnn4/S220/Karsh_usa.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34883581.post-115897907004064692</id><published>2006-03-22T19:10:00.000-05:00</published><updated>2006-09-22T22:37:50.086-04:00</updated><title type='text'>The Art of Digital War - Virus / Worm Analysis</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;According to Richard Bejtlich (Author of &lt;a href="http://www.amazon.com/gp/product/0321246772/sr=8-1/qid=1143067984/ref=pd_bbs_1/002-0821840-6803212?%5Fencoding=UTF8"&gt;Tao of Network Security Monitoring&lt;/a&gt; and &lt;a href="http://www.amazon.com/gp/product/0321349962/ref=pd_bxgy_img_b/104-7290784-5690337?%5Fencoding=UTF8"&gt;Extrusion Detection&lt;/a&gt;) there are five phases of compromise (of an external attack).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-family:Arial;font-size:100%;"  &gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;  &lt;/div&gt;     &lt;ol  style="margin-top: 0in; text-align: justify; font-family: arial;font-family:arial;" start="1" type="1"&gt; &lt;li class="MsoNormal"  style="font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;Reconnaissance&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"  style="font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;Exploitation&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"  style="font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;Reinforcement&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"  style="font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;Consolidation&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;Pillage&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt; &lt;/ol&gt;   &lt;span style="font-family: arial;font-family:arial;font-size:100%;"  &gt; &lt;/span&gt;&lt;span style="font-family: arial;font-family:Arial;font-size:100%;"  &gt;&lt;o:p&gt;&lt;/o:p&gt;Guess what: &lt;/span&gt;&lt;span style=";font-family:arial;font-size:100%;"  &gt;Viruses of the new era has attack models, similar to a sophisticated Hacker (or Cracker). It scans your network, exploits your vulnerable applications, creates backdoors for control, and does DoS (Denial of Service) attacks against other systems and even fights other viruses and worms to show supremacy! &lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;Here is a brief summary of the &lt;a href="http://arafkarsh.googlepages.com/Virus-Worm-Behaviours-Summary.pdf"&gt;Virus / Worm Behavior Analysis&lt;/a&gt; document (Adobe PDF document Size 105K) I prepared as part of my research on Virus behaviors around 8 months ago (in August 2005). &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;I was thinking about creating a virus database based on these attributes (my spreadsheet contains close to 250 attributes to understand the virus behavior). &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=";font-family:arial;font-size:100%;"  &gt; &lt;/span&gt;&lt;span style=";font-family:Arial;font-size:10;"  &gt;&lt;span style=";font-family:arial;font-size:100%;"  &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:Arial;font-size:10;"  &gt;&lt;span style=";font-family:arial;font-size:100%;"  &gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Watch this space for more details… ..&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34883581-115897907004064692?l=securitydatamining.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://arafkarsh.googlepages.com/Virus-Worm-Behaviours-Summary.pdf' title='The Art of Digital War - Virus / Worm Analysis'/><link rel='replies' type='application/atom+xml' href='http://securitydatamining.blogspot.com/feeds/115897907004064692/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34883581&amp;postID=115897907004064692' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34883581/posts/default/115897907004064692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34883581/posts/default/115897907004064692'/><link rel='alternate' type='text/html' href='http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-virus-worm-analysis.html' title='The Art of Digital War - Virus / Worm Analysis'/><author><name>Araf Karsh</name><uri>http://www.blogger.com/profile/08692657964904569309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_1lItfk2Ab9o/SRLYy-SCQKI/AAAAAAAAAFU/Jj1CrPjWnn4/S220/Karsh_usa.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34883581.post-115897883071844446</id><published>2006-03-09T00:10:00.001-05:00</published><updated>2010-03-29T11:51:34.336-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Firewalls'/><category scheme='http://www.blogger.com/atom/ns#' term='IDS'/><title type='text'>The Art of Digital War - [Part 2] Alarms in Digital Intrusion</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;a href="http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-part-1-digital.html"&gt;Part 1&lt;/a&gt; / &lt;a href="http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-part-2-alarms-in.html"&gt;Part 2&lt;/a&gt; / &lt;a href="http://securitydatamining.blogspot.com/2006/09/art-of-digital-war-part-3-abstract.html"&gt;Part 3&lt;/a&gt;&amp;nbsp;/ &lt;a href="http://securitydatamining.blogspot.com/2006/08/art-of-digital-war-part-4-risk-and.html"&gt;Part 4&lt;/a&gt; /&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial;"&gt;The following table shows a set of words and its frequency. I know you must be wondering about, frequency related to what? That’s the key!&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial;"&gt;&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt; &lt;br /&gt;&lt;table border="1" cellpadding="0" cellspacing="0" class="MsoTableGrid" style="border-bottom-style: none; border-bottom-width: medium; border-collapse: collapse; border-color: initial; border-left-style: none; border-left-width: medium; border-right-style: none; border-right-width: medium; border-top-style: none; border-top-width: medium; margin-left: 5.4pt; width: 399px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(255, 255, 153) none repeat scroll 0% 50%; border: 1pt solid windowtext; padding: 0in 5.4pt; width: 28.4pt;" valign="top" width="38"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: Arial;"&gt;Word&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(255, 255, 153) none repeat scroll 0% 50%; border-style: solid solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;b&gt;&lt;span style="font-family: Arial;"&gt;Frequency&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;td rowspan="11" style="border-style: solid solid solid none; padding: 0in 5.4pt; width: 14.25pt;" valign="top" width="19"&gt;&lt;div class="MsoNormal" style="margin-left: -8.85pt;"&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(255, 255, 153) none repeat scroll 0% 50%; border-style: solid solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: Arial;"&gt;Word&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(255, 255, 153) none repeat scroll 0% 50%; border-style: solid solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;b&gt;&lt;span style="font-family: Arial;"&gt;Frequency&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;td rowspan="11" style="border-style: solid solid solid none; padding: 0in 5.4pt; width: 15.65pt;" valign="top" width="21"&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(255, 255, 153) none repeat scroll 0% 50%; border-style: solid solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: Arial;"&gt;Word&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(255, 255, 153) none repeat scroll 0% 50%; border-style: solid solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;b&gt;&lt;span style="font-family: Arial;"&gt;Frequency&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 28.4pt;" valign="top" width="38"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;The&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;1101&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;That&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;389&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;As&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;228&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 28.4pt;" valign="top" width="38"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;And&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;878&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Is&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;334&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Be&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;226&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 28.4pt;" valign="top" width="38"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;To&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;726&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Not&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;315&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Lord&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;218&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 28.4pt;" valign="top" width="38"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Of&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;657&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;This&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;296&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;He&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;216&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 28.4pt;" valign="top" width="38"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;I&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;561&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;His&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;292&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;What&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;203&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 28.4pt;" valign="top" width="38"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;You&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;544&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;But&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;265&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;So&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;197&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 28.4pt;" valign="top" width="38"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;My&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;508&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;With&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;257&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Him&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;189&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 28.4pt;" valign="top" width="38"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;A&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;498&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;For&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;247&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Have&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;179&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 28.4pt;" valign="top" width="38"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;In&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;414&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Your&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;242&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;….&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;……&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 28.4pt;" valign="top" width="38"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;It&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;414&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Me&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;235&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid none; padding: 0in 5.4pt; width: 0.5in;" valign="top" width="48"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 56.35pt;" valign="top" width="75"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt; &lt;/table&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt; &lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;The above table shows the word count from Shakespeare’s Hamlet!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt; &lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial;"&gt;If we put these words in the ‘&lt;span style="color: #993300;"&gt;RIGHT CONTEXT&lt;/span&gt;’ you will get a classic in English literature. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial;"&gt;‘To be or not to be: that’s the question’ is a famous quote from Shakespeare's Hamlet by Prince Hamlet (of &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;Denmark&lt;/st1:place&gt;&lt;/st1:country-region&gt;) in a self conversation mode. Other Conversations include his (Hamlet’s) conversations with The Ghost (his assassinated father), his friend Horatio, The King Claudius etc. So, the words arranged in the Right Context, create the scenarios and build the conversation with various characters (Hero, Villain, Friends, Lovers etc) which results in the complete story.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt; &lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Arial;"&gt;Now let us look at the current set of Intrusion Detection Systems. It generates Alarms with some severity (and lots of them are false positives) and the current breed of Enterprise Security Management software’s do some basic algorithms to do the scoring which ends up similar to the data in the following table.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/span&gt; &lt;br /&gt;&lt;table border="1" cellpadding="0" cellspacing="0" class="MsoTableGrid" style="border-collapse: collapse; border: medium none; margin-left: 5.4pt;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(255, 255, 153) none repeat scroll 0% 50%; border: 1pt solid windowtext; padding: 0in 5.4pt; width: 99pt;" valign="top" width="132"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: Arial;"&gt;Alarm&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(255, 255, 153) none repeat scroll 0% 50%; border-style: solid solid solid none; padding: 0in 5.4pt; width: 2.75in;" valign="top" width="264"&gt;&lt;div align="right" class="MsoNormal" style="margin: 0in 0.05in 0pt -5.4pt; text-align: right;"&gt;&lt;b&gt;&lt;span style="font-family: Arial;"&gt;Risk Score / Priority / Event Count&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 99pt;" valign="top" width="132"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Alarm 100&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 2.75in;" valign="top" width="264"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;1101&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 99pt;" valign="top" width="132"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Alarm 12931&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 2.75in;" valign="top" width="264"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;878&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 99pt;" valign="top" width="132"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Alarm 14987&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 2.75in;" valign="top" width="264"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;726&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: rgb(204, 255, 204) none repeat scroll 0% 50%; border-style: none solid solid; padding: 0in 5.4pt; width: 99pt;" valign="top" width="132"&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-family: Arial;"&gt;Alarm 231&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 2.75in;" valign="top" width="264"&gt;&lt;div align="right" class="MsoNormal" style="text-align: right;"&gt;&lt;span style="font-family: Arial;"&gt;657&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt; &lt;/table&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt; &lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;If you compare the two set of table it doesn’t tell you exactly the story behind those words (or Alarms). Security Analysts with their experience and intuition runs through these Alarms and creates a mental map of a potentially story. However, what matters or what the industry or the Security Analysts wants, is to put these words (Alarms/Events) in the ‘&lt;span style="color: #993300;"&gt;RIGHT CONTEXT&lt;/span&gt;&lt;span style="color: black;"&gt;’&lt;/span&gt;!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt; &lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: arial;"&gt;Therefore, why don’t we look at this data set from a different point of view? i.e., instead of Security Events, Why don’t we try to see a ‘Conversation’?&lt;br /&gt;&lt;br /&gt;For Example.&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: arial;"&gt;1. A financial user using his Financial Application for his routine daily job. &lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: arial;"&gt;2. Customers accesing the Web Application &lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: arial;"&gt;3. Inter department communications.&lt;br /&gt;&lt;br /&gt;All these have a definitive start and end segments. However currently we look at all these transactions as events and then we do correlate based on these events.&lt;br /&gt;&lt;br /&gt;Now why should we see events? Why can’t we see a conversation?&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;What is a Conversation?&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;A Conversation happens when a user logs into a system do certain activities and then logs off.A Conversation could be for few seconds to hours, depends upon the nature of the conversation. A Conversation could be polite or rude! So the idea is clear. A Conversation shows a set of events in itslogical order (or grouping them in its logical order).&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: Arial;"&gt;If we look at the usual network traffic, most of raw events (Alarms generated by the security devices) can be grouped under a certain types of conversations. For Example;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial;"&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;1. Business Conversation&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;Legitimate web users or business partners accessing the Application server (Web Services).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;&lt;br /&gt;2. Inter - Department Conversations&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;Understanding the applications which communicate across the department (in normal office hours)&lt;/span&gt;&lt;span style="font-family: Arial;"&gt;&lt;o:p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-family: arial;"&gt;3. Personal Conversations&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;Employees browsing the web pages, checking personal emails etc&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;4. Un-known Conversation&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;This type of conversations is the one which doesn’t fit into current business rules or policies.&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;5. Rude Conversation&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;An Attacker scanning a server and compromising it&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;&lt;br /&gt;6. Impolite Employee Conversation&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;Employees breaking the security policies&lt;/span&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;span style="font-family: arial;"&gt;7. Harmful Robotic Conversation&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;Self propagating worm attack&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;span style="color: #993300; font-family: Arial;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-family: arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-size: 130%;"&gt;&lt;strong&gt;Data doesn’t tell a story unless it is interpreted in the right way&lt;/strong&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34883581-115897883071844446?l=securitydatamining.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitydatamining.blogspot.com/feeds/115897883071844446/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34883581&amp;postID=115897883071844446' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34883581/posts/default/115897883071844446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34883581/posts/default/115897883071844446'/><link rel='alternate' type='text/html' href='http://securitydatamining.blogspot.com/2006/03/art-of-digital-war-part-2-alarms-in.html' title='The Art of Digital War - [Part 2] Alarms in Digital Intrusion'/><author><name>Araf Karsh</name><uri>http://www.blogger.com/profile/08692657964904569309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_1lItfk2Ab9o/SRLYy-SCQKI/AAAAAAAAAFU/Jj1CrPjWnn4/S220/Karsh_usa.jpg'/></author><thr:total>0</thr:total></entry></feed>
