<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>BreachBytes</title>
	<atom:link href="http://www.breachbytes.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.breachbytes.com</link>
	<description>Network Forensics &#124; Network Monitoring &#124; Incident Response</description>
	<pubDate>Wed, 02 Jul 2008 03:08:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Recent reports on data breaches and identity theft</title>
		<link>http://www.breachbytes.com/2008/06/12/recent-reports-on-data-breahces-and-idenity-theft/</link>
		<comments>http://www.breachbytes.com/2008/06/12/recent-reports-on-data-breahces-and-idenity-theft/#comments</comments>
		<pubDate>Thu, 12 Jun 2008 14:32:06 +0000</pubDate>
		<dc:creator>Ben Uphoff</dc:creator>
		
		<category><![CDATA[Breaches]]></category>

		<category><![CDATA[Cybercrime]]></category>

		<category><![CDATA[Identify Theft]]></category>

		<category><![CDATA[Links to articles]]></category>

		<category><![CDATA[best practices]]></category>

		<category><![CDATA[identity theft]]></category>

		<guid isPermaLink="false">http://www.breachbytes.com/2008/06/12/recent-reports-on-data-breahces-and-idenity-theft/</guid>
		<description><![CDATA[Robert Vamosi has a nice overview of two recent reports on his Defense in Depth blog, the first on data breaches and the second on identity theft. The interesting figures from both reports: 9/10 breaches could have been prevented by following best practices and 57% of identity thieves use the information to open new lines [...]]]></description>
			<content:encoded><![CDATA[<p>Robert Vamosi has a nice overview of two recent reports on his <a title="Defense in Depth" href="http://news.cnet.com/defense-in-depth/">Defense in Depth</a> blog, the first on data breaches and the second on identity theft. The interesting figures from both reports: 9/10 breaches could have been prevented by following best practices and 57% of identity thieves use the information to open new lines of credit (not too surprising).</p>
<p>A summary of the Verizon report on data breaches is available <a title="Verizon Business Releases Trailblazing Data-Breach Study Spanning 500 Forensic Investigations" href="http://www.verizonbusiness.com/about/news/displaynews.xml?newsid=25135&amp;mode=vzlong&amp;lang=en&amp;width=530">here</a> while the entire report can be found <a title="2008 DATA BREACH INVESTIGATION REPORT" href="http://www.verizonbusiness.com/resources/security/databreachreport.pdf">here</a> as a PDF. Likewise, a summary of the identity theft report can be found <a title="Identity Theft: The Aftermath 2007" href="http://www.idtheftcenter.org/artman2/publish/m_press/Identity_Theft_The_Aftermath_2007.shtml">here</a> and the full version <a title="Identity Theft: The Aftermath 2007" href="http://www.idtheftcenter.org/artman2/uploads/1/Aftermath_2007_20080529v2_1.pdf">here</a> as a PDF.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.breachbytes.com/2008/06/12/recent-reports-on-data-breahces-and-idenity-theft/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Net/FSE on IT Network World Canada</title>
		<link>http://www.breachbytes.com/2008/06/09/netfse-on-it-network-world-canada/</link>
		<comments>http://www.breachbytes.com/2008/06/09/netfse-on-it-network-world-canada/#comments</comments>
		<pubDate>Mon, 09 Jun 2008 15:51:22 +0000</pubDate>
		<dc:creator>Andy Alsop</dc:creator>
		
		<category><![CDATA[Links to articles]]></category>

		<category><![CDATA[Net/FSE]]></category>

		<category><![CDATA[Network World]]></category>

		<guid isPermaLink="false">http://www.breachbytes.com/2008/06/09/netfse-on-it-network-world-canada/</guid>
		<description><![CDATA[Net/FSE has received coverage from IT Network World Canada posting it to their available downloads.  And in regard to our not returning their call, yes we have returned their call (albeit a little late).
]]></description>
			<content:encoded><![CDATA[<p>Net/FSE has received coverage from <a href="http://blogs.itworldcanada.com/nw-downloads/2008/05/26/netfse-packet-analytics/" title="Net/FSE download page on IT Network World Canada">IT Network World Canada </a>posting it to their available downloads.  And in regard to our not returning their call, yes we have returned their call (albeit a little late).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.breachbytes.com/2008/06/09/netfse-on-it-network-world-canada/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Network Event Analysis with Net/FSE</title>
		<link>http://www.breachbytes.com/2008/04/24/network-event-analysis-with-netfse/</link>
		<comments>http://www.breachbytes.com/2008/04/24/network-event-analysis-with-netfse/#comments</comments>
		<pubDate>Thu, 24 Apr 2008 23:20:36 +0000</pubDate>
		<dc:creator>Andy Alsop</dc:creator>
		
		<category><![CDATA[Commentary]]></category>

		<category><![CDATA[Links to articles]]></category>

		<category><![CDATA[NetFlow for Security]]></category>

		<category><![CDATA[Network Forensics]]></category>

		<category><![CDATA[incident response]]></category>

		<category><![CDATA[network security]]></category>

		<category><![CDATA[]]></category>

		<category><![CDATA[incident investigation]]></category>

		<category><![CDATA[log file retention]]></category>

		<guid isPermaLink="false">http://www.breachbytes.com/2008/04/24/network-event-analysis-with-netfse/</guid>
		<description><![CDATA[An article written by my partner Ben Uphoff has been published by (IN)SECURE Magazine.  Scroll down to page 68 for the full text of the article.
Ben has done a great job of outlining what it takes to perform effective incident investigation using Net/FSE for in-depth alert analysis. I&#8217;d like to outline some of the [...]]]></description>
			<content:encoded><![CDATA[<p align="left">An <a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-16.pdf" title="Insecuremag.com: Network Event Analysis with Net/FSE" target="_blank">article</a> written by my partner <a href="http://www.breachbytes.com/author/benuphoff/" title="Blog post by Ben Uphoff">Ben Uphoff</a> has been published by <a href="http://www.net-security.org/insecuremag.php" title="(IN)SECURE Magazine" target="_blank">(IN)SECURE Magazine</a>.  <a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-16.pdf" title="Insecuremag.com: Network Event Analysis with Net/FSE" target="_blank">Scroll down to page 68</a> for the full text of the article.</p>
<p>Ben has done a great job of outlining what it takes to perform effective incident investigation using <a href="http://www.packetanalytics.com/products.php" title="Net/FSE - the Network Forensic Search Engine" target="_blank">Net/FSE</a> for in-depth alert analysis. I&#8217;d like to outline some of the snippets from the article that support the point that network intrusions, breaches and incidents are inevitable and the only way to perform proper incident investigation is to &#8220;keep it all.&#8221;</p>
<blockquote>
<p align="left">A core belief at Packet Analytics is that despite the best efforts of security vendors and practitioners, incidents are inevitable. There are simply too many threats and too many angles of attack. Technology on enterprise networks evolves so quickly that it is nearly impossible to keep up with the ever-changing threat landscape. For this reason, network breaches and security incidents must be seen as part of doing business in a connected world. Enterprises can mitigate the risk of a breach by following best practices and preparing a comprehensive incident response and recovery plan.</p>
<p class="MsoNormal">One challenge with working with network event data is that you can never be sure what event information is relevant until after the fact. For example, enterprises did not see value in storing DNS logs until DNS exfiltration attacks started appearing. With no historical log of DNS activity, those that fell victim to such attacks had no way of definitively knowing the extent of the data leakage resulting from the breach.</p>
<p class="MsoNormal">Contrary to the “keep it all” approach, SIMs try to reduce data volume at the collection points by aggregating similar events into statistical summaries that are then fed into the correlation engine, losing potentially valuable information in the process. Summaries are useful for the correlation engine but not for deep analysis of network events</p>
</blockquote>
<p class="MsoNormal">We look forward to starting a dialog on the &#8220;keep it all&#8221; strategy and how we can improve the effectiveness of security and network operations in performing Network Event Analysis.  Please post a comment.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.breachbytes.com/2008/04/24/network-event-analysis-with-netfse/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Virtual Security Roundup</title>
		<link>http://www.breachbytes.com/2008/04/08/virtual-security-roundup/</link>
		<comments>http://www.breachbytes.com/2008/04/08/virtual-security-roundup/#comments</comments>
		<pubDate>Tue, 08 Apr 2008 15:06:49 +0000</pubDate>
		<dc:creator>Ben Uphoff</dc:creator>
		
		<category><![CDATA[network security]]></category>

		<category><![CDATA[netflow]]></category>

		<category><![CDATA[packet capture]]></category>

		<category><![CDATA[virtual environment security]]></category>

		<category><![CDATA[virtual machines]]></category>

		<guid isPermaLink="false">http://www.breachbytes.com/2008/04/08/virtual-security-roundup/</guid>
		<description><![CDATA[There is a lot of talk right now about security for virtual machines. My post from last week was about a company generating NetFlow data from virtual switches. Now at least two significant efforts are being announced at RSA. First, Solera Networks is releasing a free beta of a virtual network tap. Their premise is [...]]]></description>
			<content:encoded><![CDATA[<p>There is a lot of talk right now about security for virtual machines. My <a href="http://www.breachbytes.com/2008/04/02/netflow-meets-virtualization/" title="NetFlow meets Virtualization">post from last week</a> was about a company generating NetFlow data from virtual switches. Now at least two significant efforts are being announced at RSA. First, <a href="http://www.soleranetworks.com/" title="Solera Networks">Solera Networks</a> is releasing a <a href="http://www.soleranetworks.com/news/solera-networks-extends-network-visibility-with-first-ever-virtual-regeneration-tap/" title="Solera Networks Extends Network Visibility with First Ever Virtual Regeneration Tap">free beta of a virtual network tap</a>. Their premise is that buying virtual equivalents of IDS, IPS, etc is wasteful and expensive to enterprises. The virtual tap interfaces with Solera&#8217;s line of packet capture devices and closes the gap in network visibility in virtual environments. This approach seems stronger than Montego&#8217;s approach (NetFlow only). Solera provides the entire packet stream allowing you to do pretty much anything.</p>
<p>The second big announcement is from IBM, who is announcing <a href="http://www.news.com/8301-10784_3-9913589-7.html?tag=nefd.lede" title="IBM introduces security for virtual computing environments">&#8220;Phantom&#8221;</a>, a hypervisor security layer.  This layer will let admins in virtual environments lock down the virtualized environment outside the VM instances allowing a single point of configuration to lock down a host of virtualized servers or clients. This will be a technology to keep an eye on in the coming months.</p>
<p>As usual, the security industry is catching up with a technology (this time around VM) that has been around for a considerable amount of time. This attention to virtual environment security is welcome but as usual a bit late in the game. The securtiy industry  is still not keeping pace with technology advances. I don&#8217;t expect it to catch up anytime soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.breachbytes.com/2008/04/08/virtual-security-roundup/feed/</wfw:commentRss>
		</item>
		<item>
		<title>NetFlow meets Virtualization</title>
		<link>http://www.breachbytes.com/2008/04/02/netflow-meets-virtualization/</link>
		<comments>http://www.breachbytes.com/2008/04/02/netflow-meets-virtualization/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 16:13:02 +0000</pubDate>
		<dc:creator>Ben Uphoff</dc:creator>
		
		<category><![CDATA[Links to articles]]></category>

		<category><![CDATA[NetFlow for Security]]></category>

		<category><![CDATA[netflow]]></category>

		<category><![CDATA[network visibility]]></category>

		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://www.breachbytes.com/2008/04/02/netflow-meets-virtualization/</guid>
		<description><![CDATA[Montego Networks CTO John Peterson has an excellent writeup on enabling NetFlow for visibility into virtualized networks. I talk a lot about network visibility with flow data on BreachBytes, but up until not I was not aware of any company implementing NetFlow for virtual switches. Montego&#8217;s technology makes visible some of the &#8220;dark space&#8221; that [...]]]></description>
			<content:encoded><![CDATA[<p>Montego Networks CTO John Peterson has an <a href="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/03/netflow-and-vis.html" title="NetFlow and Visibility in the Virtual Environment">excellent writeup</a> on enabling NetFlow for visibility into virtualized networks. I talk a lot about network visibility with flow data on BreachBytes, but up until not I was not aware of any company implementing NetFlow for virtual switches. Montego&#8217;s technology makes visible some of the &#8220;dark space&#8221; that had previously existed in networks using virtualization. This looks like promising technology to keep an eye on in the future.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.breachbytes.com/2008/04/02/netflow-meets-virtualization/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
