<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Finding Aurora (googlehack)</title>
	<atom:link href="http://www.networkforensics.com/2010/01/15/finding-aurora-googlehack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.networkforensics.com/2010/01/15/finding-aurora-googlehack/</link>
	<description></description>
	<lastBuildDate>Tue, 20 Jul 2010 16:25:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jesse Lands</title>
		<link>http://www.networkforensics.com/2010/01/15/finding-aurora-googlehack/comment-page-1/#comment-46</link>
		<dc:creator>Jesse Lands</dc:creator>
		<pubDate>Thu, 18 Feb 2010 18:59:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.netwitness.com/blog/?p=95#comment-46</guid>
		<description>Really?!?! You searched 6 months of traffic and ruled out the Aurora attack for them.  And all in 15 minutes.  I can&#039;t even look through one gateway for an hours traffic in 15 minutes.  To suggest that IDS will stop or discover APT by itself is absurd.  It should be a piece in your arsenal, but not your only weapon.</description>
		<content:encoded><![CDATA[<p>Really?!?! You searched 6 months of traffic and ruled out the Aurora attack for them.  And all in 15 minutes.  I can&#8217;t even look through one gateway for an hours traffic in 15 minutes.  To suggest that IDS will stop or discover APT by itself is absurd.  It should be a piece in your arsenal, but not your only weapon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven F. Fox</title>
		<link>http://www.networkforensics.com/2010/01/15/finding-aurora-googlehack/comment-page-1/#comment-8</link>
		<dc:creator>Steven F. Fox</dc:creator>
		<pubDate>Wed, 20 Jan 2010 18:54:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.netwitness.com/blog/?p=95#comment-8</guid>
		<description>&quot;All I see is data - how do I discover the knowledge?&quot;  This question was asked by the Executive Director of a Detroit-area non-profit organization while I was analyzing their server logs.  As I walked him through my analysis, his glassy eyed stare gradually melted, revealing a sense of understanding.

The &quot;business paradigm&quot; embraces the disciplines of analysis as they apply to process improvement and risk mitigation when they are communicated in familiar terminology, eg. financial ROI, value statements, cost of ownership, etc.  Unfortunately, the advanced threat vectors on the cyber battlefield require a different analysis approach that is unfamiliar to business stakeholders - threat analysis.

I agree with Tim - network data must recorded from day one.  The &quot;rhythm&quot; of the networks can be discerned from this information.  By cross refencing this information with knowledged gleaned from business analyst, one can discover key risk indicators.  This forms the foundation to a threat analysis that examines the possible abuse cases in relation to the business.</description>
		<content:encoded><![CDATA[<p>&#8220;All I see is data &#8211; how do I discover the knowledge?&#8221;  This question was asked by the Executive Director of a Detroit-area non-profit organization while I was analyzing their server logs.  As I walked him through my analysis, his glassy eyed stare gradually melted, revealing a sense of understanding.</p>
<p>The &#8220;business paradigm&#8221; embraces the disciplines of analysis as they apply to process improvement and risk mitigation when they are communicated in familiar terminology, eg. financial ROI, value statements, cost of ownership, etc.  Unfortunately, the advanced threat vectors on the cyber battlefield require a different analysis approach that is unfamiliar to business stakeholders &#8211; threat analysis.</p>
<p>I agree with Tim &#8211; network data must recorded from day one.  The &#8220;rhythm&#8221; of the networks can be discerned from this information.  By cross refencing this information with knowledged gleaned from business analyst, one can discover key risk indicators.  This forms the foundation to a threat analysis that examines the possible abuse cases in relation to the business.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention NetWitness Network Forensics » Blog Archive » Finding Aurora (googlehack) -- Topsy.com</title>
		<link>http://www.networkforensics.com/2010/01/15/finding-aurora-googlehack/comment-page-1/#comment-4</link>
		<dc:creator>Tweets that mention NetWitness Network Forensics » Blog Archive » Finding Aurora (googlehack) -- Topsy.com</dc:creator>
		<pubDate>Fri, 15 Jan 2010 22:41:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.netwitness.com/blog/?p=95#comment-4</guid>
		<description>[...] This post was mentioned on Twitter by netwitness, Will Gragido. Will Gragido said: RT @netwitness: New @NetWitness Blog Post: &quot;Finding Aurora&quot; (on the Google Hack) http://bit.ly/74936b #Google #cyberwar #security [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by netwitness, Will Gragido. Will Gragido said: RT @netwitness: New @NetWitness Blog Post: &quot;Finding Aurora&quot; (on the Google Hack) <a href="http://bit.ly/74936b" rel="nofollow">http://bit.ly/74936b</a> #Google #cyberwar #security [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
