Why I don't say APT
APT is a word that means different things to different audiences. It's important to be concise in defining terms and using the correct words to avoid unnecessary conflict and misunderstanding.
Pseudo(code) Proof of Network Security Evolution
Pseudo-code proof that network behavioral anomaly detection (NBAD) of threats is the superior evolution of signature based detection.
Step Away from the PCAP!
Great investigators know the importance of details but often we go too deep, too quickly. An organized approach to incident response will allow more actionable intelligence to be created in less time.
When DDoS Happens to Good Networks
What distributed denial of service (DDoS) is and how NetFlow can give situational awareness when it happens to your network.
You Say Solution, I Say Problem
Vendors and Analysts want to have conversations around products. Organizations want to talk about their business problems. Vendors rename their products "solutions" and Organizations start evaluating the products and forget about their business problems. Here is an open letter to both sides.
Time to Hire a Security Team
An average organization will lose more than $10M to cyber crime this year in detectable losses and much more in un-quantifiable damages as trade secrets, customer data and financial records are stolen without detection. It's time to re-evaluate the need for advanced security teams in organizations that want to stay afloat in an age of rampant, sophisticated corporate espionage from attackers ranging from organized crime to nation-states.
Has APT1 Been Eating My Porridge?
NetFlow when effectively stored makes a great basis for analyzing indicators of compromise (IOC) like those provided in Mandiant's APT1 report.
APT Number One
The systematic problems the Mandiant APT1 report revealed in enterprise surveillance efforts.
Before There Was a Great Wall
How the importance of physical surveillance throughout human history teaches us why we are failing at network security and how we can fix it.
Anatomy of an SQL Injection
What SQL Injection is and how intelligent monitoring of NetFlow can detect and deter it.
Are My Computers for Rent?
Using NetFlow to determine if network resources are being sold on the black market.
Day Zero Is How Long??!
We are taking a retarded amount of time to discover unknown (zero day) threats and how we can reduce that window.
Network Security School of Ft. Knox
Summary of the "Network Security School of Ft. Knox" series I penned and the webinar accompanying it.
Network Security School of Fort Knox: Part 6
The last installment explains the importance of knowing what to do when a breach is detected.
Network Security School of Fort Knox: Part 5
InfoSec attackers are not created equal. They range from punk kids to nation states. It's important to know who is coming after your protected assets.