Wednesday, March 4, 2015

2015 Social Security Blogger Awards – Who are the Nominees?

If (and only if) you are a security blogger, you can vote HERE. Voting ends March 16. The following judges provided the nominations: Ericka Chickowski, George Hulme, Kelly Jackson-Higgins (Dark Reading), Illena Armstrong (SC Magazine) and Eleanor Dallaway (InfoSecurity Magazine) and Rich Mogull. 

The most exciting part is that AlienVault has been nominated for Best Corporate Security Blog! 

Here are the categories and nominees for each category:
Most Entertaining Security Blog

https://www.surveymonkey.com/i/t.gif Graham Cluley
https://www.surveymonkey.com/i/t.gifUncommon Sense Security
https://www.surveymonkey.com/i/t.gifkrypt3ia Blog
https://www.surveymonkey.com/i/t.gifNaked Security Blog
https://www.surveymonkey.com/i/t.gifSecurity Uncorked
https://www.surveymonkey.com/i/t.gifDave Shackleford Blog


 
Most Educational Security Blog
https://www.surveymonkey.com/i/t.gifSANS Internet StormCast
https://www.surveymonkey.com/i/t.gifSecurity Now
https://www.surveymonkey.com/i/t.gifEFF Deeplinks blog
https://www.surveymonkey.com/i/t.gifAvivah Litan's blog
https://www.surveymonkey.com/i/t.gifThreatPost
https://www.surveymonkey.com/i/t.gifTroy Hunt
https://www.surveymonkey.com/i/t.gifThe Security Ledger
https://www.surveymonkey.com/i/t.gifBranden Williams blog
https://www.surveymonkey.com/i/t.gifImperial violet
https://www.surveymonkey.com/i/t.gifErrata Security/Rob Graham


Best New Security Blog or Podcast
https://www.surveymonkey.com/i/t.gifDave Waterson on Security
https://www.surveymonkey.com/i/t.gifElastica blog: Zulfikar Ramazan
https://www.surveymonkey.com/i/t.gifInfospectives Blog
https://www.surveymonkey.com/i/t.gifNorse DarkMatters


Best Security Podcast
https://www.surveymonkey.com/i/t.gifSANS StormCast
https://www.surveymonkey.com/i/t.gifSouthern Fried Security Podcast
https://www.surveymonkey.com/i/t.gifPaul Dot Com/Paul’s Security Weekly
https://www.surveymonkey.com/i/t.gifThreatPost Podcast
https://www.surveymonkey.com/i/t.gifSecurity Now
https://www.surveymonkey.com/i/t.gifRisky Biz


Best Blog Post of the Year
https://www.surveymonkey.com/i/t.gif Attack Attribution in Cyberspace - Bruce Schneier https://www.schneier.com/blog/archives/2015/01/attack_attribut.html
https://www.surveymonkey.com/i/t.gifMore Data on Attributing the Sony Attack - Bruce Schneier https://www.schneier.com/blog/archives/2014/12/more_data_on_at.html
https://www.surveymonkey.com/i/t.gifA Hacker Looks at 40- Dave Shakleford http://daveshackleford.com/?p=1037
https://www.surveymonkey.com/i/t.gifFuture of the firewall series - Firemon Blog http://www.firemon.com/category/future-of-the-firewall/
https://www.surveymonkey.com/i/t.gifSony hack was the work of SPECTRE - Robert Graham http://blog.erratasec.com/2014/12/sony-hack-was-work-of-spectre.html#.VPFepPnF98F
https://www.surveymonkey.com/i/t.gifIn the Beginning There was Full Disclosure - Space Rogue Blog http://www.spacerogue.net/wordpress/?p=536

Best Corporate Security Blog
https://www.surveymonkey.com/i/t.gif TripWire State of Security
https://www.surveymonkey.com/i/t.gifTrend Micro
https://www.surveymonkey.com/i/t.gifThreatPost
https://www.surveymonkey.com/i/t.gifSymantec
https://www.surveymonkey.com/i/t.gifAkamai Security Blog
https://www.surveymonkey.com/i/t.gifSophos Naked Security Blog
https://www.surveymonkey.com/i/t.gifCrowdstrike Adversary Manifesto
https://www.surveymonkey.com/i/t.gifThreat Attack blog
https://www.surveymonkey.com/i/t.gifThe Alien Vault Blogs    <- That's us!
https://www.surveymonkey.com/i/t.gifRecorded Future Blog



Tuesday, September 2, 2014

Mike Sconzo at OWASP Austin talking about Machine Learning


The video recording of Mike's talk is here https://vimeo.com/104466721

Mike Sconzo, (@sooshie) presented at the OWASP Austin chapter meeting on 8/26.  He showed how machine learning can be used to detect drive-by and SQL Injection attacks. Machine learning is interesting - it's tricky to do numeric-only analysis when log files contain words.

Mike showed a data frame he uses for logs, letting him parse them. He showed several cool technologies he uses in his process:

Here's his basic process:



Although the talk was not commercial, Mike works for Click Security http://clicksecurity.com
Here's a link to some of his goodies http://clicksecurity.github.io/data_hacking/
And, finally, here's an alternative picture of Mike in his natural habitat:


Tuesday, July 29, 2014

Railsgoat! July OWASP Austin Chapter with Ken Johnson - with link to recording

Ken Johnson travelled to Austin for the July OWASP meeting.  No thanks to US Airways! Remember, last meeting Ken and Mike McCabe were supposed to present, and US Airways deprived us of their presence. Vern Williams jumped in heroically to give a talk, but Ken and Mike spent most of a day trapped in Raleigh, subjected to several layers of lies from the airline.

Here's the recorded presentation http://vimeo.com/channels/owaspaustin

This month Ken made it!  Nice crowd on hand:


Ruby & Rails was an interesting topic - it seems like a lot of people using those technologies are startups trying to build apps as quick as they can, and Enterprises trying to pretend they're startups.  Both of these scenarios tend to "forget" about security and can lead to nasty problems.  It can be downright scary to security folks.

Given this state of security worries, chapter priorities included a Happy Hour, as usual:



We might have a recording of the presentation coming soon - if so I'll post it as a comment.














The slides are here http://prezi.com/5zo5lxs82lr7/railsgoat/

follow Ken @cktricky and Mike @mccabe615