<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8992597326904513257</id><updated>2011-09-13T07:31:40.274-07:00</updated><category term='picviz'/><category term='fun'/><category term='lddh'/><title type='text'>logger foobar</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://logviz.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992597326904513257/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://logviz.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Sebastien</name><uri>http://www.blogger.com/profile/08080964285180259007</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_OGv00_-zJH8/S4wWwO6-wbI/AAAAAAAAAM8/mELVshRpdoE/S220/picviz-icon.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8992597326904513257.post-1594578023921039659</id><published>2010-09-01T01:27:00.000-07:00</published><updated>2010-09-01T01:42:51.100-07:00</updated><title type='text'>Forensic Challenge 5: Log Mysteries</title><content type='html'>&lt;a href="http://chuvakin.blogspot.com"&gt;Anton&lt;/a&gt;, &lt;a href="http://raffy.ch/blog/"&gt;Raffy&lt;/a&gt; and I are pleased to release the 5th &lt;a href="http://www.honeynet.org"&gt;honeynet &lt;/a&gt;forensic challenge. Challenges are one of the favorite Honeynet Project things that people enjoy from us, and it is a pleasure for me to participate in such a great log analysis challenge.&lt;br /&gt;&lt;br /&gt;Data are one of the hardest things to get, I regularly hear from customers and people I meet during various conferences around the world (both industrial and academic) that they had a hard time to test their tools on real data.&lt;br /&gt;&lt;br /&gt;Indeed, it is not easy to setup an environment that looks real, and until now, despite the few efforts out there, &lt;a href="http://www.ll.mit.edu/mission/communications/ist/corpora/ideval/data/index.html"&gt;DARPA was the only one to release data&lt;/a&gt; in 1998, 1999 and 2000, we don't see much data available to the public. Good data must mix both real stuff you have on your network and attacks in it (and not &lt;span style="font-weight: bold;"&gt;just &lt;/span&gt;attacks).&lt;br /&gt;&lt;br /&gt;A lot of people have data but cannot share it for mostly confidentiality reasons. I admit this is not easy and this is why I started&lt;a href="http://code.google.com/p/loganon/"&gt; the loganon project&lt;/a&gt; during the last Google Summer Of Code (I will post something specific on this project later).&lt;br /&gt;&lt;br /&gt;Most of the time I bring this subject on the table I hear people saying this is a dead-end, too hard to do, nobody will cooperate. Well, I am pretty sure &lt;a href="http://www.wikipedia.org"&gt;Wikipedia &lt;/a&gt;heard the same stuff before starting.&lt;br /&gt;&lt;br /&gt;So instead of worrying and wondering how to do it, we just do it. Enjoy this challenge, since it is a pretty open challenge I expect a lot of surprising results.&lt;br /&gt;&lt;br /&gt;Get it here &lt;a href="http://honeynet.org/challenges/2010_5_log_mysteries"&gt;http://honeynet.org/challenges/2010_5_log_mysteries&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8992597326904513257-1594578023921039659?l=logviz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://logviz.blogspot.com/feeds/1594578023921039659/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://logviz.blogspot.com/2010/09/forensic-challenge-5-log-mysteries.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992597326904513257/posts/default/1594578023921039659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992597326904513257/posts/default/1594578023921039659'/><link rel='alternate' type='text/html' href='http://logviz.blogspot.com/2010/09/forensic-challenge-5-log-mysteries.html' title='Forensic Challenge 5: Log Mysteries'/><author><name>Sebastien</name><uri>http://www.blogger.com/profile/08080964285180259007</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_OGv00_-zJH8/S4wWwO6-wbI/AAAAAAAAAM8/mELVshRpdoE/S220/picviz-icon.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8992597326904513257.post-2092357455216978794</id><published>2010-03-01T11:35:00.000-08:00</published><updated>2010-03-01T13:08:34.406-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='picviz'/><title type='text'>PicViz News</title><content type='html'>It has been almost 6 months without new releases of &lt;span class="il"&gt;PicViz&lt;/span&gt;. There are good reason to it !&lt;br /&gt;&lt;br /&gt;Philippe and I actually reworked on the architecture to make it way more powerful. Our first goal was to give &lt;span class="il"&gt;PicViz&lt;/span&gt; an efficient way to integrate logs and network traffic without going through the PGDL language and various scripts to generate it. These types of input are now automagically integrated and we are tuning the whole thing for even better performance...&lt;br /&gt;&lt;br /&gt;We also injected in &lt;span class="il"&gt;PicViz&lt;/span&gt; a lot of abstract maths to make it a terrific tool to find correlations in multiple dimensions. We want &lt;span class="il"&gt;PicViz&lt;/span&gt; to assist users to find attacks very quickly.&lt;br /&gt;&lt;div class="im"&gt;&lt;br /&gt;This work is very exciting, looking at the results we already have. Needless to say that there is a big gap between the &lt;span class="il"&gt;Picviz&lt;/span&gt; you know and the one we are working on! The GUI has been completely rewritten and is incomparably snappier. We also provide a lot of assistance and interaction to the user.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Parallel Coordinates are now easier to understand and use. We are closer than ever before to the original target of the project : be able to manage and react quickly to attacks at a nation's level and fill the technical gap of a long term SIEM and IDS usage.&lt;br /&gt;&lt;br /&gt;Stay tuned!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8992597326904513257-2092357455216978794?l=logviz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://logviz.blogspot.com/feeds/2092357455216978794/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://logviz.blogspot.com/2010/03/picviz-news.html#comment-form' title='2 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992597326904513257/posts/default/2092357455216978794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992597326904513257/posts/default/2092357455216978794'/><link rel='alternate' type='text/html' href='http://logviz.blogspot.com/2010/03/picviz-news.html' title='PicViz News'/><author><name>Sebastien</name><uri>http://www.blogger.com/profile/08080964285180259007</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_OGv00_-zJH8/S4wWwO6-wbI/AAAAAAAAAM8/mELVshRpdoE/S220/picviz-icon.png'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8992597326904513257.post-3338025028502176034</id><published>2010-02-05T04:30:00.000-08:00</published><updated>2010-02-05T04:43:39.011-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='lddh'/><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><title type='text'>3c501.c</title><content type='html'>Working on a secret project, I had to work on the 3c501.c driver. Reading comments I had the pleasure to read:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;This is a device driver for the 3Com Etherlink 3c501. Do not purchase this card, even as a joke.  It's performance is horrible, and it breaks in many ways.&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8992597326904513257-3338025028502176034?l=logviz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://logviz.blogspot.com/feeds/3338025028502176034/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://logviz.blogspot.com/2010/02/3c501c.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992597326904513257/posts/default/3338025028502176034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992597326904513257/posts/default/3338025028502176034'/><link rel='alternate' type='text/html' href='http://logviz.blogspot.com/2010/02/3c501c.html' title='3c501.c'/><author><name>Sebastien</name><uri>http://www.blogger.com/profile/08080964285180259007</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_OGv00_-zJH8/S4wWwO6-wbI/AAAAAAAAAM8/mELVshRpdoE/S220/picviz-icon.png'/></author><thr:total>0</thr:total></entry></feed>
