<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Webremix Articles</title>
    <link>http://www.webremix.info/</link>
    <description>Webremix : all the web new, remixed</description>
    <dc:creator>webremix.info</dc:creator>
    <item>
      <title>IGI airport yet to get perimeter intrusion detection system</title>
      <link>http://economictimes.indiatimes.com/news/news-by-industry/transportation/airlines-/-aviation/IGI-airport-yet-to-get-perimeter-intrusion-detection-system/articleshow/6455310.cms</link>
      <description>The Indira Gandhi International Airport here may boast of a new world-class terminal, but it is yet to get an electronic surveillance mechanism to make it more secure.</description>
      <pubDate>Sun, 29 Aug 2010 06:57:38 GMT</pubDate>
      <guid>http://economictimes.indiatimes.com/news/news-by-industry/transportation/airlines-/-aviation/IGI-airport-yet-to-get-perimeter-intrusion-detection-system/articleshow/6455310.cms</guid>
      <dc:date>2010-08-29T06:57:38Z</dc:date>
    </item>
    <item>
      <title>FAA Computers Are Vulnerable to Cyberattack</title>
      <link>http://www.cio-today.com/story.xhtml?story_id=74802</link>
      <description>Federal Aviation Administration computer systems remain vulnerable to cyber attacks despite improvements at a number of key radar facilities in the past year, according to a new U.S. government review.
&lt;p&gt;
The Department of Transportation's inspector general said while the FAA has taken steps to install more sophisticated systems to detect cyber intrusions in some air traffic control facilities, most sites have not been upgraded. And there is no timetable yet to complete the project, the IG said.
&lt;/p&gt;
&lt;p&gt;
FAA spokeswoman Laura Brown said the agency is working on a timetable and will notify the IG with that information soon. The FAA also said that upgrades to critical air traffic control systems have taken precedence over the intrusion detection improvements at a number of facilities.
&lt;/p&gt;
&lt;p&gt;
Without the detection abilities, the FAA cannot effectively monitor air traffic control for possible cyber attacks or take action to stop them, the inspector general said in a letter obtained by The Associated Press.
&lt;/p&gt;
&lt;p&gt;
The findings echo broad U.S. government worries about gaps in critical U.S. computer systems and networks that leave them vulnerable to cyber attacks by criminals, terrorists or nation states.
&lt;/p&gt;
&lt;p&gt;
U.S. networks are persistently probed and attacked by hackers and criminals looking to steal money or information, get access to classified documents or military technologies, or disrupt networks that control vital utilities and services.
&lt;/p&gt;
&lt;p&gt;
Last year, a government audit found that air traffic control systems were vulnerable to cyber attacks, and that some support systems had been breached, allowing hackers access to personnel records and network servers.
&lt;/p&gt;
&lt;p&gt;
The computer systems used to control air traffic are often in the same building as ones used for administrative functions, but they are not connected.
&lt;/p&gt;
&lt;p&gt;
Cyber experts repeatedly warn, however, that in some cases software glitches and other gaps can be exploited by hackers to move between computer systems at critical infrastructure facilities.
&lt;/p&gt;
&lt;p&gt;
In the report...&lt;/p&gt;</description>
      <pubDate>Thu, 19 Aug 2010 14:36:04 GMT</pubDate>
      <guid>http://www.cio-today.com/story.xhtml?story_id=74802</guid>
      <dc:date>2010-08-19T14:36:04Z</dc:date>
    </item>
    <item>
      <title>Juniper Networks Protects Customers From New Microsoft Vulnerabilities Disclosed Today</title>
      <link>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/37664368/</link>
      <description>JNPR ) today confirmed its Intrusion Detection and Prevention (IDP) security systems and Integrated Security Gateway (ISG) firewall/virtual private network (VPN) systems with IDP offer protection for ...</description>
      <pubDate>Tue, 10 Aug 2010 20:00:50 GMT</pubDate>
      <guid>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/37664368/</guid>
      <dc:date>2010-08-10T20:00:50Z</dc:date>
    </item>
    <item>
      <title>Who will trust open source security from the government</title>
      <link>http://www.zdnet.com/blog/open-source/who-will-trust-open-source-security-from-the-government/6892</link>
      <description>The Open Information Security Foundation, headed by Mark Jonkman of Emerging Threats and Victor Julien of the Vuurmuur firewall project, are offering an intrusion detection and prevention engine with multi-threading automatic protocol detection for a wide variety of protocols.</description>
      <pubDate>Wed, 21 Jul 2010 12:47:54 GMT</pubDate>
      <guid>http://www.zdnet.com/blog/open-source/who-will-trust-open-source-security-from-the-government/6892</guid>
      <dc:date>2010-07-21T12:47:54Z</dc:date>
    </item>
    <item>
      <title>Juniper Networks Protects Customers From New Microsoft Vulnerabilities Disclosed Today</title>
      <link>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/36874077/</link>
      <description>JNPR ) today confirmed its Intrusion Detection and Prevention (IDP) security systems and Integrated Security Gateway (ISG) firewall/virtual private network (VPN) systems with IDP offer protection for ...</description>
      <pubDate>Tue, 13 Jul 2010 20:40:01 GMT</pubDate>
      <guid>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/36874077/</guid>
      <dc:date>2010-07-13T20:40:01Z</dc:date>
    </item>
    <item>
      <title>RandomStorm Adds Log Management to Integrated Network Security Management and Compliance Platform</title>
      <link>http://www.topix.net/tech/spyware/2010/06/randomstorm-adds-log-management-to-integrated-network-security-management-and-compliance-platform?fromrss=1</link>
      <description>&lt;p&gt;StormAgent is based on industry standard, open source intrusion detection technology and has been designed to monitor access and changes to system and application log files across the entire corporate infrastructure, alerting network managers whenever unauthorised activity is detected.&lt;/p&gt;</description>
      <pubDate>Tue, 29 Jun 2010 10:31:29 GMT</pubDate>
      <guid>http://www.topix.net/tech/spyware/2010/06/randomstorm-adds-log-management-to-integrated-network-security-management-and-compliance-platform?fromrss=1</guid>
      <dc:date>2010-06-29T10:31:29Z</dc:date>
    </item>
    <item>
      <title>Marketwatch: Threats Create Opportunities</title>
      <link>http://www.technologyreview.com/computing/25588/</link>
      <description>&lt;p&gt;A decade ago, a company looking to secure its computer systems would  have purchased antivirus software, a firewall, and perhaps an intrusion  detection system. Today, the growing variety of attacks has given rise  to nearly 70 different security niches, including markets for firewalls  that specifically protect Web-based applications and for systems that  prevent data loss across an enterprise. Meanwhile, each submarket is  getting increasingly complex. In 2009 one of the biggest security  companies, &amp;shy;Symantec, generated 2.9 million separate signatures, or  digital patterns associated with malicious software--an increase of 71  percent over the previous year.&lt;/p&gt;
&lt;br /&gt;

&lt;br /&gt;</description>
      <pubDate>Tue, 22 Jun 2010 04:00:00 GMT</pubDate>
      <guid>http://www.technologyreview.com/computing/25588/</guid>
      <dc:date>2010-06-22T04:00:00Z</dc:date>
    </item>
    <item>
      <title>Altor Testing Cloud Security</title>
      <link>http://java.sys-con.com/node/1429394</link>
      <description>Altor Networks, the three-year-old start-up with the patent-pending hypervisor-based security for virtual data centers and clouds, is beta testing the next iteration of its purpose-built virtual server security product. It expects to release Altor 4.0, code named Duvel, in early Q3. 
Altor started out with a stateful high-performance firewall and on-board intrusion detection and has added complete 360 degree virtual network visibility and monitoring, automated security and compliance assessment and reporting. 
It argues that security and compliance concerns are holding back virtualization and has moved to address the safety of the traffic between VMs. &lt;p&gt;&lt;a href="http://java.sys-con.com/node/1429394"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Sat, 12 Jun 2010 16:15:00 GMT</pubDate>
      <guid>http://java.sys-con.com/node/1429394</guid>
      <dc:date>2010-06-12T16:15:00Z</dc:date>
    </item>
    <item>
      <title>Intrusion detection system at Delhi airport stuck</title>
      <link>http://www.dnaindia.com/india/report_intrusion-detection-system-at-delhi-airport-stuck_1390828</link>
      <description>The installation of the perimeter intrusion detection system (PIDS), which is armed with thermal-imaging cameras, video-recorders and radars to detect movement of individuals and vehicles at the airport, has been delayed because of last-minute chan-ges in the original project.</description>
      <pubDate>Tue, 01 Jun 2010 19:06:02 GMT</pubDate>
      <guid>http://www.dnaindia.com/india/report_intrusion-detection-system-at-delhi-airport-stuck_1390828</guid>
      <dc:date>2010-06-01T19:06:02Z</dc:date>
    </item>
    <item>
      <title>Juniper Networks Protects Customers From New Microsoft Vulnerabilities Disclosed Today</title>
      <link>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/34985277/</link>
      <description>JNPR ) today confirmed its Intrusion Detection and Prevention (IDP) security systems and Integrated Security Gateway (ISG) firewall/virtual private network (VPN) systems with IDP offer protection for ...</description>
      <pubDate>Tue, 11 May 2010 18:49:33 GMT</pubDate>
      <guid>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/34985277/</guid>
      <dc:date>2010-05-11T18:49:33Z</dc:date>
    </item>
    <item>
      <title>Thirty-Five Antivirus Programs Share Common Hole 
    (PC Magazine)</title>
      <link>http://us.rd.yahoo.com/dailynews/rss/tech/*http://news.yahoo.com/s/zd/20100510/tc_zd/250722</link>
      <description>PC Magazine - A security firm has discovered a new attack technique that could allow a program to bypass the host intrusion detection and certain other protections provided by common Windows security software. The report lists 35 security products on which they tested it; it worked on all of them.</description>
      <pubDate>Mon, 10 May 2010 10:06:40 GMT</pubDate>
      <guid>http://us.rd.yahoo.com/dailynews/rss/tech/*http://news.yahoo.com/s/zd/20100510/tc_zd/250722</guid>
      <dc:date>2010-05-10T10:06:40Z</dc:date>
    </item>
    <item>
      <title>Amazon Opens Virtual Private Cloud in Europe</title>
      <link>http://ajax.sys-con.com/node/1381607</link>
      <description>Amazon has taken its Virtual Private Cloud (VPC) to Europe.

Customers can now seamlessly connect their IT infrastructure via an encrypted IPsec Virtual Private Network (VPN) connection to Amazon resources in the European Union, keeping their data in the EU and lowering latency.

Until Tuesday VPC, a bridge between a company&amp;rsquo;s existing IT infrastructure and a set of isolated Amazon compute resources in the Amazon cloud, was only available in the US. 
With VPC customers can use their existing management capabilities such as security services, firewalls and intrusion detection systems on their Amazon resources. &lt;p&gt;&lt;a href="http://ajax.sys-con.com/node/1381607"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 05 May 2010 12:30:00 GMT</pubDate>
      <guid>http://ajax.sys-con.com/node/1381607</guid>
      <dc:date>2010-05-05T12:30:00Z</dc:date>
    </item>
    <item>
      <title>Securing the Public Cloud</title>
      <link>http://www.linux.com/news/enterprise/cloud-computing/302648:securing-the-public-cloud</link>
      <description>&lt;div&gt;
	Security is paramount when it comes to enterprise data in public clouds. Encryption, intrusion detection and ID management all need to be part of the evaluation and deployment processes.&lt;/div&gt;</description>
      <pubDate>Tue, 27 Apr 2010 17:41:32 GMT</pubDate>
      <guid>http://www.linux.com/news/enterprise/cloud-computing/302648:securing-the-public-cloud</guid>
      <dc:date>2010-04-27T17:41:32Z</dc:date>
    </item>
    <item>
      <title>HP Declares War on Cisco with a Faster Data Center</title>
      <link>http://www.cio-today.com/story.xhtml?story_id=72849</link>
      <description>Just months after its 3Com acquisition, Hewlett-Packard made an announcement Monday aimed at Cisco Systems. HP said its new Cisco-free internal data center is seeing faster information throughput and lower energy consumption running entirely on HP networking equipment.
&lt;p&gt;
Located in Houston, the new data center is one of six internal facilities running HP's worldwide business operations. The new center includes 34 3Com core routing devices, more than 300 HP ProCurve switches, and four TippingPoint intrusion-detection and protection devices.
&lt;/p&gt;
&lt;p&gt;
&amp;quot;This networking technology provides a true competitive choice in a space that has needed more choices for almost two decades,&amp;quot; said Randy Mott, executive vice president and chief information officer at HP. &amp;quot;These new products, along with HP's Converged Infrastructure portfolio, are something every CIO should be taking advantage of.&amp;quot;
&lt;/p&gt;
&lt;p&gt;

Assaulting Cisco

&lt;/p&gt;
&lt;p&gt;
Mott's comments are a direct assault on Cisco. The new HP Networking portfolio, which integrates 3Com's portfolio, paves the way for twice the port and capacity density and a 50 percent reduction in power consumption from previous solutions. Using an architecture built on open standards, HP said its global IT organization worked with HP Networking teams to redesign the architecture with new products.
&lt;/p&gt;
&lt;p&gt;
&amp;quot;We're not locked into proprietary protocols that many in the IT industry are familiar with, and this gives us more flexibility to change as our business grows,&amp;quot; said Ken Gray, vice president of infrastructure at HP. &amp;quot;We're Cisco-free in this data center and have a plan to extend this freedom across all of our internal IT data centers next year.&amp;quot;
&lt;/p&gt;
&lt;p&gt;
Gray's war-like comment -- and its validity -- may concern Cisco. Zeus Kerravala, a vice president at the Yankee Group, said 3Com's data portfolio is strong and the majority of the lineup has been built out over the past couple of years with a differentiating philosophy of openness. 
&lt;/p&gt;
&lt;p&gt;
&amp;quot;While a lot of the...&lt;/p&gt;</description>
      <pubDate>Mon, 19 Apr 2010 18:50:05 GMT</pubDate>
      <guid>http://www.cio-today.com/story.xhtml?story_id=72849</guid>
      <dc:date>2010-04-19T18:50:05Z</dc:date>
    </item>
    <item>
      <title>Product How-to: Use multicore flow processing to boost network router/security appliance throughput</title>
      <link>http://www.topix.net/tech/perl/2010/04/product-how-to-use-multicore-flow-processing-to-boost-network-router-security-appliance-throughput?fromrss=1</link>
      <description>&lt;p&gt;In many network and security appliances, the need for regular expression matching is an essential requirement, specifically for deep packet inspection applications such as intrusion detection and prevention systems , content firewalls, virus scanning, data loss prevention , and lawful intercept applications.&lt;/p&gt;</description>
      <pubDate>Fri, 02 Apr 2010 10:22:16 GMT</pubDate>
      <guid>http://www.topix.net/tech/perl/2010/04/product-how-to-use-multicore-flow-processing-to-boost-network-router-security-appliance-throughput?fromrss=1</guid>
      <dc:date>2010-04-02T10:22:16Z</dc:date>
    </item>
    <item>
      <title>Anti-intrusion system for Delhi international  airport next month</title>
      <link>http://www.dnaindia.com/india/report_anti-intrusion-system-for-delhi-international-airport-next-month_1356803</link>
      <description>The mechanism known as the Perimeter Intrusion Detection System (PIDS) will be deployed by mid-April this year along the 37 km of the airport periphery.</description>
      <pubDate>Mon, 08 Mar 2010 13:01:31 GMT</pubDate>
      <guid>http://www.dnaindia.com/india/report_anti-intrusion-system-for-delhi-international-airport-next-month_1356803</guid>
      <dc:date>2010-03-08T13:01:31Z</dc:date>
    </item>
    <item>
      <title>Homeland Chief Outlines U.S. Cybersecurity Strategy</title>
      <link>http://www.cio-today.com/story.xhtml?story_id=72011</link>
      <description>U.S. Department of Homeland Security Secretary Janet Napolitano outlined the steps DHS is taking to secure cyberspace at the RSA Conference 2010 in San Francisco on Wednesday. The former governor of Arizona also called upon experts and the public to contribute ideas to improve the nation's cybersecurity.
&lt;p&gt; 
&amp;quot;All Americans have an important role to play in securing our computer systems and cyber networks,&amp;quot; Napolitano said. &amp;quot;We are challenging our nation's best and brightest to utilize their expertise and creativity to devise new ways to engage the public in the shared responsibility of safeguarding our cyber resources and information.&amp;quot;
&lt;/p&gt;
&lt;p&gt;

Boosting Infrastructure Security

&lt;/p&gt;
&lt;p&gt;
In her keynote address, Napolitano stressed DHS's dedication to recruiting and retaining the cybersecurity employees needed to confront terrorist and criminal threats. Moreover, she emphasized the department's commitment to supporting innovations such as EINSTEIN -- an intrusion detection program originally developed by US-CERT, the department's computer emergency readiness team.
&lt;/p&gt;
&lt;p&gt;
&amp;quot;In the past year we've deployed the second phase of EINSTEIN to 11 federal agencies, and we will be growing to 21 this year,&amp;quot; Napolitano noted. &amp;quot;And now we are testing the technology for the third phase of EINSTEIN,&amp;quot; which will give DHS &amp;quot;the ability to detect malicious activity and disable attempted intrusions before harm is done to our critical systems.&amp;quot;
&lt;/p&gt;
&lt;p&gt;
Ensuring U.S. government continuity as well as private-sector services and information -- even as it protects privacy -- are among the important tasks DHS now faces, Napolitano said. To meet these challenges, DHS has developed &amp;quot;a national cybersecurity incident response plan in full collaboration with the private sector&amp;quot; that will be tested during an exercise in September.
&lt;/p&gt;
&lt;p&gt; 
What's more, DHS efforts continue to focus on &amp;quot;providing the ability to bounce back even more quickly should a large-scale attack -- or really an attack of any size -- occur,&amp;quot; Napolitano said. To this end,...&lt;/p&gt;</description>
      <pubDate>Thu, 04 Mar 2010 19:15:31 GMT</pubDate>
      <guid>http://www.cio-today.com/story.xhtml?story_id=72011</guid>
      <dc:date>2010-03-04T19:15:31Z</dc:date>
    </item>
    <item>
      <title>Comprehensive National Cybersecurity Initiative</title>
      <link>http://www.schneier.com/blog/archives/2010/03/comprehensive_n.html</link>
      <description>On Tuesday, the White House published an unclassified summary of its Comprehensive National Cybersecurity Initiative (CNCI). Howard Schmidt made the announcement at the RSA Conference. These are the 12 initiatives in the plan: Initiative #1. Manage the Federal Enterprise Network as a single network enterprise with Trusted Internet. Initiative #2. Deploy an intrusion detection system of sensors across the Federal...</description>
      <pubDate>Thu, 04 Mar 2010 18:55:46 GMT</pubDate>
      <guid>http://www.schneier.com/blog/archives/2010/03/comprehensive_n.html</guid>
      <dc:date>2010-03-04T18:55:46Z</dc:date>
    </item>
    <item>
      <title>U.S. Declassifies Part of Secret Cybersecurity Plan</title>
      <link>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/32741368/</link>
      <description>The Obama administration declassified part of the government&amp;rsquo;s cybersecurity plan Tuesday, publishing parts of it that discuss intrusion detection systems for federal computer networks and the g...</description>
      <pubDate>Wed, 03 Mar 2010 06:28:47 GMT</pubDate>
      <guid>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/32741368/</guid>
      <dc:date>2010-03-03T06:28:47Z</dc:date>
    </item>
    <item>
      <title>Alert Logic to Present at Cloud Expo April 19-21 in New York City</title>
      <link>http://linux.sys-con.com/node/1265920</link>
      <description>The emergence of the Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) models are just two of the many inflection points as IT migrates away from the traditional data centers and into the cloud, shifting more control over security from the enterprise to the service provider. How will your security and compliance strategy change when this transformation is complete? 

Misha Govshteyn is co-founder and responsible for product development and strategy at Alert Logic, a Software-as-a-Service based security solutions provider. In this capacity, Govshteyn regularly consults with service providers and enterprises on securing cloud-based applications. Prior to co-founding Alert Logic, Govshteyn served as a Director of Managed Services for Reliant Energy Communications. In this role, he developed and successfully launched five major product lines including Managed Intrusion Detection services and managed enterprise firewall/VPN products.&lt;p&gt;&lt;a href="http://linux.sys-con.com/node/1265920"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 19 Feb 2010 00:45:00 GMT</pubDate>
      <guid>http://linux.sys-con.com/node/1265920</guid>
      <dc:date>2010-02-19T00:45:00Z</dc:date>
    </item>
    <item>
      <title>Alert Logic to Present at Cloud Expo April 19-21 in New York City</title>
      <link>https://linux.sys-con.com/node/1265920</link>
      <description>The emergence of the Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) models are just two of the many inflection points as IT migrates away from the traditional data centers and into the cloud, shifting more control over security from the enterprise to the service provider. How will your security and compliance strategy change when this transformation is complete? 

Misha Govshteyn is co-founder and responsible for product development and strategy at Alert Logic, a Software-as-a-Service based security solutions provider. In this capacity, Govshteyn regularly consults with service providers and enterprises on securing cloud-based applications. Prior to co-founding Alert Logic, Govshteyn served as a Director of Managed Services for Reliant Energy Communications. In this role, he developed and successfully launched five major product lines including Managed Intrusion Detection services and managed enterprise firewall/VPN products.&lt;p&gt;&lt;a href="https://linux.sys-con.com/node/1265920"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 19 Feb 2010 00:45:00 GMT</pubDate>
      <guid>https://linux.sys-con.com/node/1265920</guid>
      <dc:date>2010-02-19T00:45:00Z</dc:date>
    </item>
    <item>
      <title>Botnets Found in Government and Business Systems</title>
      <link>http://www.cio-today.com/story.xhtml?story_id=71747</link>
      <description>A new Zeus botnet has been discovered affecting 75,000 systems in 2,500 organizations around the world. Both corporate and government networks have become victims of the severe cyberattack dubbed the Kneber attack, named after the username linked with the attack. 
&lt;p&gt;
The attack was first discovered in January while a security analyst at Hernon, Va.-based NetWitness was installing a monitoring system for a client. In investigating the discovery, the company found Kneber had compromised 68,000 corporate log-ins; access to various e-mail systems, including Yahoo and Hotmail; access to online banking sites; and access to social-networking sites, including Facebook. All of this was done in a four-week period.
&lt;/p&gt;
&lt;p&gt;
Kneber has been identified as a botnet, where compromised computers run software remotely. 
&lt;/p&gt;
&lt;p&gt;
&amp;quot;Systems compromised by this botnet provide the attackers not only user credentials and confidential information, but remote access inside the compromised networks,&amp;quot; said Amit Yoran, CEO of NetWitness and former director of the National Cyber Security Division.
&lt;/p&gt;
&lt;p&gt;
Damage Done
&lt;/p&gt;
&lt;p&gt;
The Kneber botnet is not stopped by traditional malware protection or other intrusion-detection systems, and NetWitness analysts fear organizations will not see the damage from this attack until it has already occurred. 
&lt;/p&gt;
&lt;p&gt;
More than half the infected machines were also infected with a peer-to-peer botnet dubbed Waledac, a worm that is capable of collecting and forwarding password information. It's also capable of receiving commands from a remote server, including to upgrade malware components or send information from the infected computer. 
&lt;/p&gt;
&lt;p&gt;
Used together, the botnets have the potential to enable hackers to collaborate in what NetWitness said may be a &amp;quot;criminal underground.&amp;quot;
&lt;/p&gt;
&lt;p&gt;
&amp;quot;On a microlevel, there are new versions of Trojans and viruses that come out all the time and some gain traction while others do not,&amp;quot; said Matthew Prince, cocreator of Project Honey Pot, a spam tracking network. &amp;quot;On the macrolevel it is really scary.&amp;quot;
&lt;/p&gt;
&lt;p&gt;
Cybercriminal Revolution
&lt;/p&gt;
&lt;p&gt;
The...&lt;/p&gt;</description>
      <pubDate>Thu, 18 Feb 2010 18:51:17 GMT</pubDate>
      <guid>http://www.cio-today.com/story.xhtml?story_id=71747</guid>
      <dc:date>2010-02-18T18:51:17Z</dc:date>
    </item>
    <item>
      <title>Einstein 2: U.S. government's 'enlightening' new cybersecurity weapon</title>
      <link>http://www.networkworld.com/news/2010/021110-cybersecurity-einstein-2.html</link>
      <description>The Department of Homeland Security is detecting new patterns of cyberattacks from foreign adversaries -- some targeted at particular agencies and others aimed at the entire U.S. government -- due to to special-purpose intrusion-detection systems that will be widely deployed in federal networks during 2010.</description>
      <pubDate>Thu, 11 Feb 2010 12:00:00 GMT</pubDate>
      <guid>http://www.networkworld.com/news/2010/021110-cybersecurity-einstein-2.html</guid>
      <dc:date>2010-02-11T12:00:00Z</dc:date>
    </item>
    <item>
      <title>Juniper Networks Protects Customers From New Microsoft Vulnerabilities Disclosed Today</title>
      <link>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/32101042/</link>
      <description>JNPR ) today  confirmed its Intrusion Detection and Prevention (IDP) security systems and  Integrated Security Gateway (ISG) firewall/virtual private network (VPN)  systems with IDP offer protection f...</description>
      <pubDate>Tue, 09 Feb 2010 20:06:18 GMT</pubDate>
      <guid>http://story.venezuelastar.com/index.php/ct/9/cid/3a8a80d6f705f8cc/id/32101042/</guid>
      <dc:date>2010-02-09T20:06:18Z</dc:date>
    </item>
    <item>
      <title>Amazon’s Virtual Private Cloud Computing Floats into Beta</title>
      <link>http://wireless.sys-con.com/node/1221956</link>
      <description>Amazon Web Services (AWS) sent its enterprise-directed Virtual Private Cloud (VPC) widgetry into full public beta Monday. The thing&amp;rsquo;s been in limited public beta since the summer and before that it was in private beta.

VPC is Amazon&amp;rsquo;s way of creating hybrid clouds by letting an enterprise connect its existing infrastructure to a set of isolated AWS compute resources via a virtual private network (VPN) &amp;ndash; a bog standard encrypted IPsec tunnel &amp;ndash; and use its own existing security services, firewalls and intrusion detection systems for the EC2 instances and traffic. Ditto whatever third-party management software it&amp;rsquo;s using.
&lt;p&gt;&lt;a href="http://wireless.sys-con.com/node/1221956"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 16 Dec 2009 23:45:00 GMT</pubDate>
      <guid>http://wireless.sys-con.com/node/1221956</guid>
      <dc:date>2009-12-16T23:45:00Z</dc:date>
    </item>
    <item>
      <title>Amazon’s Virtual Private Cloud Computing Floats into Beta</title>
      <link>http://web2.sys-con.com/node/1221956</link>
      <description>Amazon Web Services (AWS) sent its enterprise-directed Virtual Private Cloud (VPC) widgetry into full public beta Monday. The thing&amp;rsquo;s been in limited public beta since the summer and before that it was in private beta.

VPC is Amazon&amp;rsquo;s way of creating hybrid clouds by letting an enterprise connect its existing infrastructure to a set of isolated AWS compute resources via a virtual private network (VPN) &amp;ndash; a bog standard encrypted IPsec tunnel &amp;ndash; and use its own existing security services, firewalls and intrusion detection systems for the EC2 instances and traffic. Ditto whatever third-party management software it&amp;rsquo;s using.
&lt;p&gt;&lt;a href="http://web2.sys-con.com/node/1221956"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 16 Dec 2009 06:00:00 GMT</pubDate>
      <guid>http://web2.sys-con.com/node/1221956</guid>
      <dc:date>2009-12-16T06:00:00Z</dc:date>
    </item>
    <item>
      <title>The Application Delivery Spell Book</title>
      <link>http://ajax.sys-con.com/node/1198798</link>
      <description>&lt;p&gt;&lt;em /&gt;&lt;/p&gt;
  &lt;p&gt;&lt;em&gt;The long, lost application delivery spell compendium has been found! Its once hidden, arcane knowledge is slowly being translated for the good of all web applications. Luckily, you don&amp;rsquo;t have to be Elminster or Gandalf or &lt;/em&gt;&lt;em&gt; to cast &lt;/em&gt;this &lt;em&gt;spell over your infrastructure&lt;/em&gt;&lt;/p&gt;
  &lt;p&gt;&lt;strong&gt;Detect Invisible (Application) Stalkers &lt;a
        href="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/ItIsHardToDefendWhenYouDontKnowYoureBein_3562/image_2.png"&gt;&lt;img
        align="right" height="271"
        src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/ItIsHardToDefendWhenYouDontKnowYoureBein_3562/image_thumb.png"
        title="image" width="210" /&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;School of Magic:&lt;/strong&gt; Abjuration (Protective Spells) &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Components&lt;/strong&gt;: Somatic (requires gestures), Material (requires physical component) &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Casting Time: &lt;/strong&gt;special &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Range: &lt;/strong&gt;Layers 3-7&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Area: &lt;/strong&gt;global &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Duration: &lt;/strong&gt;Until discharged &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Saving Throw: &lt;/strong&gt;Special&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Spell Resistance: &lt;/strong&gt;No&lt;/p&gt;
  &lt;blockquote&gt;   &lt;p&gt;&lt;a
        href="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/ItIsHardToDefendWhenYouDontKnowYoureBein_3562/invisiblestalker_2.jpg"&gt;&lt;img
        align="left" height="161"
        src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/ItIsHardToDefendWhenYouDontKnowYoureBein_3562/invisiblestalker_thumb.jpg"
        title="invisiblestalker"
      width="161" /&gt;&lt;/a&gt; Invisible (application) stalkers are creatures native to the Internet. They sometimes serve miscreants, corporate spies, and script kiddies, who summon them to perform attacks against specific targets. A summoned invisible stalker undertakes the form of a legitimate application request, pretending to be a real user, and will tirelessly undertake whatever task the caster commands, even if the task sends packets hundreds or thousands of miles away. The creature follows a command until the task is completed and obeys only the caster. &lt;/p&gt;    &lt;p&gt;Invisible (application) stalkers operate only at layer 7 and eschew the use of forms commonly recognized as being of evil intent. Thus an &lt;em&gt;invoke firewall log &lt;/em&gt;spell will show only multiple requests over time from similar agents, and &lt;em&gt;intrusion detection &lt;/em&gt;spells have no effect on the creatures. Only a &lt;em&gt;detect invisible (application) stalker &lt;/em&gt;spell can recognize and subsequently dismiss these agents of evil. &lt;/p&gt;    &lt;p&gt;This spell inserts into the path of the invisible (application) stalker a wall which cannot be avoided, blocking them or reporting to the caster their proximity, as determined by the caster. The material component for this spell is a &lt;a
      href="http://www.f5.com/products/big-ip/product-modules/application-security-manager.html"&gt;web application firewall&lt;/a&gt;, which must be placed between the invisible (application) stalker and its intended target. The somatic component requires the caster to complete a series of mouse clicks and keyboard strokes that deploy an application security policy including the ability to prevent &lt;a href="http://en.wikipedia.org/wiki/Web_scraping"&gt;web scraping&lt;/a&gt;. The casting time for this spell varies based on the complexity of the existing environment, and how many victims are being targeted by the invisible (application) stalkers. &lt;/p&gt;    &lt;p&gt;Once completed, the spell will last until the caster discharges it by disabling the policy created by the somatic gestures. &lt;/p&gt;    &lt;p&gt;The invisible (application) stalker may attempt a saving throw (Will) to realize it is being blocked. If it makes the save, it may attempt to figure out how the wall is blocking it. It must then make a second Will save or discorporate immediately. If the spell is cast as a reporting only mechanism, there is no saving throw allowed and the invisible (application) stalker will never be aware it has been detected. &lt;/p&gt; &lt;/blockquote&gt;
     &lt;div&gt;&lt;strong&gt;THE FIRST STEP IN ANY SOLUTION IS ALWAYS RECOGNIZING THERE IS A PROBLEM &lt;/strong&gt;&lt;/div&gt;

  There are a few attacks today that just can&amp;rsquo;t be detected by applications. &lt;a href="http://devcentral.f5.com/weblogs/macvittie/archive/2008/07/08/3429.aspx"&gt;Layer 7 DoS&lt;/a&gt;
 can&amp;rsquo;t be detected from within an application because the code that executes does so in the context of a &lt;em&gt;single request&lt;/em&gt;
 and a DoS implies many requests from many sources. The only way for a developer to detect this attack is to be able to view the single request that is typical of an application in the context of &lt;em&gt;all &lt;/em&gt;
requests across &lt;em&gt;all &lt;/em&gt;
instances of the application &amp;ndash; even across machines &amp;ndash; and that&amp;rsquo;s simply not possible from within the application.   &lt;p&gt;Similarly, web scraping attacks are nearly impossible for a developer to detect because there is nothing in the request that would indicate anything is out of the ordinary. Nothing. No special code, no special characters, no odd manifestations within the headers or network data. In order for the developer to detect such an attack s/he would need to be able to determine whether the client is manned by a human being or is a script/bot. And no, using User-Agent headers isn&amp;rsquo;t going to work on this one because miscreants have figured out that too many security devices are able to block their attacks based on that value and thus have learned to circumvent it by scripting real browsers or manipulating the HTTP headers such that their bots/scripts appear to be valid user-driven browsers. &lt;/p&gt;
  &lt;p&gt;But that&amp;rsquo;s what a &lt;a href="http://www.f5.com/products/big-ip/product-modules/application-security-manager.html"&gt;web application firewall (WAF)&lt;/a&gt; was designed to do: to watch, to evaluate requests in context, across all instances and all requests. It has the visibility, it has the capability, and it can detect attacks that are not easily if at all detected from within the application. Even if the WAF isn&amp;rsquo;t blocking the attacks, it can at least tell you they are happening, which is something the developers need to know if they&amp;rsquo;re going to put in place solutions to prevent them. &lt;/p&gt;
  &lt;p&gt;&lt;em&gt;&amp;ldquo;Security manager, &amp;lsquo;J.F. Rice,&amp;rsquo; whose name and employer have been disguised for obvious reasons&amp;rdquo; &lt;/em&gt;explains his need to &amp;ldquo;see&amp;rdquo; inside connections and understand what is happening in his environment. &lt;/p&gt;
 &lt;a href="http://news.idg.no/cw/art.cfm?id=08DFD829-1A64-67EA-E4996B477BBCB6D3"&gt;We&amp;rsquo;ve been blind to attacks on our Web sites&lt;/a&gt;
    &lt;p&gt;I installed a Web application firewall in my company's DMZ to tell us about active attacks that may not be identified by our other devices. I set the device up in monitor mode, though it can be set up to block attacks, because my goal was just to see what was going on. I wanted to know more about what's inside the connections to those Web servers.&lt;/p&gt;
    &lt;p&gt;What I discovered is that our Web sites are being &amp;quot;scraped&amp;quot; by other companies -- our competitors! Some of the information on our sites is valuable intellectual property. It is provided online, in a restricted manner (passwords and such), to our customers. Such restrictions aren't very difficult to overcome for the Web crawlers that our competitors are using, because webmasters usually don't know much about security. They make a token attempt to put passwords and restrictions on sensitive files, but they often don't do a very good job.&lt;/p&gt;
    &lt;p&gt;&lt;a
    href="http://www.f5.com/solutions/security/"&gt;Web application security&lt;/a&gt; requires visibility as well as the expected defensive capabilities. A &lt;a href="http://www.f5.com/products/big-ip/product-modules/application-security-manager.html"&gt;web application firewall&lt;/a&gt; can provide both capabilities even though you may not leverage both at the same time or at all. Using a WAF as a mechanism to determine what kind of attacks are being directed at your web applications is just as valuable a proposition as enabling its preventative capabilities. &lt;/p&gt;
  &lt;p&gt;Either way, knowing is the first step to moving forward on a strategy to address it. &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&lt;a href="http://twitter.com/lmacvittie"&gt;&lt;img height="18"
      src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/125/o_twitt-twoo-icon.png"
    width="18" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
    href="http://tweepml.org/F5-Networks-Tweeple/"
      title="Follow F5 Networks on Twitter"&gt;&lt;img height="18"
      src="http://tweepml.org/s/tweepml16.png" width="18" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
    href="http://tweepml.org/F5-DevCentral/"
      title="Follow F5 DevCentral on Twitter"&gt;&lt;img height="18"
      src="http://tweepml.org/s/tweepml16.png" width="18" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/Rss.aspx"&gt;&lt;img
    src="http://devcentral.f5.com/Portals/0/images/Icons/icon_xml_18.gif" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
      href="http://www.slideshare.net/lmacvittie"&gt;&lt;img height="18"
      src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/125/o_slideshare.png"
    width="18" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
      href="http://www.linkedin.com/in/lmacvittie"&gt;&lt;img
    src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/125/o_linkedin_16.png" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
      href="http://www.friendfeed.com/lmacvittie"&gt;&lt;img height="16"
      src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/InfrastructureasaServiceHowcontextawares_69CD/friendfeed_3.jpg"
    width="16" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
      href="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/InfrastructureasaServiceHowcontextawares_69CD/icon_facebook_2.png"&gt;&lt;img
      height="16"
      src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/InfrastructureasaServiceHowcontextawares_69CD/icon_facebook_4.png" width="16" /&gt;&lt;/a&gt; &lt;/p&gt;
  &lt;p&gt;&lt;a
    href="http://www.addthis.com/feed.php?pub=lmacvittie&amp;amp;h1=http%3A%2F%2Fdevcentral.f5.com%2Fweblogs%2Fmacvittie%2FRss.aspx&amp;amp;t1="
      title="Subscribe using any feed reader!"&gt;&lt;img height="18"
      src="http://s9.addthis.com/button1-fd.gif" width="125" /&gt;&lt;/a&gt; &lt;a
    href="http://www.addthis.com/bookmark.php"
      title="Bookmark and Share"&gt;&lt;img height="18"
      src="http://s9.addthis.com/button1-share.gif" width="125" /&gt;&lt;/a&gt; &lt;/p&gt;
  &lt;p&gt;Related blogs &amp;amp; articles: &lt;/p&gt;
  &lt;ul&gt;   &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/f5news/archive/2009/11/20/innovative-web-protection-and-compliance.aspx"&gt;Innovative Web Protection and Compliance&lt;/a&gt;&amp;nbsp;&lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://www.slideshare.net/DSorensenCPR/f5-offers-advanced-web-security-with-bigip-v101"&gt;BIG-IP v10.1 Security &lt;/a&gt; [Slideshare Presentation] &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/10/01/the-gazebo-on-your-web-site.aspx"&gt;Excuse Me But Is That a Gazebo On Your Site?!&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/09/28/web-application-security-at-the-edge-is-more-efficient-than.aspx"&gt;Web Application Security at the Edge is More Efficient Than In the Application&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/07/21/i-can-has-ur-.htaccess-file.aspx"&gt;I Can Has UR .htaccess File&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/07/08/automatically-removing-cookies.aspx"&gt;Automatically Removing Cookies&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/06/23/clickjacking-protection-using-x-frame-options-available-for-firefox.aspx"&gt;Clickjacking Protection Using X-FRAME-OPTIONS Available for Firefox&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/01/05/stop-brute-force-listing-of-http-options-with-network-side-scripting.aspx"&gt;Stop brute force listing of HTTP OPTIONS with network-side scripting&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/04/23/jedi-mind-tricks-http-request-smuggling.aspx"&gt;Jedi Mind Tricks: HTTP Request Smuggling&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/01/15/i-am-in-your-http-headers-attacking-your-application.aspx"&gt;I am in your HTTP headers, attacking your application&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;
  &lt;div&gt;Technorati Tags: &lt;a
    href="http://technorati.com/tags/MacVittie"&gt;MacVittie&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/F5"&gt;F5&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/web+application+security"&gt;web application security&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/security"&gt;security&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/web+2.0"&gt;web 2.0&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/web+scraping"&gt;web scraping&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/ASM"&gt;ASM&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/web+application+firewall"&gt;web application firewall&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/WAF"&gt;WAF&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/D%26D"&gt;D&amp;amp;D&lt;/a&gt;,&lt;a href="http://technorati.com/tags/ADSB"&gt;ADSB&lt;/a&gt;&lt;/div&gt;
&lt;img height="1"
  src="http://devcentral.f5.com/weblogs/macvittie/aggbug/6222.aspx" width="1" /&gt;
&lt;img height="1"
  src="http://feeds.feedburner.com/~r/f5/XOwx/~4/lxUJyY7D-YI" width="1" /&gt;
&lt;p&gt;&lt;a href="http://ajax.sys-con.com/node/1198798"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 24 Nov 2009 17:30:00 GMT</pubDate>
      <guid>http://ajax.sys-con.com/node/1198798</guid>
      <dc:date>2009-11-24T17:30:00Z</dc:date>
    </item>
    <item>
      <title>The Application Delivery Spell Book</title>
      <link>https://ajax.sys-con.com/node/1198798</link>
      <description>&lt;p&gt;&lt;em /&gt;&lt;/p&gt;
  &lt;p&gt;&lt;em&gt;The long, lost application delivery spell compendium has been found! Its once hidden, arcane knowledge is slowly being translated for the good of all web applications. Luckily, you don&amp;rsquo;t have to be Elminster or Gandalf or &lt;/em&gt;&lt;em&gt; to cast &lt;/em&gt;this &lt;em&gt;spell over your infrastructure&lt;/em&gt;&lt;/p&gt;
  &lt;p&gt;&lt;strong&gt;Detect Invisible (Application) Stalkers &lt;a
        href="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/ItIsHardToDefendWhenYouDontKnowYoureBein_3562/image_2.png"&gt;&lt;img
        align="right" height="271"
        src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/ItIsHardToDefendWhenYouDontKnowYoureBein_3562/image_thumb.png"
        title="image" width="210" /&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;School of Magic:&lt;/strong&gt; Abjuration (Protective Spells) &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Components&lt;/strong&gt;: Somatic (requires gestures), Material (requires physical component) &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Casting Time: &lt;/strong&gt;special &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Range: &lt;/strong&gt;Layers 3-7&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Area: &lt;/strong&gt;global &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Duration: &lt;/strong&gt;Until discharged &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Saving Throw: &lt;/strong&gt;Special&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Spell Resistance: &lt;/strong&gt;No&lt;/p&gt;
  &lt;blockquote&gt;   &lt;p&gt;&lt;a
        href="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/ItIsHardToDefendWhenYouDontKnowYoureBein_3562/invisiblestalker_2.jpg"&gt;&lt;img
        align="left" height="161"
        src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/ItIsHardToDefendWhenYouDontKnowYoureBein_3562/invisiblestalker_thumb.jpg"
        title="invisiblestalker"
      width="161" /&gt;&lt;/a&gt; Invisible (application) stalkers are creatures native to the Internet. They sometimes serve miscreants, corporate spies, and script kiddies, who summon them to perform attacks against specific targets. A summoned invisible stalker undertakes the form of a legitimate application request, pretending to be a real user, and will tirelessly undertake whatever task the caster commands, even if the task sends packets hundreds or thousands of miles away. The creature follows a command until the task is completed and obeys only the caster. &lt;/p&gt;    &lt;p&gt;Invisible (application) stalkers operate only at layer 7 and eschew the use of forms commonly recognized as being of evil intent. Thus an &lt;em&gt;invoke firewall log &lt;/em&gt;spell will show only multiple requests over time from similar agents, and &lt;em&gt;intrusion detection &lt;/em&gt;spells have no effect on the creatures. Only a &lt;em&gt;detect invisible (application) stalker &lt;/em&gt;spell can recognize and subsequently dismiss these agents of evil. &lt;/p&gt;    &lt;p&gt;This spell inserts into the path of the invisible (application) stalker a wall which cannot be avoided, blocking them or reporting to the caster their proximity, as determined by the caster. The material component for this spell is a &lt;a
      href="http://www.f5.com/products/big-ip/product-modules/application-security-manager.html"&gt;web application firewall&lt;/a&gt;, which must be placed between the invisible (application) stalker and its intended target. The somatic component requires the caster to complete a series of mouse clicks and keyboard strokes that deploy an application security policy including the ability to prevent &lt;a href="http://en.wikipedia.org/wiki/Web_scraping"&gt;web scraping&lt;/a&gt;. The casting time for this spell varies based on the complexity of the existing environment, and how many victims are being targeted by the invisible (application) stalkers. &lt;/p&gt;    &lt;p&gt;Once completed, the spell will last until the caster discharges it by disabling the policy created by the somatic gestures. &lt;/p&gt;    &lt;p&gt;The invisible (application) stalker may attempt a saving throw (Will) to realize it is being blocked. If it makes the save, it may attempt to figure out how the wall is blocking it. It must then make a second Will save or discorporate immediately. If the spell is cast as a reporting only mechanism, there is no saving throw allowed and the invisible (application) stalker will never be aware it has been detected. &lt;/p&gt; &lt;/blockquote&gt;
     &lt;div&gt;&lt;strong&gt;THE FIRST STEP IN ANY SOLUTION IS ALWAYS RECOGNIZING THERE IS A PROBLEM &lt;/strong&gt;&lt;/div&gt;

  There are a few attacks today that just can&amp;rsquo;t be detected by applications. &lt;a href="http://devcentral.f5.com/weblogs/macvittie/archive/2008/07/08/3429.aspx"&gt;Layer 7 DoS&lt;/a&gt;
 can&amp;rsquo;t be detected from within an application because the code that executes does so in the context of a &lt;em&gt;single request&lt;/em&gt;
 and a DoS implies many requests from many sources. The only way for a developer to detect this attack is to be able to view the single request that is typical of an application in the context of &lt;em&gt;all &lt;/em&gt;
requests across &lt;em&gt;all &lt;/em&gt;
instances of the application &amp;ndash; even across machines &amp;ndash; and that&amp;rsquo;s simply not possible from within the application.   &lt;p&gt;Similarly, web scraping attacks are nearly impossible for a developer to detect because there is nothing in the request that would indicate anything is out of the ordinary. Nothing. No special code, no special characters, no odd manifestations within the headers or network data. In order for the developer to detect such an attack s/he would need to be able to determine whether the client is manned by a human being or is a script/bot. And no, using User-Agent headers isn&amp;rsquo;t going to work on this one because miscreants have figured out that too many security devices are able to block their attacks based on that value and thus have learned to circumvent it by scripting real browsers or manipulating the HTTP headers such that their bots/scripts appear to be valid user-driven browsers. &lt;/p&gt;
  &lt;p&gt;But that&amp;rsquo;s what a &lt;a href="http://www.f5.com/products/big-ip/product-modules/application-security-manager.html"&gt;web application firewall (WAF)&lt;/a&gt; was designed to do: to watch, to evaluate requests in context, across all instances and all requests. It has the visibility, it has the capability, and it can detect attacks that are not easily if at all detected from within the application. Even if the WAF isn&amp;rsquo;t blocking the attacks, it can at least tell you they are happening, which is something the developers need to know if they&amp;rsquo;re going to put in place solutions to prevent them. &lt;/p&gt;
  &lt;p&gt;&lt;em&gt;&amp;ldquo;Security manager, &amp;lsquo;J.F. Rice,&amp;rsquo; whose name and employer have been disguised for obvious reasons&amp;rdquo; &lt;/em&gt;explains his need to &amp;ldquo;see&amp;rdquo; inside connections and understand what is happening in his environment. &lt;/p&gt;
 &lt;a href="http://news.idg.no/cw/art.cfm?id=08DFD829-1A64-67EA-E4996B477BBCB6D3"&gt;We&amp;rsquo;ve been blind to attacks on our Web sites&lt;/a&gt;
    &lt;p&gt;I installed a Web application firewall in my company's DMZ to tell us about active attacks that may not be identified by our other devices. I set the device up in monitor mode, though it can be set up to block attacks, because my goal was just to see what was going on. I wanted to know more about what's inside the connections to those Web servers.&lt;/p&gt;
    &lt;p&gt;What I discovered is that our Web sites are being &amp;quot;scraped&amp;quot; by other companies -- our competitors! Some of the information on our sites is valuable intellectual property. It is provided online, in a restricted manner (passwords and such), to our customers. Such restrictions aren't very difficult to overcome for the Web crawlers that our competitors are using, because webmasters usually don't know much about security. They make a token attempt to put passwords and restrictions on sensitive files, but they often don't do a very good job.&lt;/p&gt;
    &lt;p&gt;&lt;a
    href="http://www.f5.com/solutions/security/"&gt;Web application security&lt;/a&gt; requires visibility as well as the expected defensive capabilities. A &lt;a href="http://www.f5.com/products/big-ip/product-modules/application-security-manager.html"&gt;web application firewall&lt;/a&gt; can provide both capabilities even though you may not leverage both at the same time or at all. Using a WAF as a mechanism to determine what kind of attacks are being directed at your web applications is just as valuable a proposition as enabling its preventative capabilities. &lt;/p&gt;
  &lt;p&gt;Either way, knowing is the first step to moving forward on a strategy to address it. &lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&lt;a href="http://twitter.com/lmacvittie"&gt;&lt;img height="18"
      src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/125/o_twitt-twoo-icon.png"
    width="18" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
    href="http://tweepml.org/F5-Networks-Tweeple/"
      title="Follow F5 Networks on Twitter"&gt;&lt;img height="18"
      src="http://tweepml.org/s/tweepml16.png" width="18" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
    href="http://tweepml.org/F5-DevCentral/"
      title="Follow F5 DevCentral on Twitter"&gt;&lt;img height="18"
      src="http://tweepml.org/s/tweepml16.png" width="18" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/Rss.aspx"&gt;&lt;img
    src="http://devcentral.f5.com/Portals/0/images/Icons/icon_xml_18.gif" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
      href="http://www.slideshare.net/lmacvittie"&gt;&lt;img height="18"
      src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/125/o_slideshare.png"
    width="18" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
      href="http://www.linkedin.com/in/lmacvittie"&gt;&lt;img
    src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/125/o_linkedin_16.png" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
      href="http://www.friendfeed.com/lmacvittie"&gt;&lt;img height="16"
      src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/InfrastructureasaServiceHowcontextawares_69CD/friendfeed_3.jpg"
    width="16" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a
      href="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/InfrastructureasaServiceHowcontextawares_69CD/icon_facebook_2.png"&gt;&lt;img
      height="16"
      src="http://devcentral.f5.com/weblogs/images/devcentral_f5_com/weblogs/macvittie/WindowsLiveWriter/InfrastructureasaServiceHowcontextawares_69CD/icon_facebook_4.png" width="16" /&gt;&lt;/a&gt; &lt;/p&gt;
  &lt;p&gt;&lt;a
    href="http://www.addthis.com/feed.php?pub=lmacvittie&amp;amp;h1=http%3A%2F%2Fdevcentral.f5.com%2Fweblogs%2Fmacvittie%2FRss.aspx&amp;amp;t1="
      title="Subscribe using any feed reader!"&gt;&lt;img height="18"
      src="http://s9.addthis.com/button1-fd.gif" width="125" /&gt;&lt;/a&gt; &lt;a
    href="http://www.addthis.com/bookmark.php"
      title="Bookmark and Share"&gt;&lt;img height="18"
      src="http://s9.addthis.com/button1-share.gif" width="125" /&gt;&lt;/a&gt; &lt;/p&gt;
  &lt;p&gt;Related blogs &amp;amp; articles: &lt;/p&gt;
  &lt;ul&gt;   &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/f5news/archive/2009/11/20/innovative-web-protection-and-compliance.aspx"&gt;Innovative Web Protection and Compliance&lt;/a&gt;&amp;nbsp;&lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://www.slideshare.net/DSorensenCPR/f5-offers-advanced-web-security-with-bigip-v101"&gt;BIG-IP v10.1 Security &lt;/a&gt; [Slideshare Presentation] &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/10/01/the-gazebo-on-your-web-site.aspx"&gt;Excuse Me But Is That a Gazebo On Your Site?!&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/09/28/web-application-security-at-the-edge-is-more-efficient-than.aspx"&gt;Web Application Security at the Edge is More Efficient Than In the Application&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/07/21/i-can-has-ur-.htaccess-file.aspx"&gt;I Can Has UR .htaccess File&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/07/08/automatically-removing-cookies.aspx"&gt;Automatically Removing Cookies&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/06/23/clickjacking-protection-using-x-frame-options-available-for-firefox.aspx"&gt;Clickjacking Protection Using X-FRAME-OPTIONS Available for Firefox&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/01/05/stop-brute-force-listing-of-http-options-with-network-side-scripting.aspx"&gt;Stop brute force listing of HTTP OPTIONS with network-side scripting&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a
      href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/04/23/jedi-mind-tricks-http-request-smuggling.aspx"&gt;Jedi Mind Tricks: HTTP Request Smuggling&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/01/15/i-am-in-your-http-headers-attacking-your-application.aspx"&gt;I am in your HTTP headers, attacking your application&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;
  &lt;div&gt;Technorati Tags: &lt;a
    href="http://technorati.com/tags/MacVittie"&gt;MacVittie&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/F5"&gt;F5&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/web+application+security"&gt;web application security&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/security"&gt;security&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/web+2.0"&gt;web 2.0&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/web+scraping"&gt;web scraping&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/ASM"&gt;ASM&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/web+application+firewall"&gt;web application firewall&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/WAF"&gt;WAF&lt;/a&gt;,&lt;a
    href="http://technorati.com/tags/D%26D"&gt;D&amp;amp;D&lt;/a&gt;,&lt;a href="http://technorati.com/tags/ADSB"&gt;ADSB&lt;/a&gt;&lt;/div&gt;
&lt;img height="1"
  src="http://devcentral.f5.com/weblogs/macvittie/aggbug/6222.aspx" width="1" /&gt;
&lt;img height="1"
  src="http://feeds.feedburner.com/~r/f5/XOwx/~4/lxUJyY7D-YI" width="1" /&gt;
&lt;p&gt;&lt;a href="https://ajax.sys-con.com/node/1198798"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 24 Nov 2009 17:30:00 GMT</pubDate>
      <guid>https://ajax.sys-con.com/node/1198798</guid>
      <dc:date>2009-11-24T17:30:00Z</dc:date>
    </item>
    <item>
      <title>Review: HP blade takes a stab at Cisco</title>
      <link>http://www.networkworld.com/reviews/2009/100509-hp-blade-test.html</link>
      <description>HP has an alternative to the many security appliances that combine firewall, intrusion detection and VPN functions: Just put a single blade in the vendor's ProCurve switch and be done with it.</description>
      <pubDate>Mon, 05 Oct 2009 11:38:47 GMT</pubDate>
      <guid>http://www.networkworld.com/reviews/2009/100509-hp-blade-test.html</guid>
      <dc:date>2009-10-05T11:38:47Z</dc:date>
    </item>
    <item>
      <title>Cloud Security on Ulitzer: Cloud Computing and Self-Service Security</title>
      <link>http://ajax.sys-con.com/node/1130676</link>
      <description>So here&amp;rsquo;s the rub, if MSSP&amp;rsquo;s/ISP&amp;rsquo;s/ASP&amp;rsquo;s-cum-Cloud operators want to woo mature enterprise customers to use their services, they are leaving money on the table and not fulfilling customer needs by failing to roll out complimentary security capabilities which lessen the compliance and security burdens of their prospective customers. While many provide commoditized solutions such as anti-spam and anti-virus capabilities, more complex (but profoundly important) security services such as DLP (data loss/leakage prevention,) WAF, Intrusion Detection and Prevention (IDP,) XML Security, Application Delivery Controllers, VPN&amp;rsquo;s, etc. should also be considered for roadmaps by these suppliers.&lt;p&gt;&lt;a href="http://ajax.sys-con.com/node/1130676"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Sat, 03 Oct 2009 18:30:00 GMT</pubDate>
      <guid>http://ajax.sys-con.com/node/1130676</guid>
      <dc:date>2009-10-03T18:30:00Z</dc:date>
    </item>
    <item>
      <title>Cloud Security on Ulitzer: Cloud Computing and Self-Service Security</title>
      <link>https://ajax.sys-con.com/node/1130676</link>
      <description>So here&amp;rsquo;s the rub, if MSSP&amp;rsquo;s/ISP&amp;rsquo;s/ASP&amp;rsquo;s-cum-Cloud operators want to woo mature enterprise customers to use their services, they are leaving money on the table and not fulfilling customer needs by failing to roll out complimentary security capabilities which lessen the compliance and security burdens of their prospective customers. While many provide commoditized solutions such as anti-spam and anti-virus capabilities, more complex (but profoundly important) security services such as DLP (data loss/leakage prevention,) WAF, Intrusion Detection and Prevention (IDP,) XML Security, Application Delivery Controllers, VPN&amp;rsquo;s, etc. should also be considered for roadmaps by these suppliers.&lt;p&gt;&lt;a href="https://ajax.sys-con.com/node/1130676"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Sat, 03 Oct 2009 18:30:00 GMT</pubDate>
      <guid>https://ajax.sys-con.com/node/1130676</guid>
      <dc:date>2009-10-03T18:30:00Z</dc:date>
    </item>
    <item>
      <title>Lifecycle of a network security vulnerability</title>
      <link>http://www.topix.net/tech/perl/2009/09/lifecycle-of-a-network-security-vulnerability?fromrss=1</link>
      <description>&lt;p&gt;Rating: --- The chapter below walks you through the process of providing network intrusion detection system coverage for a security vulnerability from start to finish, using practical examples and highlighting popular and useful open source tools.&lt;/p&gt;</description>
      <pubDate>Wed, 16 Sep 2009 04:47:23 GMT</pubDate>
      <guid>http://www.topix.net/tech/perl/2009/09/lifecycle-of-a-network-security-vulnerability?fromrss=1</guid>
      <dc:date>2009-09-16T04:47:23Z</dc:date>
    </item>
    <item>
      <title>Cloud Computing Best Practices</title>
      <link>http://websphere.sys-con.com/node/1103814</link>
      <description>&lt;p&gt;Some of the key things to think about when putting your application on the cloud are discussed below. Cloud computing is relatively new, and best practice is still being established. However we can learn from earlier technologies and concepts such as utility compute, SaaS, outsourcing and even internal enterprise centre management, as well as from experience with vendors such as Amazon and FlexiScale.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Licensing: &lt;/strong&gt;If you are using the cloud for spikes or overspill make sure that the products you want to use in the cloud can be used in this way. Certain products restrict their licenses to be used from a cloud perspective. This is especially true of commercial Grid, HPC or DataGrid vendors.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Data transfer costs: &lt;/strong&gt; When using a provider like Amazon with a detailed cost model, make sure that any data transfers are internal to the provider network rather than external. In the case of Amazon, internal traffic is free but you will be charged for any traffic over the external IP addresses.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Latency:&lt;/strong&gt; If you have low latency requirements then the Cloud may not be the best environment to achieve this. If you are trying to run an ERP or some such system in the cloud then the latency may be good enough but if you are trying to run a binary or FX Exchange then of course the latency requirements are very different and more stringent. It is essential to make sure you understand the performance requirements of your application and have a clear understanding of what is deemed business critical.&lt;/p&gt;


&lt;p&gt;One vendor who has focused on attacking low latency in the cloud is &lt;a
    href="http://blog.gigaspaces.com/2008/11/07/scaling-the-web-layer-%E2%80%93-the-web-container-benchmark/"&gt;GigaSpaces&lt;/a&gt; and so if you require cloud low latency then these are one of the companies you should evaluate. Also for processing distributed data loads there is the &lt;a
    href="http://en.wikipedia.org/wiki/MapReduce"&gt;map reduce pattern&lt;/a&gt; and &lt;a href="http://wiki.apache.org/hadoop/AmazonEC2"&gt;Hadoop&lt;/a&gt;. These type of architectures eliminating the boundaries created by scale-out database based approaches.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;State: &lt;/strong&gt;Check whether your cloud infrastructure providers have persistence. When an application is brought down and then back up all local changes will be wiped and you start with a blank slate. This obviously has ramifications with instances that need to store user or application state. To combat this on their platform Amazon delivered EC2 persistent storage in which data can remain linked to a specific computing instance. You should ensure you understand the state limitations of any Cloud Computing platform that you work with.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Data Regulations:&lt;/strong&gt; If you are storing data in the cloud you may be breaching data laws depending where your data is stored i.e. which country or continent. To combat this Amazon S3 now supports location constraints, which allow you to specify where in the world to store data for a bucket and provides a new API to retrieve the location constraint for an existing bucket. However if you are using another cloud provider you should check where your data is stored.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Dependencies: &lt;/strong&gt;Be aware of dependencies of service providers. If service &amp;lsquo;y&amp;rsquo; is dependant on &amp;lsquo;x&amp;rsquo; then if you subscribe to service &amp;lsquo;y&amp;rsquo; and service &amp;lsquo;x&amp;rsquo; goes down you lose your service. Always check any dependencies when you are using a cloud service.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Standardisation: &lt;/strong&gt;A major issue with current cloud computing platforms is that there is no standardisation of the APIs and platform technologies that underpin the services provided. Although this represents a lack of maturity you need to consider how locked in you are when considering a Cloud platform or migrating between cloud computing platforms will be very difficult if not impossible. This may not be an issue if your supplier is IBM and always likely to be IBM, but it will be an issue if you are just dipping your toe in the water and discover that other platforms are better suited to your needs.&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;Security: &lt;/strong&gt;Lack of security or apparent lack of security is one of the perceived major drawbacks of working with Cloud platform and Cloud technology. When moving sensitive data about or storing it in public cloud it should be encrypted. And it is important to consider a secure ID mechanism for authentication and authorisation for services. As with normal enterprise infrastructures only open the ports needed and consider installing a host based intrusion detection systems such as &lt;a
    href="http://www.ossec.net/"&gt;OSSEC&lt;/a&gt;.&amp;nbsp;The advantage of working with an enterprise Cloud provider, such as IBM or Sun is that many of these security optimisations are already taken care of. See our prior &lt;a
    href="http://www.cloudiquity.com/2009/02/securing-distributed-applications-on-ec2/"&gt;blog entry &lt;/a&gt;for securing n-tier and distributed applications on the cloud. Be sure to check out Amazon&amp;rsquo;s new &lt;a
    href="http://aws.amazon.com/vpc/"&gt;VPC inititative&lt;/a&gt; as well as looking at &lt;a
    href="http://www.cohesiveft.com/vpncubed/"&gt;VPN-Cubed&lt;/a&gt; by&lt;a
    href="http://www.Cohesiveft.com"&gt; CohesiveFT&lt;/a&gt; if you have to tie together public Clouds with private applications, services or infrastructure. If you need to keep costs down and evaluate free then look at &lt;a href="http://www.openvpn.net/"&gt;OpenVPN&lt;/a&gt;.&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;Compliance: &lt;/strong&gt;Regulatory controls mean that certain applications may not be able to deployed in the Cloud. For example the US &lt;em&gt;Patriot Act&lt;/em&gt; could have very serious consequences for non-US firms considering U.S. hosted cloud providers. Be aware that often cloud computing platforms are made up of components from a variety of vendors who may themselves provide computing in a variety of legal jurisdictions. Be very aware of the dependencies and ensure you factor this into any operational risk management assessment. See also my prior &lt;a href="http://www.cloudiquity.com/2009/03/will-the-cloud-survive-regulation/"&gt;blog entry &lt;/a&gt;on this topic&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;Quality of service:&lt;/strong&gt; You will need to ensure that the behaviour and effectiveness of the cloud application that you implement can be measured and tracked both to meet existing or new Service Level agreements. We have discussed previously some of the tools that come with this option built in (&lt;a
    href="http://www.gigaspaces.com/cloud"&gt;GigaSpaces&lt;/a&gt;) and other tools that provide functionality that enable you to use this with your Cloud Architecture (&lt;a
    href="http://www.rightscale.com/"&gt;RightScale&lt;/a&gt;, &lt;a href="https://www.scalr.net/"&gt;Scalr&lt;/a&gt; etc). Achieving Quality of Service will encompass scaling, reliability, service fluidity, monitoring, management and system performance.&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;System hardening: &lt;/strong&gt;Like all enterprise application infrastructures you need to harden the system so that it is secure, robust, and achieves the necessary functional requirements that you need. See my prior &lt;a href="http://www.cloudiquity.com/2009/04/system-hardening-guidelines-for-amazon-ec2/"&gt;blog entry&lt;/a&gt; on system hardening for Amazon EC2.&lt;/p&gt;


&lt;div&gt;Content adapted from my book &amp;ldquo;TheSavvyGuideTo HPC, Grid, DataGrid, Virtualisation and Cloud Computing&amp;rdquo; &lt;a href="http://www.amazon.com/TheSavvyGuideTo-Grid-Virtualisation-Cloud-Computing/dp/095599070X"&gt;available on Amazon&lt;/a&gt;.&lt;/div&gt;

&lt;div&gt;&lt;img height="168"
    src="http://www.cloudiquity.com/wp-content/uploads/2009/05/138dc060ada07b2b569a0210-1l_aa240_.jpg" width="168" /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://websphere.sys-con.com/node/1103814"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Sun, 13 Sep 2009 16:15:00 GMT</pubDate>
      <guid>http://websphere.sys-con.com/node/1103814</guid>
      <dc:date>2009-09-13T16:15:00Z</dc:date>
    </item>
    <item>
      <title>Cloud Computing Best Practices</title>
      <link>http://dotnet.sys-con.com/node/1103814</link>
      <description>&lt;p&gt;Some of the key things to think about when putting your application on the cloud are discussed below. Cloud computing is relatively new, and best practice is still being established. However we can learn from earlier technologies and concepts such as utility compute, SaaS, outsourcing and even internal enterprise centre management, as well as from experience with vendors such as Amazon and FlexiScale.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Licensing: &lt;/strong&gt;If you are using the cloud for spikes or overspill make sure that the products you want to use in the cloud can be used in this way. Certain products restrict their licenses to be used from a cloud perspective. This is especially true of commercial Grid, HPC or DataGrid vendors.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Data transfer costs: &lt;/strong&gt; When using a provider like Amazon with a detailed cost model, make sure that any data transfers are internal to the provider network rather than external. In the case of Amazon, internal traffic is free but you will be charged for any traffic over the external IP addresses.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Latency:&lt;/strong&gt; If you have low latency requirements then the Cloud may not be the best environment to achieve this. If you are trying to run an ERP or some such system in the cloud then the latency may be good enough but if you are trying to run a binary or FX Exchange then of course the latency requirements are very different and more stringent. It is essential to make sure you understand the performance requirements of your application and have a clear understanding of what is deemed business critical.&lt;/p&gt;


&lt;p&gt;One vendor who has focused on attacking low latency in the cloud is &lt;a
    href="http://blog.gigaspaces.com/2008/11/07/scaling-the-web-layer-%E2%80%93-the-web-container-benchmark/"&gt;GigaSpaces&lt;/a&gt; and so if you require cloud low latency then these are one of the companies you should evaluate. Also for processing distributed data loads there is the &lt;a
    href="http://en.wikipedia.org/wiki/MapReduce"&gt;map reduce pattern&lt;/a&gt; and &lt;a href="http://wiki.apache.org/hadoop/AmazonEC2"&gt;Hadoop&lt;/a&gt;. These type of architectures eliminating the boundaries created by scale-out database based approaches.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;State: &lt;/strong&gt;Check whether your cloud infrastructure providers have persistence. When an application is brought down and then back up all local changes will be wiped and you start with a blank slate. This obviously has ramifications with instances that need to store user or application state. To combat this on their platform Amazon delivered EC2 persistent storage in which data can remain linked to a specific computing instance. You should ensure you understand the state limitations of any Cloud Computing platform that you work with.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Data Regulations:&lt;/strong&gt; If you are storing data in the cloud you may be breaching data laws depending where your data is stored i.e. which country or continent. To combat this Amazon S3 now supports location constraints, which allow you to specify where in the world to store data for a bucket and provides a new API to retrieve the location constraint for an existing bucket. However if you are using another cloud provider you should check where your data is stored.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Dependencies: &lt;/strong&gt;Be aware of dependencies of service providers. If service &amp;lsquo;y&amp;rsquo; is dependant on &amp;lsquo;x&amp;rsquo; then if you subscribe to service &amp;lsquo;y&amp;rsquo; and service &amp;lsquo;x&amp;rsquo; goes down you lose your service. Always check any dependencies when you are using a cloud service.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Standardisation: &lt;/strong&gt;A major issue with current cloud computing platforms is that there is no standardisation of the APIs and platform technologies that underpin the services provided. Although this represents a lack of maturity you need to consider how locked in you are when considering a Cloud platform or migrating between cloud computing platforms will be very difficult if not impossible. This may not be an issue if your supplier is IBM and always likely to be IBM, but it will be an issue if you are just dipping your toe in the water and discover that other platforms are better suited to your needs.&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;Security: &lt;/strong&gt;Lack of security or apparent lack of security is one of the perceived major drawbacks of working with Cloud platform and Cloud technology. When moving sensitive data about or storing it in public cloud it should be encrypted. And it is important to consider a secure ID mechanism for authentication and authorisation for services. As with normal enterprise infrastructures only open the ports needed and consider installing a host based intrusion detection systems such as &lt;a
    href="http://www.ossec.net/"&gt;OSSEC&lt;/a&gt;.&amp;nbsp;The advantage of working with an enterprise Cloud provider, such as IBM or Sun is that many of these security optimisations are already taken care of. See our prior &lt;a
    href="http://www.cloudiquity.com/2009/02/securing-distributed-applications-on-ec2/"&gt;blog entry &lt;/a&gt;for securing n-tier and distributed applications on the cloud. Be sure to check out Amazon&amp;rsquo;s new &lt;a
    href="http://aws.amazon.com/vpc/"&gt;VPC inititative&lt;/a&gt; as well as looking at &lt;a
    href="http://www.cohesiveft.com/vpncubed/"&gt;VPN-Cubed&lt;/a&gt; by&lt;a
    href="http://www.Cohesiveft.com"&gt; CohesiveFT&lt;/a&gt; if you have to tie together public Clouds with private applications, services or infrastructure. If you need to keep costs down and evaluate free then look at &lt;a href="http://www.openvpn.net/"&gt;OpenVPN&lt;/a&gt;.&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;Compliance: &lt;/strong&gt;Regulatory controls mean that certain applications may not be able to deployed in the Cloud. For example the US &lt;em&gt;Patriot Act&lt;/em&gt; could have very serious consequences for non-US firms considering U.S. hosted cloud providers. Be aware that often cloud computing platforms are made up of components from a variety of vendors who may themselves provide computing in a variety of legal jurisdictions. Be very aware of the dependencies and ensure you factor this into any operational risk management assessment. See also my prior &lt;a href="http://www.cloudiquity.com/2009/03/will-the-cloud-survive-regulation/"&gt;blog entry &lt;/a&gt;on this topic&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;Quality of service:&lt;/strong&gt; You will need to ensure that the behaviour and effectiveness of the cloud application that you implement can be measured and tracked both to meet existing or new Service Level agreements. We have discussed previously some of the tools that come with this option built in (&lt;a
    href="http://www.gigaspaces.com/cloud"&gt;GigaSpaces&lt;/a&gt;) and other tools that provide functionality that enable you to use this with your Cloud Architecture (&lt;a
    href="http://www.rightscale.com/"&gt;RightScale&lt;/a&gt;, &lt;a href="https://www.scalr.net/"&gt;Scalr&lt;/a&gt; etc). Achieving Quality of Service will encompass scaling, reliability, service fluidity, monitoring, management and system performance.&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;System hardening: &lt;/strong&gt;Like all enterprise application infrastructures you need to harden the system so that it is secure, robust, and achieves the necessary functional requirements that you need. See my prior &lt;a href="http://www.cloudiquity.com/2009/04/system-hardening-guidelines-for-amazon-ec2/"&gt;blog entry&lt;/a&gt; on system hardening for Amazon EC2.&lt;/p&gt;


&lt;div&gt;Content adapted from my book &amp;ldquo;TheSavvyGuideTo HPC, Grid, DataGrid, Virtualisation and Cloud Computing&amp;rdquo; &lt;a href="http://www.amazon.com/TheSavvyGuideTo-Grid-Virtualisation-Cloud-Computing/dp/095599070X"&gt;available on Amazon&lt;/a&gt;.&lt;/div&gt;

&lt;div&gt;&lt;img height="168"
    src="http://www.cloudiquity.com/wp-content/uploads/2009/05/138dc060ada07b2b569a0210-1l_aa240_.jpg" width="168" /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://dotnet.sys-con.com/node/1103814"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Sun, 13 Sep 2009 11:15:00 GMT</pubDate>
      <guid>http://dotnet.sys-con.com/node/1103814</guid>
      <dc:date>2009-09-13T11:15:00Z</dc:date>
    </item>
    <item>
      <title>Cloud Computing Best Practices</title>
      <link>http://soa.sys-con.com/node/1103814</link>
      <description>&lt;p&gt;Some of the key things to think about when putting your application on the cloud are discussed below. Cloud computing is relatively new, and best practice is still being established. However we can learn from earlier technologies and concepts such as utility compute, SaaS, outsourcing and even internal enterprise centre management, as well as from experience with vendors such as Amazon and FlexiScale.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Licensing: &lt;/strong&gt;If you are using the cloud for spikes or overspill make sure that the products you want to use in the cloud can be used in this way. Certain products restrict their licenses to be used from a cloud perspective. This is especially true of commercial Grid, HPC or DataGrid vendors.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Data transfer costs: &lt;/strong&gt; When using a provider like Amazon with a detailed cost model, make sure that any data transfers are internal to the provider network rather than external. In the case of Amazon, internal traffic is free but you will be charged for any traffic over the external IP addresses.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Latency:&lt;/strong&gt; If you have low latency requirements then the Cloud may not be the best environment to achieve this. If you are trying to run an ERP or some such system in the cloud then the latency may be good enough but if you are trying to run a binary or FX Exchange then of course the latency requirements are very different and more stringent. It is essential to make sure you understand the performance requirements of your application and have a clear understanding of what is deemed business critical.&lt;/p&gt;


&lt;p&gt;One vendor who has focused on attacking low latency in the cloud is &lt;a
    href="http://blog.gigaspaces.com/2008/11/07/scaling-the-web-layer-%E2%80%93-the-web-container-benchmark/"&gt;GigaSpaces&lt;/a&gt; and so if you require cloud low latency then these are one of the companies you should evaluate. Also for processing distributed data loads there is the &lt;a
    href="http://en.wikipedia.org/wiki/MapReduce"&gt;map reduce pattern&lt;/a&gt; and &lt;a href="http://wiki.apache.org/hadoop/AmazonEC2"&gt;Hadoop&lt;/a&gt;. These type of architectures eliminating the boundaries created by scale-out database based approaches.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;State: &lt;/strong&gt;Check whether your cloud infrastructure providers have persistence. When an application is brought down and then back up all local changes will be wiped and you start with a blank slate. This obviously has ramifications with instances that need to store user or application state. To combat this on their platform Amazon delivered EC2 persistent storage in which data can remain linked to a specific computing instance. You should ensure you understand the state limitations of any Cloud Computing platform that you work with.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Data Regulations:&lt;/strong&gt; If you are storing data in the cloud you may be breaching data laws depending where your data is stored i.e. which country or continent. To combat this Amazon S3 now supports location constraints, which allow you to specify where in the world to store data for a bucket and provides a new API to retrieve the location constraint for an existing bucket. However if you are using another cloud provider you should check where your data is stored.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Dependencies: &lt;/strong&gt;Be aware of dependencies of service providers. If service &amp;lsquo;y&amp;rsquo; is dependant on &amp;lsquo;x&amp;rsquo; then if you subscribe to service &amp;lsquo;y&amp;rsquo; and service &amp;lsquo;x&amp;rsquo; goes down you lose your service. Always check any dependencies when you are using a cloud service.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Standardisation: &lt;/strong&gt;A major issue with current cloud computing platforms is that there is no standardisation of the APIs and platform technologies that underpin the services provided. Although this represents a lack of maturity you need to consider how locked in you are when considering a Cloud platform or migrating between cloud computing platforms will be very difficult if not impossible. This may not be an issue if your supplier is IBM and always likely to be IBM, but it will be an issue if you are just dipping your toe in the water and discover that other platforms are better suited to your needs.&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;Security: &lt;/strong&gt;Lack of security or apparent lack of security is one of the perceived major drawbacks of working with Cloud platform and Cloud technology. When moving sensitive data about or storing it in public cloud it should be encrypted. And it is important to consider a secure ID mechanism for authentication and authorisation for services. As with normal enterprise infrastructures only open the ports needed and consider installing a host based intrusion detection systems such as &lt;a
    href="http://www.ossec.net/"&gt;OSSEC&lt;/a&gt;.&amp;nbsp;The advantage of working with an enterprise Cloud provider, such as IBM or Sun is that many of these security optimisations are already taken care of. See our prior &lt;a
    href="http://www.cloudiquity.com/2009/02/securing-distributed-applications-on-ec2/"&gt;blog entry &lt;/a&gt;for securing n-tier and distributed applications on the cloud. Be sure to check out Amazon&amp;rsquo;s new &lt;a
    href="http://aws.amazon.com/vpc/"&gt;VPC inititative&lt;/a&gt; as well as looking at &lt;a
    href="http://www.cohesiveft.com/vpncubed/"&gt;VPN-Cubed&lt;/a&gt; by&lt;a
    href="http://www.Cohesiveft.com"&gt; CohesiveFT&lt;/a&gt; if you have to tie together public Clouds with private applications, services or infrastructure. If you need to keep costs down and evaluate free then look at &lt;a href="http://www.openvpn.net/"&gt;OpenVPN&lt;/a&gt;.&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;Compliance: &lt;/strong&gt;Regulatory controls mean that certain applications may not be able to deployed in the Cloud. For example the US &lt;em&gt;Patriot Act&lt;/em&gt; could have very serious consequences for non-US firms considering U.S. hosted cloud providers. Be aware that often cloud computing platforms are made up of components from a variety of vendors who may themselves provide computing in a variety of legal jurisdictions. Be very aware of the dependencies and ensure you factor this into any operational risk management assessment. See also my prior &lt;a href="http://www.cloudiquity.com/2009/03/will-the-cloud-survive-regulation/"&gt;blog entry &lt;/a&gt;on this topic&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;Quality of service:&lt;/strong&gt; You will need to ensure that the behaviour and effectiveness of the cloud application that you implement can be measured and tracked both to meet existing or new Service Level agreements. We have discussed previously some of the tools that come with this option built in (&lt;a
    href="http://www.gigaspaces.com/cloud"&gt;GigaSpaces&lt;/a&gt;) and other tools that provide functionality that enable you to use this with your Cloud Architecture (&lt;a
    href="http://www.rightscale.com/"&gt;RightScale&lt;/a&gt;, &lt;a href="https://www.scalr.net/"&gt;Scalr&lt;/a&gt; etc). Achieving Quality of Service will encompass scaling, reliability, service fluidity, monitoring, management and system performance.&lt;/p&gt;


&lt;p&gt;&lt;strong&gt;System hardening: &lt;/strong&gt;Like all enterprise application infrastructures you need to harden the system so that it is secure, robust, and achieves the necessary functional requirements that you need. See my prior &lt;a href="http://www.cloudiquity.com/2009/04/system-hardening-guidelines-for-amazon-ec2/"&gt;blog entry&lt;/a&gt; on system hardening for Amazon EC2.&lt;/p&gt;


&lt;div&gt;Content adapted from my book &amp;ldquo;TheSavvyGuideTo HPC, Grid, DataGrid, Virtualisation and Cloud Computing&amp;rdquo; &lt;a href="http://www.amazon.com/TheSavvyGuideTo-Grid-Virtualisation-Cloud-Computing/dp/095599070X"&gt;available on Amazon&lt;/a&gt;.&lt;/div&gt;

&lt;div&gt;&lt;img height="168"
    src="http://www.cloudiquity.com/wp-content/uploads/2009/05/138dc060ada07b2b569a0210-1l_aa240_.jpg" width="168" /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://soa.sys-con.com/node/1103814"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Sat, 12 Sep 2009 19:00:00 GMT</pubDate>
      <guid>http://soa.sys-con.com/node/1103814</guid>
      <dc:date>2009-09-12T19:00:00Z</dc:date>
    </item>
  </channel>
</rss>

