<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: Tag breaches</title>
    <link>http://blog.clearnetsec.com/articles/tag/breaches</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>A few data points for assessing threats</title>
      <description>In a &lt;a href="http://blog.clearnetsec.com/articles/2006/09/14/is-it-possible-to-prioritize-the-deployment-of-common-security-tools-for-most-companies"&gt;recent post&lt;/a&gt; we talked about if it is possible to prioritize the deployment of solutions which are widely accepted to reduce risk to a business (without completing a threat assessment).  A list you can say to someone "Well, without knowing your details I can say the most frequent threats or highest risks for &lt;strong&gt;&lt;i&gt;most &lt;/i&gt;&lt;/strong&gt;companies is from &lt;i&gt;THESE THINGS&lt;/i&gt;, but we really should do a threat assessment first".&lt;br /&gt;&lt;br /&gt;&lt;p&gt;I googled around and created a short list (I'm sure there are 1000s out there) of data points to help determine the "THESE THINGS" part: &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;My favorite resource:  &lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;From PrivacyRights.org, chronology of data breaches: &lt;a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm"&gt;http://www.privacyrights.org/ar/ChronDataBreaches.htm&lt;/a&gt; (probably the best resource because it doesn't restrict by type of threat)&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;i&gt;Like above:&lt;/i&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;From Mailerblog.com, data loss viewer (viewer to attrition's database of data breaches): &lt;a href="http://www.mailerblog.com/dataloss/dataloss.php"&gt;http://www.mailerblog.com/dataloss/dataloss.php&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;From PogoWasRight.org, collects information on data breaches: &lt;a href="http://www.pogowasright.org/"&gt;http://www.pogowasright.org/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The recent Visa USA press release:  &lt;a href="http://biz.yahoo.com/prnews/060915/dcf014.html?.v=3D64"&gt;http://biz.yahoo.com/prnews/060915/dcf014.html?.v=3D64&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A few network based threat stats:&lt;/strong&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;From DShield.org, top ports for scanning: &lt;a href="http://www.dshield.org/topports.php"&gt;
http://www.dshield.org/topports.php&lt;/a&gt;&lt;/p&gt;

From Incidents.org, survival time history: 
&lt;a href="http://isc.incidents.org/survivalhistory.php?isc=4fcfc1652464f1b60c02afecb75d332a"&gt;http://isc.incidents.org/survivalhistory.php?isc=4fcfc1652464f1b60c02afecb75d332a&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm"&gt;&lt;br /&gt;
&lt;/a&gt;&lt;p&gt;From Zone-h.org, attacks archive (defacements): &lt;a href="http://www.zone-h.org/component/option,com_attacks/Itemid,44/"&gt;http://www.zone-h.org/component/option,com_attacks/Itemid,44/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Virus specific:&lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;From SecurityStats.com, virus related statistics: &lt;a href="http://www.securitystats.com/virusstats.html"&gt;http://www.securitystats.com/virusstats.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;From F-Secure, virus statistics: &lt;a href="http://www.f-secure.com/virus-info/statistics/"&gt;http://www.f-secure.com/virus-info/statistics/&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;From McAfree, virus activity: &lt;a href="http://vil.mcafee.com/mast/viruses_by_continent.asp?continent_k=0&amp;amp;track_by=1&amp;amp;period_id=1"&gt;http://vil.mcafee.com/mast/viruses_by_continent.asp?continent_k=0&amp;amp;track_by=1&amp;amp;period_id=1&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;From Symantec, threat explorer: &lt;a href="http://www.symantec.com/enterprise/security_response/threatexplorer/threats.jsp"&gt;http://www.symantec.com/enterprise/security_response/threatexplorer/threats.jsp&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;From Postini, StatTrack (including DHA/SPAM stats): &lt;a href="http://www.postini.com/stats/"&gt;http://www.postini.com/stats/&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Insider snippets:&lt;/strong&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;From Bruce Schneier, news summary:  &lt;a href="http://www.schneier.com/blog/archives/2005/12/insider_threat.html"&gt;http://www.schneier.com/blog/archives/2005/12/insider_threat.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Illicity Cyber Activity in the Banking and Finance Sectors, news summary:  &lt;a href="http://www.gcn.com/online/vol1_no1/27074-1.html"&gt;http://www.gcn.com/online/vol1_no1/27074-1.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Reconnex threat stats:  &lt;a href="http://www.reconnex.net/Threat/"&gt;http://www.reconnex.net/Threat/&lt;/a&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/p&gt;

&lt;p&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/p&gt;

&lt;p&gt;&lt;i&gt;I can probably find a lot more statistics from combing CERT pages, but I stopped:&lt;/i&gt; &lt;a href="http://www.cert-in.org.in/worldcert.htm"&gt;http://www.cert-in.org.in/worldcert.htm&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p/&gt;

</description>
      <pubDate>Sun, 24 Sep 2006 00:04:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:d6573cee-799e-423e-85fd-f277d0d99e42</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2006/09/24/a-few-data-points-for-assessing-threats</link>
      <category>security</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>threat assessment</category>
      <category>virus statistics</category>
      <category>breaches</category>
    </item>
  </channel>
</rss>
