<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: Tag complex events</title>
    <link>http://blog.clearnetsec.com/articles/tag/complexevents</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>building a better security events system</title>
      <description>&lt;p&gt;
It&#8217;s hard to build a decision support system based on partial views of the world.  
&lt;/p&gt;
&lt;p&gt;
My goal is to identify interesting events on a network and to prioritize those events based on sets of attributes.  Yes, there are lots of products that do this.  But most focus on a slice of the world (e.g. an IDS fires an alert based on a regex match on a single packet). And that is boring.  
&lt;/p&gt;
&lt;p&gt;
Doing it for the whole world is where the action is at.  
&lt;/p&gt;
&lt;p&gt;
Capture an alert fired from an IDS, check netflow for a session, note a &#8220;first-time&#8221; event recorded in a syslog message, mix in statistical data mining and learning techniques &#8211; and do it all in near real time.  This is how things get interesting.
&lt;/p&gt;
&lt;p&gt;
Unfortunately it&#8217;s hard to get complete visibility (i.e. get all syslog, all netflow, all application logs, etc.).  There must be a point though where I can get enough information to successfully prioritize interesting events.  I&#8217;m not sure exactly where that&#8217;s at, but it&#8217;s a fun problem to work on. 
&lt;/p&gt;
&lt;p&gt;
&lt;i&gt;The picture is of the inside of IT-Universitetet in Copenhagen where I&#8217;m working for a few weeks.  The meeting rooms all jet out into the open space in the middle &#8211; a pretty cool design.&lt;/i&gt;
&lt;/p&gt;
&lt;img src="http://blog.clearnetsec.com/files/itu.gif"&gt;

</description>
      <pubDate>Sat, 30 Jun 2007 15:56:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:4ea21165-d129-4503-b259-01fdc1539e54</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2007/06/30/building-a-better-security-events-system</link>
      <category>security</category>
      <category>ClearNet</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>ids</category>
      <category>alerts</category>
      <category>events</category>
      <category>complex events</category>
    </item>
  </channel>
</rss>
