<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in Pro-Forma &amp;#8216;06 Punditry Results</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Thu, 13 Mar 2008 03:17:44 -0000</lastBuildDate><item><title>Re: Pro-Forma &amp;#8216;06 Punditry Results</title><link>http://www.matasano.com/log/661/pro-forma-06-punditry-results/#comment-2321345</link><description>What is APE? I only know OSSIM....</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">W.L&amp;gt;</dc:creator><pubDate>Thu, 13 Mar 2008 03:17:44 -0000</pubDate></item><item><title>Re: Pro-Forma &amp;#8216;06 Punditry Results</title><link>http://www.matasano.com/log/661/pro-forma-06-punditry-results/#comment-2321344</link><description>We're using OSSIM in out company. I think it's a good replacement of commercial SIMs, although it hasn't got so much report funcionality.&lt;br&gt;&lt;br&gt;you can take a look at &lt;a href="http://www.ossim.net" rel="nofollow"&gt;http://www.ossim.net&lt;/a&gt; to check it.&lt;br&gt;&lt;br&gt;Hkr.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hikaru</dc:creator><pubDate>Wed, 14 Mar 2007 16:37:40 -0000</pubDate></item><item><title>Re: Pro-Forma &amp;#8216;06 Punditry Results</title><link>http://www.matasano.com/log/661/pro-forma-06-punditry-results/#comment-2321343</link><description>An interesting thread, &lt;br&gt;&lt;br&gt;I'm sure we're lacking marketing but at least I'd like to know why:&lt;br&gt;&lt;br&gt;#4 OSSIM&lt;br&gt;&lt;br&gt;is not an option, after almost five years of development.&lt;br&gt;&lt;br&gt;You get:&lt;br&gt;- Correlation engine.&lt;br&gt;- Simple correlation engine language (xml).&lt;br&gt;- Lightweight plugins.&lt;br&gt;- Cross correlation (Snort-Nessus)&lt;br&gt;- Various anomaly detection engines (OS, Mac, Services, IP/TCP/UDP/...)&lt;br&gt;- Website provides more information.&lt;br&gt;&lt;br&gt;I'd be glad to provide more information, samples and documents in case I get the opportunity.&lt;br&gt;&lt;br&gt;Dominique</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dominique Karg</dc:creator><pubDate>Sun, 21 Jan 2007 16:41:51 -0000</pubDate></item><item><title>Re: Pro-Forma &amp;#8216;06 Punditry Results</title><link>http://www.matasano.com/log/661/pro-forma-06-punditry-results/#comment-2321342</link><description>I think we need to get a spreadsheet of the vulnerabilities and work them out by application and impact. I'm also probably giving the research community credit for things that turn out not to be reliably exploitable on XPSP2. I also get the sense that this has been a rough year for browsers in general and IE in particular.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 03 Jan 2007 17:34:53 -0000</pubDate></item><item><title>Re: Pro-Forma &amp;#8216;06 Punditry Results</title><link>http://www.matasano.com/log/661/pro-forma-06-punditry-results/#comment-2321341</link><description>Tom-&lt;br&gt;On #1 - why didn't the # of M$ vulnerabilities drop?  Is it too early (i.e. you'll repeat this prediction for 2007 and declare you were just ahead of the curve) or are their investments in SDL and security audit not working?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">PaulM</dc:creator><pubDate>Wed, 03 Jan 2007 17:16:36 -0000</pubDate></item><item><title>Re: Pro-Forma &amp;#8216;06 Punditry Results</title><link>http://www.matasano.com/log/661/pro-forma-06-punditry-results/#comment-2321340</link><description>From the orignal 2006 Prediction post:&lt;br&gt;&lt;br&gt;"Expect a mainstream open-source&lt;br&gt;combination of Argus and Sguil to own the security management&lt;br&gt;conversation next year."&lt;br&gt;&lt;br&gt;Sorry to let you down. I'd take half the blame except adding Argus to Sguil doesn't a SIM make (&lt;a href="http://infosecpotpourri.blogspot.com/2006/01/sguil-is-not-sim.html" rel="nofollow"&gt;http://infosecpotpourri.blogspot.com/2006/01/sg...&lt;/a&gt;).&lt;br&gt;&lt;br&gt;Also, Sguil has used SANCP (or a similar app) to provide flow/connection/session data since its inception. I've done a bit of research and haven't been able to find a compelling reason to create some type of hook between Sguil and Argus (yet).&lt;br&gt;&lt;br&gt;OSSEC (&lt;a href="http://www.ossec.net" rel="nofollow"&gt;http://www.ossec.net&lt;/a&gt;) is starting to get more exposure though and as much as I despise the term SIM, it is starting to fill that void (even if it is labeled as a HIDS). Here is a list of log types it supports: &lt;a href="http://www.ossec.net/wiki/index.php/Supported-Logs" rel="nofollow"&gt;http://www.ossec.net/wiki/index.php/Supported-Logs&lt;/a&gt;.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bamm</dc:creator><pubDate>Wed, 03 Jan 2007 15:39:24 -0000</pubDate></item><item><title>Re: Pro-Forma &amp;#8216;06 Punditry Results</title><link>http://www.matasano.com/log/661/pro-forma-06-punditry-results/#comment-2321339</link><description>On #4, I'd agree with Anton partially (though I think log format support is less of an issue) but also point out that really what most companies are buying are the rules that are used by the SIM and the integration with ticketing systems, oh and the GUI. There are a couple good open source correlation engines out there (APE &amp;amp; OSSIM just off the top of my head) but having the other pieces is just a huge pain in the ass. &lt;br&gt;I can't tell you how many really cool ideas I had pitched by VCs for a SIM based on a really neat technical approach. None of them figured in the issue of integrating with all the ticketing systems or building a good GUI with functional workflow (see BASE &amp;amp; SGUIL vs. ACID in terms of workflow clarity), etc...&lt;br&gt;I don't expect to ever see a complete open source SIM. The correlation engines have existed for a couple years though.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">toby</dc:creator><pubDate>Wed, 03 Jan 2007 15:32:57 -0000</pubDate></item><item><title>Re: Pro-Forma &amp;#8216;06 Punditry Results</title><link>http://www.matasano.com/log/661/pro-forma-06-punditry-results/#comment-2321338</link><description>As far as #4 goes, I think we have something very close to a "credible" open source sim. OSSEC is being used more and more as a commercial SIM replacement and we currently support multiple log formats:&lt;br&gt;&lt;br&gt;&lt;a href="http://www.ossec.net/wiki/index.php/Supported-Logs" rel="nofollow"&gt;http://www.ossec.net/wiki/index.php/Supported-Logs&lt;/a&gt;&lt;br&gt;&lt;br&gt;Most people think of it as an HIDS only, but its log analysis and correlation options are side by side with most commercial solutions (and even better most of the times).&lt;br&gt;&lt;br&gt;Link to it: &lt;a href="http://www.ossec.net" rel="nofollow"&gt;http://www.ossec.net&lt;/a&gt;&lt;br&gt;&lt;br&gt;Thanks,&lt;br&gt;&lt;br&gt;Daniel Cid</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Daniel Cid</dc:creator><pubDate>Wed, 03 Jan 2007 15:03:47 -0000</pubDate></item><item><title>Re: Pro-Forma &amp;#8216;06 Punditry Results</title><link>http://www.matasano.com/log/661/pro-forma-06-punditry-results/#comment-2321337</link><description>Sorry, I have to snicker at the miserable failure of #4 prediction :-)  Just as I predicted.&lt;br&gt;&lt;br&gt;"What’s taking you guys so long?"&lt;br&gt;&lt;br&gt;Same as what I mentioned in our discussion thread: ongoing maintainance and log source support.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anton Chuvakin</dc:creator><pubDate>Wed, 03 Jan 2007 14:12:51 -0000</pubDate></item><item><title>Re: Pro-Forma &amp;#8216;06 Punditry Results</title><link>http://www.matasano.com/log/661/pro-forma-06-punditry-results/#comment-2321336</link><description>MARS sold almost "too well" this past year.  I expect a backlash against Cisco for MARS, CSA/CCA, and NAC in 2007.  Especially when companies start to renew their SMARTNet contracts and realize the utter lack of value any of those products provided.&lt;br&gt;&lt;br&gt;NAC was countered with &lt;a href="http://kevin.sf.net" rel="nofollow"&gt;http://kevin.sf.net&lt;/a&gt;&lt;br&gt;&lt;br&gt;CSA was countered by Slipfest at CanSecWest&lt;br&gt;&lt;br&gt;MARS detected one script kiddie running land.c until they graduated from idiot university and ran snot/sneeze/etc&lt;br&gt;&lt;br&gt;combine the usefulness of Cisco IPS and it appears we have a winner for "most silicon snake-oil in 2006".</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">dre</dc:creator><pubDate>Wed, 03 Jan 2007 13:17:27 -0000</pubDate></item></channel></rss>