<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The IPS Guy &#187; theipsguy</title>
	<atom:link href="http://theipsguy.com/author/theipsguy/feed/" rel="self" type="application/rss+xml" />
	<link>http://theipsguy.com</link>
	<description>Intrusion Prevention/Detection technologies.</description>
	<lastBuildDate>Sun, 13 May 2012 00:37:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Smishing</title>
		<link>http://theipsguy.com/smishing/</link>
		<comments>http://theipsguy.com/smishing/#comments</comments>
		<pubDate>Sat, 10 Dec 2011 21:25:28 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=268</guid>
		<description><![CDATA[Today I received the below email from my Credit Union. While this is not new it is the first time I have received an email warning from my bank. This is just a example of the threats to come. With the rise of the mobile Internet this is only going to continue to grow.  Credit [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<div>Today I received the below email from my Credit Union. While this is not new it is the first time I have received an email warning from my bank. This is just a example of the threats to come. With the rise of the mobile Internet this is only going to continue to grow.</div>
<div> Credit Union has received several reports from members receiving suspicious text messages and phone calls which state that their debit or credit card needs to be reactivated. Please be advised that these messages were not originated by #####, and is a reminder that cyber-crime is not just for computers anymore.</p>
<p>“Smishing”, the combination of texting and automated phone dialing, is an increasing scam the Federal Bureau of Investigation is warning consumers about as we head into the holiday shopping season. Holiday weekends typically see an increase in identity theft activity nationwide, as many financial institutions have limited Saturday hours or are closed. For additional information on how this scam works or steps you can take to safeguard your confidential information, please visit the Fraud Education section of our website.</p>
<p>At ######, we utilize the most advanced security technologies to protect your confidential information, and work diligently to identify scams and alert our members when such attempts are made. Neither we, nor any reputable financial institution would contact you by phone, text message or e-mail and ask for your confidential information.</p>
<p>If you suspect you have been a victim of identity theft, contact us immediately to report your card lost or stolen at the toll-free telephone number printed on the back of your ######### debit or credit card.</p></div>
<div>Sincerely,<br />
Credit Union</div>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/smishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Building the Case for Intrusion Prevention</title>
		<link>http://theipsguy.com/buildig-the-case-for-intrusion-prevention/</link>
		<comments>http://theipsguy.com/buildig-the-case-for-intrusion-prevention/#comments</comments>
		<pubDate>Fri, 09 Sep 2011 22:23:34 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>
		<category><![CDATA[Mcaffe]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=262</guid>
		<description><![CDATA[With the myriad of ‘trendy’ security topics taking the spotlight today, it is critical that organizations continue to focus on core network security, namely intrusion prevention, which is one of the most effective methods for securing the enterprise. Please join DG Technology for an online briefing on: • Do businesses need Intrusion Prevention Systems (”IPS”)? [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>With the myriad of ‘trendy’ security topics taking the spotlight today, it is critical that organizations continue to focus on core network security, namely intrusion prevention, which is one of the most effective methods for securing the enterprise.</p>
<p>Please join DG Technology for an online briefing on: • Do businesses need Intrusion Prevention Systems (”IPS”)? • If so, what’s the best way to evaluate potential IPS vendors? • Which vendor should you select for your IPS requirements?</p>
<p>Join us for this webinar. <a href="http://events.linkedin.com/events/773270/clickthru" rel="nofollow" target="_blank">https://www3.gotomeeting.com/register/206228382</a></p>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/buildig-the-case-for-intrusion-prevention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Article on DDOS related to WikiLeaks</title>
		<link>http://theipsguy.com/article-on-ddos-related-to-wikileaks/</link>
		<comments>http://theipsguy.com/article-on-ddos-related-to-wikileaks/#comments</comments>
		<pubDate>Mon, 13 Dec 2010 15:14:25 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=254</guid>
		<description><![CDATA[While it is certainly not new the fallout from the Wikileaks postings continue to come to light. As companies have decided not to be involved with Wikileaks and have distanced themselves from Wikileaks they have become the target of attackers that feel they are the bad guys. There have DDOS attacks against Mastercard, PayPal, Visa [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>While it is certainly not new the fallout from the Wikileaks postings continue to come to light. As companies have decided not to be involved with Wikileaks and have distanced themselves from Wikileaks they have become the target of attackers that feel they are the bad guys. There have DDOS attacks against Mastercard, PayPal, Visa and others. Many of these attacks have been carried out by a group that call themselves &#8220;Anonymous&#8221;. Unfortunately (or fortunately, depending on your perspective) for those that want to join Anonymous in their &#8220;hacktivisim&#8221; they are not truly anonymous.</p>
<p>Below is a link to an excellent paper that analyzes these DDOS attacks and the tool used to generate it. It is a good read.</p>
<p>http://bit.ly/i3okxm</p>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/article-on-ddos-related-to-wikileaks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nessus Iphone App</title>
		<link>http://theipsguy.com/nessus-iphone-app/</link>
		<comments>http://theipsguy.com/nessus-iphone-app/#comments</comments>
		<pubDate>Wed, 10 Nov 2010 16:05:33 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=244</guid>
		<description><![CDATA[Nessus has joined other security vendors in creating a Iphone app. They are the first vendor I know of though that allows you to manage their product. Up to this point the Iphone apps have only provided information and not allowed you to manage a product. Yes, you could get an SSH client for the [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Nessus has joined other security vendors in creating a Iphone app. They are the first vendor I know of though that allows you to manage their product. Up to this point the Iphone apps have only provided information and not allowed you to manage a product. Yes, you could get an SSH client for the phone and use that to connect to a product and scan but this is the first one I know of that allows you to manage their product. I would think companies like Qualys would have already done this since they are cloud based. It is nice to see Nessus continue to innovate and evolve.</p>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/nessus-iphone-app/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intel buys Mcafee</title>
		<link>http://theipsguy.com/intel-buys-mcafee/</link>
		<comments>http://theipsguy.com/intel-buys-mcafee/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 17:25:29 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=241</guid>
		<description><![CDATA[It was announced today that Intel will buy Mcafee for over $7 billion dollars in cash. There had been rumors that HP was looking to buy Mcafee which would have been interesting to see how they would have combined the Tippingpoint and Mcaffe intrusion prevention systems. At first glance the Intel merger does seem odd until you [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>It was announced today that Intel will buy Mcafee for over $7 billion dollars in cash. There had been rumors that HP was looking to buy Mcafee which would have been interesting to see how they would have combined the Tippingpoint and Mcaffe intrusion prevention systems. At first glance the Intel merger does seem odd until you begin to look at some of the benefits.</p>
<p>Intel is developing processors with AES instructions sets included. In many ways this allows Intel to provide hardware based encryption and they now own a product to directly integrate with this processor. They could also develop AV solutions running on chips which would dramatically increase the scanning speed.</p>
<p>If  handled correctly this could dramatically change the availability of these products. Why buy another solution if your hardware already has one.</p>
<div id="_mcePaste">Intel® AES-NI Impact</div>
<div id="_mcePaste">Testing with McAfee Endpoint Encryption* for PCs (EEPC) 6.0, encrypting a 32GB Intel® X25-E SATA SSD using the Intel® Xeon® processor 5600 series with Intel® AES-NI showed a 30% faster server SSD provisioning time compared to the prior generation processor without Intel AES-NI.</div>
<div></div>
<div>Link to Intel article.</div>
<div>http://bit.ly/9f3bKb</div>
<div></div>
<div>Article on CNN</div>
<div>http://bit.ly/aW36s1</div>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/intel-buys-mcafee/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Results for the CISM</title>
		<link>http://theipsguy.com/results-for-the-cism/</link>
		<comments>http://theipsguy.com/results-for-the-cism/#comments</comments>
		<pubDate>Mon, 16 Aug 2010 15:25:12 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=238</guid>
		<description><![CDATA[Well ISACA was not kidding when they said it takes 6-8 weeks to get the results. I received my email at 4:00pm exactly 8 weeks after taking the exam. The good news is that I passed the exam! I am now beginning the process of  verification of my work experience. ISACA says it takes 6-8 weeks for [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Well ISACA was not kidding when they said it takes 6-8 weeks to get the results. I received my email at 4:00pm exactly 8 weeks after taking the exam. The good news is that I passed the exam! I am now beginning the process of  verification of my work experience. ISACA says it takes 6-8 weeks for this as well and I am sure it will probably take the full 8 weeks.</p>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/results-for-the-cism/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thoughts on the CISM exam</title>
		<link>http://theipsguy.com/thoughts-on-the-cism-exam/</link>
		<comments>http://theipsguy.com/thoughts-on-the-cism-exam/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 14:28:25 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=236</guid>
		<description><![CDATA[So I took the CISM exam in June 12th. I have not received the results back yet, it generally takes 6-8 weeks. The test was tough and I thought the practice database from ISACA was a good representation of the type of questions to expect. I do think though that they could reduce the number [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>So I took the CISM exam in June 12th. I have not received the results back yet, it generally takes 6-8 weeks. The test was tough and I thought the practice database from ISACA was a good representation of the type of questions to expect. I do think though that they could reduce the number of questions from 200. There were many repetitive questions and for only 5 domains they should either add more unique questions or reduce the number.</p>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/thoughts-on-the-cism-exam/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Preparing for the CISM exam</title>
		<link>http://theipsguy.com/preparing-for-the-cism-exam/</link>
		<comments>http://theipsguy.com/preparing-for-the-cism-exam/#comments</comments>
		<pubDate>Sun, 30 May 2010 18:10:32 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=233</guid>
		<description><![CDATA[I have decided to sit for the CISM exam. The exam is scheduled for June 12th. ISACA only offers the exam two times per year so I figured this was the best time to take it. The CISM is growing in popularity and is becoming more common in job requirements, although it is still not [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I have decided to sit for the CISM exam. The exam is scheduled for June 12th. ISACA only offers the exam two times per year so I figured this was the best time to take it. The CISM is growing in popularity and is becoming more common in job requirements, although it is still not as popular as the CISSP. The CISM is more focused to those in management positions around Information Security and requires three years of actual management experience in Information Security.</p>
<p>The exam is 200 questions and you can take up to 4 hours to complete. It is considered very rigorous and at least as difficult as the CISSP. I am very excited to take this exam and will post some information in subsequent posts. More information on the CISM exam can be found below.</p>
<p><a title="http://bit.ly/a2Xclj" href="http://bit.ly/a2Xclj">http://bit.ly/a2Xclj</a></p>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/preparing-for-the-cism-exam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symantec to purchase PGP and GuardianEdge</title>
		<link>http://theipsguy.com/symantec-to-purchase-pgp-and-guardianedge/</link>
		<comments>http://theipsguy.com/symantec-to-purchase-pgp-and-guardianedge/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 18:46:29 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=227</guid>
		<description><![CDATA[While not related directly to IPS it is still news worthy. Symantec announce today they are buying PGP and GuardianEdge for $370 million dollars! Symantec has somewhat languished over the last few years without alot of truly innovative security products. This now places Symantec as a major player in the encryption space. They can now [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>While not related directly to IPS it is still news worthy. Symantec announce today they are buying PGP and GuardianEdge for $370 million dollars! Symantec has somewhat languished over the last few years without alot of truly innovative security products. This now places Symantec as a major player in the encryption space. They can now compete with other companies such as Mcaffe, Sophos and Checkpoint in the encryption space.</p>
<p>Interesting note: Mcafee previously owned PGP and sold it. They then later purchased Safeboot and now Symantec owns PGP. I guess Mcafee should have just kept PGP. <img src='http://theipsguy.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>http://www.theregister.co.uk/2010/04/29/symantec_buys_pgp/</p>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/symantec-to-purchase-pgp-and-guardianedge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virtual IPS vs. Virtualized IPS</title>
		<link>http://theipsguy.com/virtual-ips-vs-virtualized-ips/</link>
		<comments>http://theipsguy.com/virtual-ips-vs-virtualized-ips/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 17:48:14 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IBM]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[Sourcefire]]></category>
		<category><![CDATA[Virtual IPS]]></category>
		<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=223</guid>
		<description><![CDATA[Virtualization is a top priority for most organizations today. Security of these virtualized environments should also be a top priority and in the Intrusion Prevention market most vendors are developing or have developed virtual or virtualized solutions. The terms virtual IPS and virtualized IPS have different meanings and I want to take some time to [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Virtualization is a top priority for most organizations today. Security of these virtualized environments should also be a top priority and in the Intrusion Prevention market most vendors are developing or have developed virtual or virtualized solutions.</p>
<p>The terms virtual IPS and virtualized IPS have different meanings and I want to take some time to attempt to differentiate these terms. Most vendors have had virtual IPS for many years. Virtual IPS is the ability to apply different polices to certain types of traffic. This could be done using VLAN tags or physical interfaces. IBM does this using the Protection Domains feature which allows a different policy to be deployed to different VLAN&#8217;s. Mcafee does this by allowing different policies to be assigned to physical interfaces and can also support policies to be applied based no VLAN tags.</p>
<p>Virtualized IPS is what most of us think of today when we discuss virtualization. Virtualized IPS is an IPS appliance that runs in a virtual environment such as VmWare, Zen or Microsoft&#8217;s Hyper-V. The IPS is installed as a virtual server and can be configured so that all server to server traffic inside and outside the virtual environment can be monitored by an IPS.</p>
<p>It is important to be clear on these differences in terminology because not all vendors have virtualized IPS and most sales people will not know enough to properly answer the question, Do you support virtualization? Most will say yes, because they have heard their support teams talk about virtual IPS not virtualized IPS. Virtualized IPS will continue to grow in importance and eventually all the major Intrusion Prevention vendors will have these offerings. Until then do your homework and hold the vendors accountable.</p>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/virtual-ips-vs-virtualized-ips/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

