Sudanes fick hand och fot avhuggen SvD Utrikes(cached at February 27, 2013, 11:32 pm)

En sudanesisk man som dömts för väpnat rån fick sin hand och ena fot avhuggen som straff, uppger människorättsorganisationer i dag.
A New Approach To Database-Aided Data Processing Slashdotby Soulskill on database at January 1, 1970, 1:00 am (cached at February 27, 2013, 11:32 pm)

An anonymous reader writes "The Parallel Universe blog has a post about parallel data processing. They start off by talking about how Moore's Law still holds, but the shift from clock frequency to multiple cores has stifled the rate at which hardware allows software to scale. (Basically, Amdahl's Law.) The simplest approach to dealing with this is sharding, but that introduces its own difficulties. The more you shard a data set, the more work you need to do to separate out the data elements that can't interact. Optimizing for 2n cores takes more than twice the work of optimizing for n cores. The article says, 'If we want to continue writing compellingly complex applications at an ever-increasing scale we must come to terms with the new Moore's law and build our software on top of solid infrastructure designed specifically for this new reality; sharding just won't cut it.' Their solution is to transfer some of the processing work to the database. 'This because the database is in a unique position to know which transactions may contend for the same data items, and how to schedule them with respect to one another for the best possible performance. The database can and should be smart.' They demonstrate how SpaceBase does this by simulating a 10,000-spaceship battle on different sets of hardware (code available here). Going from a dual-core system to a quad-core system at the same clock speed actually doubles performance without sharding."

Read more of this story at Slashdot.



After raid, Australian hacker fears possible arrest (NetworkWorld Security) SANS ISC SecNewsFeed(cached at February 27, 2013, 11:30 pm)

DoJ Admits Aaron Swartz's Prosecution Was Political (Slashdot) SANS ISC SecNewsFeed(cached at February 27, 2013, 11:30 pm)

CVE-2013-2276 (ffmpeg) (Natl. Vulnerability Database) SANS ISC SecNewsFeed(cached at February 27, 2013, 11:30 pm)

Google squishes login-bypass bug perfect for account hijackers (The Register) SANS ISC SecNewsFeed(cached at February 27, 2013, 11:30 pm)

Guest Diary: Dylan Johnson - There's value in them their logs!, (Wed, Feb 27th) SANS Internet Storm Center, InfoCON: green(cached at February 27, 2013, 11:30 pm)


[Guest Diary: Dylan Johnson BSc.CISSP] [Theres value in them their logs!]

Today we bring you a guest diary from Dylan Johnson where he shows us a really cool way to aggregate logs into one place, search, trend, analyze in realtime and graph.

Events in Logs tell a story and are invaluable as a data source. Logs can be used as a source to create complex instrumentation, aid with root cause analysis, and provide real time analysis, during a security incident for example and a plethora of other uses such as trend analysis and forecasting. One of the problems with logs is their non standard use of timestamps, so if you want to correlate across logs you need some pretty tasty regular expression skills. It would be great if your search terms dealt with a single time stamp format and could also query the intrinsic values in all of these logs, across multiple machines, in real-time and with trending information + time series data. Sounds like a big ask for free? Read on!

This diary slot is not large enough to go into any great detail, however I wanted to share a event management framework that concerns itself with shipping, normalisation, filtering, output, time series data and trending of data in log files, from here on referred to as events.

Below is the architecture:



Lets look at the architecture above as there a fair amount of independent moving parts.

Logstash is a stupendous Java application created by Jordan Sissel (see www.logstash.net) which takes data from multiple sources such as file, syslog, message queues, pipes etc and gives you the power to splice and dice, top and tail and mangle this data or event stream via filters (more on these later) and importantly gives each event a standard time stamp. Once you have filtered or normalised your data Logstash gives you plenty of output options for this data such as Elasticsearch, email, graphite and Nagios. So in a nutshell Logstash takes your event streams, does stuff to them and outputs them somewhere useful. This architecture utilises the Elasticsearch output filter (www.elasticsearch.org) an extremely fast, scalable database with Lucene (http://lucene.apache.org/core/) built in for good measure. You can query Elasticsearch via simple REST based calls. As you can see we use Kibana (www.kibana.org) as the query interface and its great as you will see later. There is also Graylog (www.graylog2.org) and one thing to note about Graylog is that is has alerting a feature currently missing in kibana.

Statsd is an aggregation service that listens for events from the Logstash Statsd (https://github.com/etsy/statsd/) output plug-in, counts the events up over time and emits them to graphite (http://graphite.wikidot.com/), a real time scalable time series data application.

One last tool to mention is GROK. GROK is utilised in Logstash filtering, its goal is to bring more semantics to regular expressions allowing expression of ideas rather than complex syntax. (http://code.google.com/p/semicomplete/wiki/GrokConcepts) There is a great tool to help with creating your GROK filters here (http://grokdebug.herokuapp.com/)

Here is a simple Logstash.conf file that reads in an Apache log from a file, parses all of the fields from each event in the log and outputs to Elasticsearch and Graphite. You can find more information on Logstash.net and there is a big community offering support on IRC Freenode.net #logstash

input {


file {


type = Apache


path = [/var/log/httpd/access_log]

}}

filter {


grok {


type = Apache


patterns_dir = /data/syslog_inbound/grok_pat


pattern = %{COMBINEDAPACHELOG}

}}

output {

elasticsearch {


bind_host = 0.0.0.0

}

statsd {


increment = Apache.Verbs.%{verb}

}}

As you can see the pattern %COMBINEDAPACHELOG is doing some pretty powerful stuff. Its breaking the log up into its constituent parts. This is really useful if you want to get trending metrics from Elasticsearch. For example, tell me what hosts are trending up and down for GETS or 404s etc.

To end on here are a few screen shots showing what you get from all of this effort.

Trending



Output to Graphite via Statsd



Base Line Stats



We have only just scratched the surface here! The framework detailed has limitless potential to solve many complex security event management problems. I hope this has given you an idea of what can be achieved with a bit of research and hard work.



Post suggestions or comments in the section below or send us any questions or comments in the contact form on https://isc.sans.edu/contact.html#contact-form

--

Adam Swanger, Web Developer (GWEB, GWAPT)

Internet Storm Center https://isc.sans.edu
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Syrienopposition söker militärt stöd SvD Utrikes(cached at February 27, 2013, 11:02 pm)

Den syriska oppositionen ska söka ”militärt stöd” vid den internationella konferens om konflikten som äger rum i Rom i morgon.
Slog personal i huvudet med pistol SvD Inrikes(cached at February 27, 2013, 11:02 pm)

En livsmedelsbutik i Malmö rånades på en mindre summa pengar av två pistolbeväpnade gärningsmän under kvällen.
Koncern lägger ner flera skolor SvD Inrikes(cached at February 27, 2013, 11:02 pm)

Minskat antal elever skördar offer bland skolorna.
Overcome Password Frustrations with “Take Control of Your Passwords” TidBITS(cached at February 27, 2013, 10:32 pm)

Instead of a big text writeup, we’re announcing Joe Kissell’s latest ebook, “Take Control of Your Passwords,” with a “Joe of Tech” comic from our friends Snaggy and Nitrozac, and a short intro video — it’s big fun!

 

Read the full article at TidBITS, the oldest continuously published technology publication on the Internet. To get a full-text RSS feed, help support our work and become a TidBITS member! Members also enjoy an ad-free version of our Web site, email delivery of individual articles, the ability to make long comments with live links, and discounts on Take Control orders and other Apple-related products.

Fackpamp gripen efter förskingring SvD Utrikes(cached at February 27, 2013, 10:32 pm)

Elba Esther Gordillo, en av de mäktigaste kvinnorna i Mexiko och ordförande för landets lärarförbund, anklagas för att ha förskingrat 200 miljoner dollar av fackförbundets tillgångar.
Hagel vill utöka militära kontakter SvD Utrikes(cached at February 27, 2013, 10:32 pm)

USA:s nye försvarsminister, 66-årige Chuck Hagel, svors in på sin nya post i försvarshögkvarteret Pentagon i dag.
How Paid Apps On Firefox OS Will Work Slashdotby Soulskill on business at January 1, 1970, 1:00 am (cached at February 27, 2013, 10:32 pm)

An anonymous reader writes "Mozilla has put up a blog post about how building a paid app will work for Firefox OS. The Firefox Marketplace will host web apps, and Mozilla is quick to point out that the apps won't lock you into Firefox OS. They will use the receipt protocol, which other devices can support. If they end up doing so, users could buy the app just once and run it anywhere. 'There is, of course, a chicken vs. egg problem here so Mozilla hopes to be the egg that helps prove out the decentralized receipt concept and iterate on the protocol. Mozilla invites other vendors to help us work on getting receipts right so that paid apps are as portable and "webby" as possible.' Mozilla has a JavaScript API for exposing device receipts, and a client-side library can then contact a verification service URL from the receipt." Somewhat related: a recent panel at Mobile World Congress consisted of representatives for Firefox OS, Ubuntu for Phones, and Sailfish OS. They spoke about the need for alternatives to Android and iOS, and how manufacturers and carriers actually seem eager to use these new operating systems to differentiate their products

Read more of this story at Slashdot.



Plans Unveiled For Full Scale Replica of the Titanic (Slashdot) SANS ISC SecNewsFeed(cached at February 27, 2013, 10:30 pm)