<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-409</id>
	<title>Nabble - Honeypots</title>
	<updated>2009-09-27T05:24:52Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Honeypots-f409.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Honeypots-f409.html" />
	<subtitle type="html">Discussions about tracking attackers by setting up decoy honeypots or entire honeynet networks. - comments provided by seclists.org</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-25634160</id>
	<title>nullcon Goa 2010 Call For Papers</title>
	<published>2009-09-27T05:24:52Z</published>
	<updated>2009-09-27T05:24:52Z</updated>
	<author>
		<name>nullcon nullcon</name>
	</author>
	<content type="html">Calling all greyhats, whitehats, blackhats, rainbowhats, nohats,
&lt;br&gt;underground, aboveground, in-the-sky, on-the-moon, Grannies, Grandpas,
&lt;br&gt;martians, Doodhwalas, Kaamwalis, Bais, Bhais, Chuck norris Fans,
&lt;br&gt;Mithun Da Fans, Himesh Reshamiya wannabees……..
&lt;br&gt;&lt;br&gt;Call For Paper is officially open for nullcon Goa 2010. It is time for
&lt;br&gt;you to polish your paper, stick up an abstract and send it across. A
&lt;br&gt;live demo/exploit/0day with the presentation might win you some extra
&lt;br&gt;brownies.
&lt;br&gt;&lt;br&gt;---------------
&lt;br&gt;WEBSITE
&lt;br&gt;---------------
&lt;br&gt;&lt;a href=&quot;http://nullcon.net&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nullcon.net&lt;/a&gt;&lt;br&gt;&lt;br&gt;---------------
&lt;br&gt;About null
&lt;br&gt;---------------
&lt;br&gt;null – The open security community (&lt;a href=&quot;http://null.co.in&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://null.co.in&lt;/a&gt;) , a non-profit
&lt;br&gt;initiative, is a community of security professionals who have passion
&lt;br&gt;for security research and contribute towards research and development,
&lt;br&gt;knowledge sharing in the field of computer security.
&lt;br&gt;&lt;br&gt;nullcon Goa 2010 is our First effort towards organizing an
&lt;br&gt;International Hacker Fest and is totally a community driven effort by
&lt;br&gt;the members of null community.
&lt;br&gt;&lt;br&gt;--------------
&lt;br&gt;TRACKS
&lt;br&gt;--------------
&lt;br&gt;The conference will run on the following two serial tracks:
&lt;br&gt;1) Gurukul Track – 1 hr sessions
&lt;br&gt;2) Turbo Track – 10/15/20 min sessions
&lt;br&gt;&lt;br&gt;&lt;br&gt;Don’t have a full fledged 1 hr paper ??? Don’t be disheartened, we
&lt;br&gt;have the Turbo Track with 10-20 minute talks.
&lt;br&gt;If you have a neat hack/0day/idea/attack|malware analysis/Research in
&lt;br&gt;Progress, simply submit to the turbo track.
&lt;br&gt;&lt;br&gt;-------------
&lt;br&gt;TOPICS
&lt;br&gt;-------------
&lt;br&gt;Topic could be anything from Auto meter crooking, hacking cars to
&lt;br&gt;hacking mobile networks, anything that would make people standup and
&lt;br&gt;take notice.
&lt;br&gt;&lt;br&gt;A subset of topics we would be interested in (but not limited to):
&lt;br&gt;Application security, Web security, social engineering, Mobile
&lt;br&gt;Networks GSM/CDMA/3G, Bluetooth, OS/Kernel, Virtualization, cloud
&lt;br&gt;security/hacking, protocol vulnerabilities, hardware security, cyber
&lt;br&gt;warfare, cyber forensics, cryptography, spam, malware, L2-L4 hacking.
&lt;br&gt;&lt;br&gt;-----------------------
&lt;br&gt;SUBMISSIONS
&lt;br&gt;-----------------------
&lt;br&gt;Initially an abstract will be required with your details.
&lt;br&gt;Send an email to (cfp _at_ nullcon.net) in the following format:
&lt;br&gt;Subject should be: nullcon Goa 2010 CFP &amp;lt;Paper Title&amp;gt;
&lt;br&gt;&lt;br&gt;Track: [Gurukul / Turbo]
&lt;br&gt;Name:
&lt;br&gt;Handle:
&lt;br&gt;Nationality:
&lt;br&gt;Organization:
&lt;br&gt;Email:
&lt;br&gt;Contact no:
&lt;br&gt;Short Biography:
&lt;br&gt;Paper Title:
&lt;br&gt;Paper Abstract: (Max 6000 words)
&lt;br&gt;Have You Presented this paper at any another conference? If Yes, Where?
&lt;br&gt;Why do you think your work is innovative or different?
&lt;br&gt;&lt;br&gt;NOTE: It is mandatory for the participants, whose papers are selected,
&lt;br&gt;to send us the final presentation (ppt, odp format) and the full paper
&lt;br&gt;(doc, pdf format) containing the detailed explanation of presentation,
&lt;br&gt;within the stipulated time (as mentioned below). The abstract should
&lt;br&gt;clearly define your findings in detail with factual information. Just
&lt;br&gt;stating that ‘it works’ may not help us understand your work
&lt;br&gt;correctly.
&lt;br&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;IMPORTANT DEADLINES
&lt;br&gt;--------------------------------------
&lt;br&gt;CFP Closes – 15th Dec 2009
&lt;br&gt;Selection Notification – 25th Dec 2009
&lt;br&gt;Submission of final Paper and presentation material – 5th Jan 2010.
&lt;br&gt;&lt;br&gt;-------------------------------------------------------------------------
&lt;br&gt;SPEAKER PRIVILEGES FOR GURUKUL TRACK
&lt;br&gt;-------------------------------------------------------------------------
&lt;br&gt;Free accommodation.
&lt;br&gt;Fixed amount of reimbursement for travel (TBD).
&lt;br&gt;Invitation to the post conference party.
&lt;br&gt;Free access to the conference.
&lt;br&gt;&lt;br&gt;---------------------------------------------------------------------
&lt;br&gt;SPEAKER PRIVILEGES FOR TURBO TRACK
&lt;br&gt;---------------------------------------------------------------------
&lt;br&gt;Free access to the conference.
&lt;br&gt;Invitation to the post conference party.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nullcon-Goa-2010-Call-For-Papers-tp25634160p25634160.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25606725</id>
	<title>Sebek issues with windows XP/Vista</title>
	<published>2009-09-24T22:24:54Z</published>
	<updated>2009-09-24T22:24:54Z</updated>
	<author>
		<name>dharm</name>
	</author>
	<content type="html">Hello ,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Did anybody tried running sebek on windows vista as a
&lt;br&gt;honeypot ? i am trying to install sebek on windows XP /Vista
&lt;br&gt;environment and getting DOB screen error. Any ideas would be
&lt;br&gt;appreciated .
&lt;br&gt;Thanks
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sebek-issues-with-windows-XP-Vista-tp25606725p25606725.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25236555</id>
	<title>Workshop on the Analysis of System Logs - Oct 14 - Call for Participation</title>
	<published>2009-08-31T23:59:28Z</published>
	<updated>2009-08-31T23:59:28Z</updated>
	<author>
		<name>Greg Bronevetsky</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Workshop on the Analysis of System Logs (WASL) 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.systemloganalysis.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.systemloganalysis.com&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Call for Participation
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;===============================
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;October 14, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Big Sky, MT
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(at SOSP)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;===============================
&lt;br&gt;&lt;br&gt;--------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;System logs contain a wide variety of information about system status 
&lt;br&gt;and health,
&lt;br&gt;including events from various applications, daemons and drivers, as well 
&lt;br&gt;as sampled
&lt;br&gt;information such as resource utilization statistics. As such, these logs 
&lt;br&gt;represent a
&lt;br&gt;rich source of information for the analysis and diagnosis of system 
&lt;br&gt;problems and
&lt;br&gt;prediction of future system events. However, their lack of organization 
&lt;br&gt;and the general
&lt;br&gt;lack of semantic consistency between information from various software 
&lt;br&gt;and hardware
&lt;br&gt;vendors means that most of this information content is wasted. Indeed, 
&lt;br&gt;today's
&lt;br&gt;most popular log analysis technique is to use regular expressions to 
&lt;br&gt;either detect
&lt;br&gt;events of interest or to filter the log so that a human operator can 
&lt;br&gt;examine it manually.
&lt;br&gt;Clearly, this captures only a fraction of the information available in 
&lt;br&gt;these logs and
&lt;br&gt;does not scale to the large systems common in business and 
&lt;br&gt;supercomputing environments.
&lt;br&gt;This workshop will focus on novel techniques for extracting 
&lt;br&gt;operationally useful
&lt;br&gt;information from existing logs and methods to improve the information 
&lt;br&gt;content of future
&lt;br&gt;logs.
&lt;br&gt;&lt;br&gt;Workshop Program
&lt;br&gt;&lt;br&gt;Session 1: Log Analysis Tools
&lt;br&gt;&amp;nbsp; &amp;nbsp; - &amp;quot;Extracting Message Types from BlueGene/L's Logs&amp;quot;, A. Makanju, A. 
&lt;br&gt;Zincir-Heywood, and E. Milios &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; - &amp;quot;Incremental Learning of System Log Formats&amp;quot;, K. Zhu, K. Fisher, 
&lt;br&gt;and D. Walker &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; - &amp;quot;Visual and Algorithmic Tooling for System Trace Analysis: A Case 
&lt;br&gt;Study&amp;quot;, W. De Pauw and S. Heisig &amp;nbsp;
&lt;br&gt;&lt;br&gt;Session 2: Analyzing System Logs
&lt;br&gt;&amp;nbsp; &amp;nbsp; - &amp;quot;Mining Dependency in Distributed Systems through Unstructured 
&lt;br&gt;Logs Analysis&amp;quot;, J. Lou, Q. Fu, Y. Wang, and J. Li &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; - &amp;quot;A Bayesian Network Approach to Modeling IT Service Availability 
&lt;br&gt;using System Logs&amp;quot;, R. Zhang, E. Cope, L. Huesler, and F. Cheng &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; - &amp;quot;Endpoint Identification Using System Logs&amp;quot;, S. Melvin &amp;nbsp;
&lt;br&gt;&lt;br&gt;Session 3: Group Discussion on Current State of the Art
&lt;br&gt;&amp;nbsp; &amp;nbsp; - Tips and tricks in current use.
&lt;br&gt;&amp;nbsp; &amp;nbsp; - Gaps and challenges in current techniques.
&lt;br&gt;&amp;nbsp; &amp;nbsp; - Vision and steps for the future.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Session 4: Panel on Future Research Agenda
&lt;br&gt;&amp;nbsp; &amp;nbsp; - What are the most difficult problems with logging, in the real world?
&lt;br&gt;&amp;nbsp; &amp;nbsp; - How to make academia-industry interactions more productive?
&lt;br&gt;&amp;nbsp; &amp;nbsp; - How to extract meaningful information from logs?
&lt;br&gt;&amp;nbsp; &amp;nbsp; - How to improve system management?
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;Workshop Chair:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Greg Bronevetsky (Lawrence Livermore National Laboratory)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25236555&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;greg@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Program Committee:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Jon Stearley, Sandia National Laboratory
&lt;br&gt;&amp;nbsp; &amp;nbsp; Bianca Schroeder, University of Toronto
&lt;br&gt;&amp;nbsp; &amp;nbsp; Sébastien Tricaud, INL
&lt;br&gt;&amp;nbsp; &amp;nbsp; Sapan Bhatia, Princeton University
&lt;br&gt;&amp;nbsp; &amp;nbsp; Risto Vaarandi, CCD CoE
&lt;br&gt;&amp;nbsp; &amp;nbsp; Jim Jansen, Penn State University
&lt;br&gt;&amp;nbsp; &amp;nbsp; Wei Xu, University of California, Berkeley
&lt;br&gt;&amp;nbsp; &amp;nbsp; Anton Chuvakin, Qualys
&lt;br&gt;&amp;nbsp; &amp;nbsp; Kara Nance, University of Alaska, Fairbanks
&lt;br&gt;&amp;nbsp; &amp;nbsp; Raffael Marty, PixlCloud
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Workshop-on-the-Analysis-of-System-Logs---Oct-14---Call-for-Participation-tp25236555p25236555.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24828047</id>
	<title>Re: Send strace output through syslog-ng</title>
	<published>2009-08-05T07:08:32Z</published>
	<updated>2009-08-05T07:08:32Z</updated>
	<author>
		<name>BB@umd</name>
	</author>
	<content type="html">Well I did not think about this, but it seems to be a great idea. Thanks a lot.
&lt;br&gt;&lt;br&gt;However, I decided to open a new port and to send syslog data through it so that it is really easy to administrate. It works great.
&lt;br&gt;&lt;br&gt;Thanks for your help,
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;BB@umd wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Good afternoon.
&lt;br&gt;&lt;br&gt;I have a honeypot which syslog-ng running. I configured it so that it can send all the log files to a remote web server. (So that mean I have already configured syslog-ng on this web server too) No matter with that, it works great.
&lt;br&gt;&lt;br&gt;Then, on my honeypot, I have a strace command attached to my ssh server. It gathers strace outputs in a strace.log file. Here is this command :
&lt;br&gt;&lt;i&gt;strace -f -q -p `cat /var/run/sshd.pid` -o /var/log/strace.log &amp;&lt;/i&gt;&lt;br&gt;&lt;br&gt;Now, I would like to send the strace output (/var/log/strace.log) to my server through syslog-ng. So, on my honeypot, I added the following in my syslog-ng.conf in the source section:
&lt;br&gt;file (&amp;quot;/var/log/strace.log&amp;quot;).
&lt;br&gt;&lt;br&gt;However, now, on the server side, I do not know how to configure syslog-ng in order to retrieve this strace output only. Is there a special filter for strace in syslog-ng ? (Usually, for example, I am using &amp;quot;filter { facility(auth);};&amp;quot; to filter auth.log : so is there something similar with strace ?)
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;BB
&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Send-strace-output-through-syslog-ng-tp24814871p24828047.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24828785</id>
	<title>Re: Send strace output through syslog-ng</title>
	<published>2009-08-05T05:52:44Z</published>
	<updated>2009-08-05T05:52:44Z</updated>
	<author>
		<name>Gergely Révay</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;First of all there is no filter for strace. My first idea for your
&lt;br&gt;problem was to open a new port on the server just for strace, but it's
&lt;br&gt;understandable if you don't want to do it. Also the idea of Chris
&lt;br&gt;sounds good as well if you don't use the facility field generally. But
&lt;br&gt;a third solution that I've found is the following:
&lt;br&gt;&lt;br&gt;You should create a separate log path for the strace output which
&lt;br&gt;should read the logs from the file and replace the PROGRAM field of
&lt;br&gt;the log message with the 'strace' string. That is why you need the
&lt;br&gt;separate logpath, to make sure that only the strace output gets the
&lt;br&gt;'strace' string. And then you can send these messages to your server
&lt;br&gt;where you can filter the logs by the PROGRAM field. For these you will
&lt;br&gt;need something like this in your config:
&lt;br&gt;&lt;br&gt;=Client=
&lt;br&gt;#
&lt;br&gt;# Sets the PROGRAM field to 'strace'
&lt;br&gt;#
&lt;br&gt;rewrite r_rewrite_set{set(&amp;quot;strace&amp;quot;, value(&amp;quot;PROGRAM&amp;quot;));};
&lt;br&gt;&lt;br&gt;#
&lt;br&gt;# Source to read from file
&lt;br&gt;#
&lt;br&gt;source s_strace {
&lt;br&gt;file (&amp;quot;/var/log/strace.log&amp;quot;);
&lt;br&gt;};
&lt;br&gt;&lt;br&gt;#
&lt;br&gt;#Destination to your server
&lt;br&gt;#
&lt;br&gt;destination d_tcp { tcp(&amp;quot;127.0.0.1&amp;quot; port(1999) );};
&lt;br&gt;&lt;br&gt;#
&lt;br&gt;# Logpath to read the file, set the
&lt;br&gt;# program name and send it to the server
&lt;br&gt;#
&lt;br&gt;log {
&lt;br&gt;source(s_strace);
&lt;br&gt;rewrite(r_rewrite_set);
&lt;br&gt;destination(d_tcp);
&lt;br&gt;};
&lt;br&gt;&lt;br&gt;= Server =
&lt;br&gt;#
&lt;br&gt;# Filter for the messages generated by strace
&lt;br&gt;#
&lt;br&gt;filter strace_filter{match(&amp;quot;strace&amp;quot; value(&amp;quot;PROGRAM&amp;quot;));};
&lt;br&gt;&lt;br&gt;#
&lt;br&gt;# Template to see the PROGRAM field
&lt;br&gt;#
&lt;br&gt;template t_filetemplate {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; template(&amp;quot;$ISODATE $HOST $PROGRAM $MSG\n&amp;quot;);
&lt;br&gt;template_escape(no); };
&lt;br&gt;&lt;br&gt;#
&lt;br&gt;# This one just opens a port
&lt;br&gt;#
&lt;br&gt;source s_net {
&lt;br&gt;tcp(ip(127.0.0.1) port(1999) max-connections(10));
&lt;br&gt;};
&lt;br&gt;&lt;br&gt;#
&lt;br&gt;# Destination to write messages to file
&lt;br&gt;#
&lt;br&gt;destination d_strace {file(&amp;quot;/var/log/test&amp;quot; template(t_filetemplate));};
&lt;br&gt;&lt;br&gt;#
&lt;br&gt;# Logpath for filtering the strace messages out
&lt;br&gt;#
&lt;br&gt;log {
&lt;br&gt;source(s_net);
&lt;br&gt;filter(strace_filter);
&lt;br&gt;destination(d_strace);
&lt;br&gt;};
&lt;br&gt;&lt;br&gt;I also would like to warn you to use tcp() as I did instead of
&lt;br&gt;syslog() because there might be a bug in sending the APP-NAME field
&lt;br&gt;through network. Also if you don't have it you should download the
&lt;br&gt;admin guide which is realy handy:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.balabit.hu/dl/guides/syslog-ng-v3.0-guide-admin-en.pdf&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.balabit.hu/dl/guides/syslog-ng-v3.0-guide-admin-en.pdf&lt;/a&gt;&lt;br&gt;&lt;br&gt;I hope I could help.
&lt;br&gt;&lt;br&gt;Good luck :)
&lt;br&gt;&lt;br&gt;Geri
&lt;br&gt;&lt;br&gt;2009/8/4 BB@umd &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=24828785&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;bbenard@...&lt;/a&gt;&amp;gt;:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Good afternoon.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I have a honeypot which syslog-ng running. I configured it so that it can
&lt;br&gt;&amp;gt; send all the log files to a remote web server. (So that mean I have already
&lt;br&gt;&amp;gt; configured syslog-ng on this web server too) No matter with that, it works
&lt;br&gt;&amp;gt; great.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Then, on my honeypot, I have a strace command attached to my ssh server. It
&lt;br&gt;&amp;gt; gathers strace outputs in a strace.log file. Here is this command :
&lt;br&gt;&amp;gt; strace -f -q -p `cat /var/run/sshd.pid` -o /var/log/strace.log &amp;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Now, I would like to send the strace output (/var/log/strace.log) to my
&lt;br&gt;&amp;gt; server through syslog-ng. So, on my honeypot, I added the following in my
&lt;br&gt;&amp;gt; syslog-ng.conf in the source section:
&lt;br&gt;&amp;gt; file (&amp;quot;/var/log/strace.log&amp;quot;).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; However, now, on the server side, I do not know how to configure syslog-ng
&lt;br&gt;&amp;gt; in order to retrieve this strace output only. Is there a special filter for
&lt;br&gt;&amp;gt; strace in syslog-ng ? (Usually, for example, I am using &amp;quot;filter {
&lt;br&gt;&amp;gt; facility(auth);};&amp;quot; to filter auth.log : so is there something similar with
&lt;br&gt;&amp;gt; strace ?)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; BB
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; View this message in context: &lt;a href=&quot;http://www.nabble.com/Send-strace-output-through-syslog-ng-tp24814871p24814871.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/Send-strace-output-through-syslog-ng-tp24814871p24814871.html&lt;/a&gt;&lt;br&gt;&amp;gt; Sent from the Honeypots mailing list archive at Nabble.com.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Send-strace-output-through-syslog-ng-tp24814871p24828785.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24818714</id>
	<title>Re: Send strace output through syslog-ng</title>
	<published>2009-08-04T17:33:20Z</published>
	<updated>2009-08-04T17:33:20Z</updated>
	<author>
		<name>Chris Brenton</name>
	</author>
	<content type="html">Hey man,
&lt;br&gt;&lt;br&gt;On Tue, 2009-08-04 at 12:38 -0700, BB@umd wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Then, on my honeypot, I have a strace command attached to my ssh server. It
&lt;br&gt;&amp;gt; gathers strace outputs in a strace.log file. Here is this command :
&lt;br&gt;&amp;gt; strace -f -q -p `cat /var/run/sshd.pid` -o /var/log/strace.log &amp;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Now, I would like to send the strace output (/var/log/strace.log) to my
&lt;br&gt;&amp;gt; server through syslog-ng.
&lt;br&gt;&lt;br&gt;What about something like:
&lt;br&gt;tail -f /var/log/strace.log | logger -p &amp;lt;facility&amp;gt; &amp;
&lt;br&gt;&lt;br&gt;&amp;gt; However, now, on the server side, I do not know how to configure syslog-ng
&lt;br&gt;&amp;gt; in order to retrieve this strace output only.
&lt;br&gt;&lt;br&gt;In the above command you need to specify an unused facility. Then on the
&lt;br&gt;server simply tell syslog-ng which file it should use for storing log
&lt;br&gt;entries with the above specified facility (this can be a new unique
&lt;br&gt;file).
&lt;br&gt;&lt;br&gt;You are suppose to use one of the &amp;quot;local use&amp;quot; facilities for stuff like
&lt;br&gt;this, but I run into conflicts far too often. Instead I like to use the
&lt;br&gt;facilities &amp;quot;news&amp;quot;, &amp;quot;uucp&amp;quot; or similar that I know will never get run on
&lt;br&gt;my network. Potential conflict solved. ;-)
&lt;br&gt;&lt;br&gt;HTH,
&lt;br&gt;C
&lt;br&gt;---
&lt;br&gt;www.chrisbrenton.org
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Send-strace-output-through-syslog-ng-tp24814871p24818714.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24814871</id>
	<title>Send strace output through syslog-ng</title>
	<published>2009-08-04T12:38:08Z</published>
	<updated>2009-08-04T12:38:08Z</updated>
	<author>
		<name>BB@umd</name>
	</author>
	<content type="html">Good afternoon.
&lt;br&gt;&lt;br&gt;I have a honeypot which syslog-ng running. I configured it so that it can send all the log files to a remote web server. (So that mean I have already configured syslog-ng on this web server too) No matter with that, it works great.
&lt;br&gt;&lt;br&gt;Then, on my honeypot, I have a strace command attached to my ssh server. It gathers strace outputs in a strace.log file. Here is this command :
&lt;br&gt;&lt;i&gt;strace -f -q -p `cat /var/run/sshd.pid` -o /var/log/strace.log &amp;&lt;/i&gt;&lt;br&gt;&lt;br&gt;Now, I would like to send the strace output (/var/log/strace.log) to my server through syslog-ng. So, on my honeypot, I added the following in my syslog-ng.conf in the source section:
&lt;br&gt;file (&amp;quot;/var/log/strace.log&amp;quot;).
&lt;br&gt;&lt;br&gt;However, now, on the server side, I do not know how to configure syslog-ng in order to retrieve this strace output only. Is there a special filter for strace in syslog-ng ? (Usually, for example, I am using &amp;quot;filter { facility(auth);};&amp;quot; to filter auth.log : so is there something similar with strace ?)
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;BB
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Send-strace-output-through-syslog-ng-tp24814871p24814871.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24603649</id>
	<title>Running Honeyd on interface IP</title>
	<published>2009-07-22T02:10:50Z</published>
	<updated>2009-07-22T02:10:50Z</updated>
	<author>
		<name>Evgeniy Arbatov</name>
	</author>
	<content type="html">Hello,
&lt;br&gt;&lt;br&gt;I have a question concerning the configuration of Honeyd IP address.
&lt;br&gt;&lt;br&gt;I want to make my honeypot visible by the IP address of host computer interface.
&lt;br&gt;I have the following setup, within the same physical host:
&lt;br&gt;&lt;br&gt;1.1.1.1 (interface IP)-&amp;gt; 2.2.2.2 (honeyd IP)
&lt;br&gt;&lt;br&gt;So if I ssh to the honeyd, I want to ssh to 1.1.1.1.
&lt;br&gt;&lt;br&gt;I guess this is something that can be done with iptables, for example like this:
&lt;br&gt;&lt;br&gt;iptables -A FORWARD -s 1.1.1.1 -p tcp --dport 22 -d 2.2.2.2 -j ACCEPT
&lt;br&gt;iptables -A INPUT -p tcp --sport 22 -j ACCEPT
&lt;br&gt;&lt;br&gt;I also add a route for 2.2.2.2 to be accessible from loopback:
&lt;br&gt;route add -host 2.2.2.2 lo
&lt;br&gt;&lt;br&gt;Then I enable IP forwarding in /etc/sysctl.conf:
&lt;br&gt;net.ipv4.ip_forward = 1
&lt;br&gt;&lt;br&gt;And in the configuration for Honeyd I say:
&lt;br&gt;add sshhost tcp port 22 &amp;quot;./ssh.sh&amp;quot;
&lt;br&gt;bind 2.2.2.2 sshhost
&lt;br&gt;&lt;br&gt;Finally, I run my Honeyd like this, binding it to my Loopback:
&lt;br&gt;honeyd -d -l /tmp/honeypot/packet.log -f smtp.conf -i lo
&lt;br&gt;&lt;br&gt;But I am still unable to access port 22 of my honeypot. What can be missing?
&lt;br&gt;&lt;br&gt;I am running honeyd-1.5b. This is what I get by running Honeyd in the
&lt;br&gt;debug mode:
&lt;br&gt;&lt;br&gt;honeyd[3388]: listening on lo: ip
&lt;br&gt;honeyd[3388]: Demoting process privileges to uid 99, gid 99
&lt;br&gt;honeyd[3388]: rrdtool returning errors - restarting.
&lt;br&gt;honeyd[3388]: Respawing rrdtool too quickly
&lt;br&gt;honeyd[3388]: Connection request: tcp (1.1.1.1:40805 - 1.1.1.1:22)
&lt;br&gt;honeyd[3388]: Killing attempted connection: tcp (1.1.1.1:22 - 1.1.1.1:40805)
&lt;br&gt;honeyd[3388]: Connection dropped by reset: tcp (1.1.1.1:40805 - 1.1.1.1:22)
&lt;br&gt;honeyd[3388]: rrdtool returning errors - restarting.
&lt;br&gt;honeyd[3388]: Respawing rrdtool too quickly
&lt;br&gt;&lt;br&gt;Thank you!
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Evgeniy
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Running-Honeyd-on-interface-IP-tp24603649p24603649.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24295364</id>
	<title>Extended deadline: Monday, July 6th. Workshop on the Analysis of System Logs (WASL) 2009</title>
	<published>2009-07-01T11:40:34Z</published>
	<updated>2009-07-01T11:40:34Z</updated>
	<author>
		<name>Greg Bronevetsky</name>
	</author>
	<content type="html">Due to multiple requests, the paper submission deadline for the Workshop 
&lt;br&gt;on the
&lt;br&gt;Analysis of System Logs has been moved to Monday, July 6th.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Workshop on the Analysis of System Logs (WASL) 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.systemloganalysis.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.systemloganalysis.com&lt;/a&gt;&amp;nbsp;Call for Papers
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;===============================
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;October 14, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Big Sky, MT
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(at SOSP)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;===============================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FULL PAPER SUBMISSION: Monday, July 6th, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AUTHOR NOTIFICATION: Monday, August 3rd, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FINAL PAPERS DUE: Monday, September 14, 2009
&lt;br&gt;--------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;System logs contain a wide variety of information about system status 
&lt;br&gt;and health,
&lt;br&gt;including events from various applications, daemons and drivers, as well 
&lt;br&gt;as sampled
&lt;br&gt;information such as resource utilization statistics. As such, these logs 
&lt;br&gt;represent a
&lt;br&gt;rich source of information for the analysis and diagnosis of system 
&lt;br&gt;problems and
&lt;br&gt;prediction of future system events. However, their lack of organization 
&lt;br&gt;and the general
&lt;br&gt;lack of semantic consistency between information from various software 
&lt;br&gt;and hardware
&lt;br&gt;vendors means that most of this information content is wasted. Indeed, 
&lt;br&gt;today's
&lt;br&gt;most popular log analysis technique is to use regular expressions to 
&lt;br&gt;either detect
&lt;br&gt;events of interest or to filter the log so that a human operator can 
&lt;br&gt;examine it manually.
&lt;br&gt;Clearly, this captures only a fraction of the information available in 
&lt;br&gt;these logs and
&lt;br&gt;does not scale to the large systems common in business and 
&lt;br&gt;supercomputing environments.
&lt;br&gt;&lt;br&gt;This workshop will focus on novel techniques for extracting 
&lt;br&gt;operationally useful
&lt;br&gt;information from existing logs and methods to improve the information 
&lt;br&gt;content of future
&lt;br&gt;logs. Topics include but are not limited to:
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Reports on publicly available sources of sample log data.
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log anonymization
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log feature detection and extraction
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Prediction of malfunction or misuse based on log data
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Statistical techniques to characterize log data
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Applications of Natural-Language Processing (NLP) to logs
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Scalable log compression
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log comparison techniques
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Methods to enhance astandardize log semantics
&lt;br&gt;&amp;nbsp; &amp;nbsp; o System diagnostic techniques
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log visualization
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Analysis of services (problem ticket) logs
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Applications of log analysis to system administration
&lt;br&gt;&lt;br&gt;Papers limited to 6 2-column pages using &amp;gt;=10pt font.
&lt;br&gt;&lt;br&gt;Workshop Chair:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Greg Bronevetsky (Lawrence Livermore National Laboratory)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=24295364&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;greg@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Program Committee:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Jon Stearley, Sandia National Laboratory
&lt;br&gt;&amp;nbsp; &amp;nbsp; Bianca Schroeder, University of Toronto
&lt;br&gt;&amp;nbsp; &amp;nbsp; Sébastien Tricaud, INL
&lt;br&gt;&amp;nbsp; &amp;nbsp; Sapan Bhatia, Princeton University
&lt;br&gt;&amp;nbsp; &amp;nbsp; Risto Vaarandi, CCD CoE
&lt;br&gt;&amp;nbsp; &amp;nbsp; Jim Jansen, Penn State University
&lt;br&gt;&amp;nbsp; &amp;nbsp; Wei Xu, University of California, Berkeley
&lt;br&gt;&amp;nbsp; &amp;nbsp; Anton Chuvakin, Qualys
&lt;br&gt;&amp;nbsp; &amp;nbsp; Hugh Njemanze, ArcSight
&lt;br&gt;&amp;nbsp; &amp;nbsp; Kara Nance, University of Alaska, Fairbanks
&lt;br&gt;&amp;nbsp; &amp;nbsp; Raffael Marty, PixlCloud
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Extended-deadline%3A-Monday%2C-July-6th.-Workshop-on-the-Analysis-of-System-Logs-%28WASL%29-2009-tp24295364p24295364.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24060122</id>
	<title>Workshop on the Analysis of System Logs (WASL) 2009</title>
	<published>2009-06-16T08:42:33Z</published>
	<updated>2009-06-16T08:42:33Z</updated>
	<author>
		<name>Greg Bronevetsky</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Workshop on the Analysis of System Logs (WASL) 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.systemloganalysis.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.systemloganalysis.com&lt;/a&gt;&amp;nbsp;Call for Papers
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;===============================
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;October 14, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Big Sky, MT
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(at SOSP)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;===============================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FULL PAPER SUBMISSION: Monday, June 29th, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AUTHOR NOTIFICATION: Monday, July 27, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FINAL PAPERS DUE: Monday, September 14, 2009
&lt;br&gt;--------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;System logs contain a wide variety of information about system status 
&lt;br&gt;and health,
&lt;br&gt;including events from various applications, daemons and drivers, as well 
&lt;br&gt;as sampled
&lt;br&gt;information such as resource utilization statistics. As such, these logs 
&lt;br&gt;represent a
&lt;br&gt;rich source of information for the analysis and diagnosis of system 
&lt;br&gt;problems and
&lt;br&gt;prediction of future system events. However, their lack of organization 
&lt;br&gt;and the general
&lt;br&gt;lack of semantic consistency between information from various software 
&lt;br&gt;and hardware
&lt;br&gt;vendors means that most of this information content is wasted. Indeed, 
&lt;br&gt;today's
&lt;br&gt;most popular log analysis technique is to use regular expressions to 
&lt;br&gt;either detect
&lt;br&gt;events of interest or to filter the log so that a human operator can 
&lt;br&gt;examine it manually.
&lt;br&gt;Clearly, this captures only a fraction of the information available in 
&lt;br&gt;these logs and
&lt;br&gt;does not scale to the large systems common in business and 
&lt;br&gt;supercomputing environments.
&lt;br&gt;&lt;br&gt;This workshop will focus on novel techniques for extracting 
&lt;br&gt;operationally useful
&lt;br&gt;information from existing logs and methods to improve the information 
&lt;br&gt;content of future
&lt;br&gt;logs. Topics include but are not limited to:
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Reports on publicly available sources of sample log data.
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log anonymization
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log feature detection and extraction
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Prediction of malfunction or misuse based on log data
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Statistical techniques to characterize log data
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Applications of Natural-Language Processing (NLP) to logs
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Scalable log compression
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log comparison techniques
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Methods to enhance astandardize log semantics
&lt;br&gt;&amp;nbsp; &amp;nbsp; o System diagnostic techniques
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log visualization
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Analysis of services (problem ticket) logs
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Applications of log analysis to system administration
&lt;br&gt;&lt;br&gt;Papers limited to 6 2-column pages using &amp;gt;=10pt font.
&lt;br&gt;&lt;br&gt;Workshop Chair:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Greg Bronevetsky (Lawrence Livermore National Laboratory)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=24060122&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;greg@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Program Committee:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Jon Stearley, Sandia National Laboratory
&lt;br&gt;&amp;nbsp; &amp;nbsp; Bianca Schroeder, University of Toronto
&lt;br&gt;&amp;nbsp; &amp;nbsp; Sébastien Tricaud, INL
&lt;br&gt;&amp;nbsp; &amp;nbsp; Sapan Bhatia, Princeton University
&lt;br&gt;&amp;nbsp; &amp;nbsp; Risto Vaarandi, CCD CoE
&lt;br&gt;&amp;nbsp; &amp;nbsp; Jim Jansen, Penn State University
&lt;br&gt;&amp;nbsp; &amp;nbsp; Wei Xu, University of California, Berkeley
&lt;br&gt;&amp;nbsp; &amp;nbsp; Anton Chuvakin, Qualys
&lt;br&gt;&amp;nbsp; &amp;nbsp; Hugh Njemanze, ArcSight
&lt;br&gt;&amp;nbsp; &amp;nbsp; Kara Nance, University of Alaska, Fairbanks
&lt;br&gt;&amp;nbsp; &amp;nbsp; Raffael Marty, PixlCloudWorkshop on the Analysis of System Logs 
&lt;br&gt;(WASL) 2009
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Workshop-on-the-Analysis-of-System-Logs-%28WASL%29-2009-tp24060122p24060122.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23721526</id>
	<title>Call for Participation - DIMVA 2009</title>
	<published>2009-05-26T03:59:20Z</published>
	<updated>2009-05-26T03:59:20Z</updated>
	<author>
		<name>Sebastian Schmerl</name>
	</author>
	<content type="html">&amp;nbsp; (We apologize if you receive multiple copies of this message.)
&lt;br&gt;----------------------------------------------------------------------
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; C A L L F O R P A R T I C I P A T I O N
&lt;br&gt;======================================================================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DIMVA 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Sixth International Conference on
&lt;br&gt;&amp;nbsp; &amp;nbsp; Detection of Intrusions and Malware &amp; Vulnerability Assessment
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Organized by GI SIG SIDAR
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Como, Italy
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;July 9-10, 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.dimva.org/dimva2009&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dimva.org/dimva2009&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23721526&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;info@...&lt;/a&gt;
&lt;br&gt;======================================================================
&lt;br&gt;&lt;br&gt;The annual &amp;nbsp;DIMVA conference serves &amp;nbsp;as a premier forum &amp;nbsp;for advancing
&lt;br&gt;the state &amp;nbsp;of the art &amp;nbsp;in intrusion detection, malware &amp;nbsp;detection, and
&lt;br&gt;vulnerability &amp;nbsp; assessment. &amp;nbsp; &amp;nbsp;Each &amp;nbsp; year &amp;nbsp; DIMVA &amp;nbsp; brings &amp;nbsp; together
&lt;br&gt;international &amp;nbsp;experts &amp;nbsp;from &amp;nbsp;academia, &amp;nbsp;industry &amp;nbsp;and &amp;nbsp;government &amp;nbsp;to
&lt;br&gt;present and discuss novel research &amp;nbsp;in these areas. DIMVA is organized
&lt;br&gt;by &amp;nbsp;the special &amp;nbsp;interest &amp;nbsp;group Security &amp;nbsp;- &amp;nbsp;Intrusion Detection &amp;nbsp;and
&lt;br&gt;Response &amp;nbsp;(SIDAR) of &amp;nbsp;the &amp;nbsp;German &amp;nbsp;Informatics &amp;nbsp;Society (GI) and takes
&lt;br&gt;place 9/10-07-2009 in Como, Italy.
&lt;br&gt;&lt;br&gt;This year's program features a single technical track with 13 papers
&lt;br&gt;DIMVA 2009 will also feature two invited talks by renowned experts:
&lt;br&gt;&lt;br&gt;* Henry Stern, Ironport / Cisco:
&lt;br&gt;&amp;nbsp; A New Era in Security Collaboration: Turning the Tables on Botnets
&lt;br&gt;&lt;br&gt;* Richard Kemmerer, University of California Santa Barbara
&lt;br&gt;&amp;nbsp; How to Steal a Botnet and What Can Happen When You Do
&lt;br&gt;&lt;br&gt;The conference program will be complemented by
&lt;br&gt;&lt;br&gt;* a Rump Session: a series of short and entertaining talks where
&lt;br&gt;&amp;nbsp; attendees can present recent research results, work in progress,
&lt;br&gt;&amp;nbsp; or other topics of interest to the community.
&lt;br&gt;&lt;br&gt;&amp;nbsp; Please contact the Rump Session Chair, Sven Dietrich, at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23721526&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;rump-chair@...&lt;/a&gt; for submission questions.
&lt;br&gt;&lt;br&gt;* CIPHER 5: a &amp;quot;Capture The Flag&amp;quot;-style contest in IT security for
&lt;br&gt;&amp;nbsp; teams of students from universities around the world. CIPHER is
&lt;br&gt;&amp;nbsp; co-arranged by the Special Interest Group SIDAR (Security - Intrusion
&lt;br&gt;&amp;nbsp; Detection and Response) of the German Informatics Society (GI).
&lt;br&gt;&amp;nbsp; (More information on &lt;a href=&quot;http://www.cipher-ctf.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cipher-ctf.org&lt;/a&gt;)
&lt;br&gt;&lt;br&gt;Registration and Travel
&lt;br&gt;=======================
&lt;br&gt;&lt;br&gt;The &amp;nbsp;DIMVA &amp;nbsp;2009 &amp;nbsp;conference &amp;nbsp;will &amp;nbsp; be &amp;nbsp;held &amp;nbsp;in &amp;nbsp;Como (Italy). &amp;nbsp; The
&lt;br&gt;registration &amp;nbsp;is &amp;nbsp;now &amp;nbsp;open. &amp;nbsp;Please &amp;nbsp;check &amp;nbsp;the &amp;nbsp;DIMVA &amp;nbsp;web &amp;nbsp;site for
&lt;br&gt;information on the rates, registration, travel and accommodation:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; !!!Early Bird Rates available now!!!
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.dimva.org/dimva2009&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.dimva.org/dimva2009&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Conference Program (preliminary)
&lt;br&gt;================================
&lt;br&gt;&lt;br&gt;Thursday, July 9th
&lt;br&gt;------------------
&lt;br&gt;&lt;br&gt;Welcome Opening Remarks
&lt;br&gt;&lt;br&gt;Session 1: Malware and SPAM
&lt;br&gt;&lt;br&gt;&amp;nbsp; A Case Study on Asprox Infection Dynamics
&lt;br&gt;&lt;br&gt;&amp;nbsp; How good are malware detectors at remediating infected systems?
&lt;br&gt;&lt;br&gt;&amp;nbsp; Towards Proactive Spam Filtering
&lt;br&gt;&lt;br&gt;&lt;br&gt;Session 2: Emulation-based Detection
&lt;br&gt;&lt;br&gt;&amp;nbsp; Shepherding Loadable Kernel Module through On-demand
&lt;br&gt;&amp;nbsp; Emulation
&lt;br&gt;&lt;br&gt;&amp;nbsp; Yataglass: Network-level Code Emulation for Analyzing
&lt;br&gt;&amp;nbsp; Memory-scanning Attacks
&lt;br&gt;&lt;br&gt;&amp;nbsp; Defending Browsers against Drive-by Downloads: Mitigating
&lt;br&gt;&amp;nbsp; Heap-spraying Code Injection Attacks
&lt;br&gt;&lt;br&gt;Keynote
&lt;br&gt;&lt;br&gt;&amp;nbsp; How to Steal a Botnet and What Can Happen When You Do
&lt;br&gt;&amp;nbsp; &amp;nbsp; Richard Kemmerer, University of California Santa Barbara
&lt;br&gt;&lt;br&gt;Session 3: Software Diversity
&lt;br&gt;&lt;br&gt;&amp;nbsp; Polymorphing Software by Randomizing Data Structure Layout
&lt;br&gt;&lt;br&gt;&amp;nbsp; On the Effectiveness of Software Diversity: A Systematic
&lt;br&gt;&amp;nbsp; Study on Real-World Vulnerabilities
&lt;br&gt;&lt;br&gt;SIG SIDAR Open Meeting
&lt;br&gt;&lt;br&gt;Friday, July 10th
&lt;br&gt;-----------------
&lt;br&gt;&lt;br&gt;Keynote
&lt;br&gt;&lt;br&gt;&amp;nbsp; A New Era in Security Collaboration: Turning the Tables on
&lt;br&gt;&amp;nbsp; Botnets
&lt;br&gt;&amp;nbsp; &amp;nbsp; Henry Stern, Ironport / Cisco
&lt;br&gt;&lt;br&gt;Session 4: Harnessing Context
&lt;br&gt;&lt;br&gt;&amp;nbsp; Using Contextual Information for IDS Alarm Classification
&lt;br&gt;&lt;br&gt;&amp;nbsp; Browser Fingerprinting from Coarse Traffic Summaries:
&lt;br&gt;&amp;nbsp; Techniques and Implications
&lt;br&gt;&lt;br&gt;&amp;nbsp; A Service Dependency Modeling Framework for Policy-based
&lt;br&gt;&amp;nbsp; Response Enforcement
&lt;br&gt;&lt;br&gt;Rump Session
&lt;br&gt;&lt;br&gt;Session 5: Anomaly Detection
&lt;br&gt;&lt;br&gt;&amp;nbsp; Learning SQL for Database Intrusion Detection using
&lt;br&gt;&amp;nbsp; Context-Sensitive Modelling
&lt;br&gt;&lt;br&gt;&amp;nbsp; Selecting and Improving System Call Models for Anomaly
&lt;br&gt;&amp;nbsp; Detection
&lt;br&gt;&lt;br&gt;CIPHER 5 Capture the Flag
&lt;br&gt;&lt;br&gt;Farewell - Concluding Remarks
&lt;br&gt;&lt;br&gt;&lt;br&gt;Corporate Sponsors
&lt;br&gt;==================
&lt;br&gt;We &amp;nbsp;solicit &amp;nbsp;interested &amp;nbsp;organizations &amp;nbsp;to serve as sponsors for DIMVA
&lt;br&gt;2009, particularly in sponsorship of student travel and other expenses
&lt;br&gt;for &amp;nbsp;DIMVA. Please &amp;nbsp;contact &amp;nbsp;the &amp;nbsp;Sponsorship &amp;nbsp;Chair &amp;nbsp;for &amp;nbsp;information
&lt;br&gt;regarding corporate sponsorship of DIMVA 2009.
&lt;br&gt;&lt;br&gt;Organizing Committee
&lt;br&gt;====================
&lt;br&gt;&amp;nbsp;General Chair: Danilo M. Bruschi,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Università degli Studi di Milano,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Italy (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23721526&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;info@...&lt;/a&gt;)
&lt;br&gt;&amp;nbsp;Program Chair: Ulrich Flegel, SAP Research CEC Karlsruhe,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Germany (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23721526&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pc-chair@...&lt;/a&gt;)
&lt;br&gt;&amp;nbsp;Rump Session Chair: Sven Dietrich,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Stevens Institute of Technology,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; U.S.A. (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23721526&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;rump-chair@...&lt;/a&gt;)
&lt;br&gt;&amp;nbsp;Sponsorship Chair: Thorsten Holz, University of Mannheim,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Germany (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23721526&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sponsor-chair@...&lt;/a&gt;)
&lt;br&gt;&amp;nbsp;Publicity Chair: Sebastian Schmerl,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Technical University of Cottbus,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Germany (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23721526&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;publicity-chair@...&lt;/a&gt;)
&lt;br&gt;&lt;br&gt;Program Committee
&lt;br&gt;=================
&lt;br&gt;Thomas Biege, Novell, Germany
&lt;br&gt;Gunter Bitz, SAP AG, Germany
&lt;br&gt;Herbert Bos, Vrije Universiteit Amsterdam, Netherlands
&lt;br&gt;Danilo Bruschi, Università degli Studi di Milano, Italy
&lt;br&gt;Roland Büschkes, RWE, Germany
&lt;br&gt;Marc Dacier, Symantec Research, France
&lt;br&gt;Hervé Debar, France Télécom, France
&lt;br&gt;Sven Dietrich, Stevens Institute of Technology, U.S.A.
&lt;br&gt;Toralv Dirro, McAfee, Germany
&lt;br&gt;Thomas Dullien, Zynamics, Germany
&lt;br&gt;Ulrich Flegel, SAP Research, Germany
&lt;br&gt;Bernhard Hämmerli, Acris GmbH &amp; HSLU Lucerne, Switzerland
&lt;br&gt;Marc Heuse, Baseline Security, Germany
&lt;br&gt;Thorsten Holz, University of Mannheim, Germany
&lt;br&gt;Erland Jonsson, Chalmers University, Sweden
&lt;br&gt;Klaus Julisch, IBM Zurich Research Laboratory, Switzerland
&lt;br&gt;Engin Kirda, Eurecom, France
&lt;br&gt;Christian Kreibich, International Computer Science Institute,
&lt;br&gt;&amp;nbsp; U.S.A.
&lt;br&gt;Christopher Kruegel, University of California in Santa Barbara,
&lt;br&gt;&amp;nbsp; U.S.A
&lt;br&gt;Pavel Laskov, University of Tuebingen, Germany
&lt;br&gt;Wenke Lee, Georgia Institute of Technology, U.S.A.
&lt;br&gt;Javier Lopez, University of Malaga, Spain
&lt;br&gt;John McHugh, University of North Carolina and Dalhousie
&lt;br&gt;&amp;nbsp; University Halifax, Canada
&lt;br&gt;Michael Meier, Technical University of Dortmund, Germany
&lt;br&gt;George Mohay, Queensland University of Technology, Australia
&lt;br&gt;Martin Rehák, Czech Technical University, Czech
&lt;br&gt;Konrad Rieck, Technical University of Berlin, Germany
&lt;br&gt;Sebastian Schmerl, Technical University of Cottbus, Germany
&lt;br&gt;Robin Sommer, ICSI/LBNL, U.S.A.
&lt;br&gt;Salvatore Stolfo, Columbia University, U.S.A
&lt;br&gt;Peter Szor, Symantec, U.S.A.
&lt;br&gt;Bernhard Thurm, SAP Research, Germany
&lt;br&gt;Al Valdes, SRI International, U.S.A.
&lt;br&gt;&lt;br&gt;Steering Committee
&lt;br&gt;==================
&lt;br&gt;&amp;nbsp;Chairs:
&lt;br&gt;&amp;nbsp;* Ulrich Flegel, SAP Research CEC Karlsruhe
&lt;br&gt;&amp;nbsp;* Michael Meier, Technical University of Dortmund
&lt;br&gt;&lt;br&gt;Members:
&lt;br&gt;&amp;nbsp;* Roland Büschkes, RWE
&lt;br&gt;&amp;nbsp;* Hervé Debar, France Telecom R&amp;D
&lt;br&gt;&amp;nbsp;* Bernhard Hämmerli, Acris GmbH, HSLU
&lt;br&gt;&amp;nbsp;* Marc Heuse, Baseline Security Consulting
&lt;br&gt;&amp;nbsp;* Klaus Julisch, IBM Zurich Research Lab
&lt;br&gt;&amp;nbsp;* Christopher Kruegel, UC Santa Barbara
&lt;br&gt;&amp;nbsp;* Pavel Laskov, University of Tuebingen
&lt;br&gt;&amp;nbsp;* Robin Sommer, ICSI/LBNL
&lt;br&gt;&amp;nbsp;* Diego Zamboni, IBM Zurich Research Lab
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;_____________________________________________________________________
&lt;br&gt;Sebastian Schmerl &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Tel: +49 (0) 355 69 20 29
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23721526&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sbs@...&lt;/a&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Fax: +49 (0) 355 69 21 27
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;BTU Cottbus
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Computer Networks and Communication System
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; P.O.Box 10 13 44, 03013 Cottbus, Germany
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www-rnks.informatik.tu-cottbus.de&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www-rnks.informatik.tu-cottbus.de&lt;/a&gt;&lt;br&gt;_____________________________________________________________________
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (9K) &lt;a href=&quot;http://old.nabble.com/attachment/23721526/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Call-for-Participation---DIMVA-2009-tp23721526p23721526.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23721506</id>
	<title>SETOP 2009 - Call for Papers, Deadline June 1st</title>
	<published>2009-05-26T03:07:10Z</published>
	<updated>2009-05-26T03:07:10Z</updated>
	<author>
		<name>Yves Roudier-2</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[Apologies for multiple copies of this announcement]
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CALL FOR PAPERS
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;	 &amp;nbsp; &amp;nbsp; &amp;nbsp;SETOP 2009 
&lt;br&gt;&amp;nbsp; Second International Workshop on Autonomous and Spontaneous Security
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Co-located with ESORICS 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;September 24-25, 2009, Saint Malo, Britany, France.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://conferences.telecom-bretagne.eu/setop-2009&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conferences.telecom-bretagne.eu/setop-2009&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;With the need for evolution, if not revolution, of current network
&lt;br&gt;architectures and the Internet, autonomous and spontaneous management
&lt;br&gt;will be a key feature of future networks and information systems. In
&lt;br&gt;this context, security is an essential property that must be thought
&lt;br&gt;at the early stage of conception of these systems and designed to be
&lt;br&gt;also autonomous and spontaneous.
&lt;br&gt;&lt;br&gt;Future networks and systems must be able to automatically configure
&lt;br&gt;themselves with respect to their security policies. The security policy
&lt;br&gt;specification must be dynamic and adapt itself to the changing
&lt;br&gt;environment. Those networks and systems must be able to interoperate
&lt;br&gt;securely when their respective security policies are heterogeneous and
&lt;br&gt;possibly conflicting. They must be able to autonomously evaluate the
&lt;br&gt;impact of an intrusion in order to spontaneously select the appropriate
&lt;br&gt;and relevant response when a given intrusion is detected.
&lt;br&gt;&lt;br&gt;Autonomous and spontaneous security is a major requirement of future
&lt;br&gt;networks and systems. Of course, it is a key issue to address in
&lt;br&gt;different wireless and mobile technologies available today such as
&lt;br&gt;RFID, Wifi, Wimax, 3G, etc. Other technologies such as ad hoc or
&lt;br&gt;sensor networks are also very interesting for new type of services,
&lt;br&gt;and security in these networks needs to be managed in an autonomous
&lt;br&gt;and spontaneous way.
&lt;br&gt;&lt;br&gt;The SETOP Workshop seeks submissions that present research results
&lt;br&gt;on all aspects related to spontaneous and autonomous security.
&lt;br&gt;Submissions by PhD students are encouraged. Topics of interest
&lt;br&gt;include, but are not limited to the following:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; * Security policy deployment
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Self evaluation of risk and impact
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Distributed intrusion detection
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Autonomous and spontaneous response
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Trust establishment
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Security in ad hoc networks
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Security in sensor/RFID networks
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Security of Next Generation Network
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Security of Service Oriented Architecture
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Security of opportunistic Networks
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Privacy in self-organized networks
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Secure localization
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Secure context aware computing
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Secure interoperability and negotiation
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Secure routing
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Identity management
&lt;br&gt;&lt;br&gt;Submission guidelines
&lt;br&gt;&lt;br&gt;Submissions must be in English. Maximum length for submissions is
&lt;br&gt;15 pages in LNCS style, including figures, bibliography and
&lt;br&gt;appendices. The SETOP papers will be published after the conference
&lt;br&gt;in Springer Verlag's Lecture Notes in Computer Science series in
&lt;br&gt;order to give the authors an opportunity to revise their papers upon
&lt;br&gt;presentation at the meeting in the light of the feedback received
&lt;br&gt;from the audience. A selection of the best papers will be invited
&lt;br&gt;to submit an extended version of their paper for publication in an
&lt;br&gt;international journal.
&lt;br&gt;&lt;br&gt;Participation
&lt;br&gt;&lt;br&gt;Authors of accepted papers are required to ensure that at least one
&lt;br&gt;will be present at the symposium. Papers that do not adhere to this
&lt;br&gt;policy will be removed from the LNCS post-proceedings.
&lt;br&gt;&lt;br&gt;Important dates:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; * Submission deadline: June 1st, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Acceptance Notification: July 7th, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Camera ready: August 15th, 2009
&lt;br&gt;&lt;br&gt;Program Committee Chairs:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; * Nora Cuppens-Boulahia (TELECOM Bretagne, Rennes)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Yves Roudier (EURECOM, Sophia-Antipolis)
&lt;br&gt;&lt;br&gt;Organization Chair:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; * Frédéric Cuppens (TELECOM Bretagne, Rennes)
&lt;br&gt;&lt;br&gt;Program Committee (to be completed):
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; * Michel Barbeau (Carleton University, Ottawa)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Christophe Bidan (Supélec, Rennes)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Levente Buttyan (Budapest University of Technology and
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Economics, Budapest)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Claude Castelluccia (INRIA, Sophia-Antipolis)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Ana Cavalli (TELECOM SudParis, Evry)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Hakima Chaouchi (TELECOM SudParis, Evry)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Claude Chaudet (TELECOM ParisTech, Paris)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Yves Correc (DGA/CELAR, Bruz)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Frédéric Cuppens (TELECOM Bretagne, Rennes)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Hervé Debar (France Télécom R&amp;D, Caen)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Alban Gabillon (UPF, université de la Polynésie Française)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Joaquin Garcia-Alfaro (Carleton University, Ottawa)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Loukas Lazos (University of Arizona, Tucson)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Jean Leneutre (TELECOM ParisTech, Paris)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Maryline Maknavicius (TELECOM SudParis, Evry)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Refik Molva (EURECOM, Sophia-Antipolis)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Radha Poovendran (University of Washington, Seattle)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Juan Carlos Ruiz (UPV, Valencia)
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Thierry Sans (Carnegie Mellon, Doha)
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SETOP-2009---Call-for-Papers%2C-Deadline-June-1st-tp23721506p23721506.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23437962</id>
	<title>HoneyD Data Visualization Scripts</title>
	<published>2009-05-07T16:11:10Z</published>
	<updated>2009-05-07T16:11:10Z</updated>
	<author>
		<name>Joshua Gimer</name>
	</author>
	<content type="html">I have been doing a little work on updating my HoneyD data
&lt;br&gt;visualization scripts and the web interface to be a little bit more
&lt;br&gt;appealing.
&lt;br&gt;&lt;br&gt;More information at my blog:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://itsecops.blogspot.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://itsecops.blogspot.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Thx
&lt;br&gt;Joshua Gimer
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/HoneyD-Data-Visualization-Scripts-tp23437962p23437962.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23424746</id>
	<title>EUSecWest 2009 (May27/28) London Agenda and PacSec 2009 (Nov 4/5) Tokyo CFP deadline: June 1 2009</title>
	<published>2009-05-06T15:24:04Z</published>
	<updated>2009-05-06T15:24:04Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">EUSecWest 2009 Speakers
&lt;br&gt;&lt;br&gt;Efficient UAK Recovery attacks against DECT 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Ralf-Philipp Weinmann, &amp;nbsp;University of Luxembourg
&lt;br&gt;A year in the life of an Adobe Flash security researcher 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Peleus &amp;nbsp;Uhley, Adobe
&lt;br&gt;Pwning your grandmother's iPhone 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Charley Miller, Independent Security Evaluators
&lt;br&gt;Post exploitation techniques on OSX and Iphone and other TBA matters.
&lt;br&gt;&amp;nbsp; 	- Vincent Iozzo,Zynamics
&lt;br&gt;STOP!! Objective-C Run-TIME.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - nemo
&lt;br&gt;Exploiting Delphi/Pascal 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Ilja Van Sprundel, IOActive
&lt;br&gt;PCI bus based operating system attack and protections 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Christophe &amp;nbsp;Devine &amp; Guillaume Vissian, Thales
&lt;br&gt;Thoughts about Trusted Computing 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Joanna Rutkowska, Invisible Things Lab
&lt;br&gt;Nice NIC you got there... does it come with an SSH daemon? 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Arrigo Trulzi
&lt;br&gt;Evolving Microsoft Exploit Mitigations 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Tim Burrell &amp; Peter Beck, &amp;nbsp;Microsoft
&lt;br&gt;Malware Case Study: the ZeuS evolution 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Vicente Diaz, S21Sec
&lt;br&gt;Writing better XSS payloads 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Alex Kouzemtchenko, SIFT
&lt;br&gt;Exploiting Firefox Extensions 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -Roberto Suggi Liverani &amp; Nick Freeman, &amp;nbsp;Security-Assessment.com
&lt;br&gt;Stored Value Gift Cards, Magstripes Revisited 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Adrian Pastor, &amp;nbsp;Gnucitizen, Corsaire
&lt;br&gt;Advanced SQL Injection to operating system control 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Bernardo Damele Assumpcao Guimaraes, Portcullis
&lt;br&gt;Cloning Mifare Classic 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Nicolas Courtois, University of London
&lt;br&gt;Rootkits on Windows Mobile/Embedded 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Petr Matousek, Coseinc
&lt;br&gt;&lt;br&gt;&lt;br&gt;PacSec 2009 &amp;nbsp;CALL FOR PAPERS
&lt;br&gt;&lt;br&gt;World Security Pros To Converge on Japan
&lt;br&gt;&lt;br&gt;TOKYO, Japan -- To address the increasing importance of information &amp;nbsp;
&lt;br&gt;security in Japan, the best known figures in the international &amp;nbsp;
&lt;br&gt;security industry will get together with leading Japanese researchers &amp;nbsp;
&lt;br&gt;to share best practices and technology. The most significant new &amp;nbsp;
&lt;br&gt;discoveries about computer network hack attacks will be presented at &amp;nbsp;
&lt;br&gt;the seventh annual PacSec conference to be discussed.
&lt;br&gt;&lt;br&gt;The PacSec meeting provides an opportunity for foreign specialists to &amp;nbsp;
&lt;br&gt;be exposed to Japanese innovation and markets and collaborate on &amp;nbsp;
&lt;br&gt;practical solutions to computer security issues. In an informal &amp;nbsp;
&lt;br&gt;setting with a mixture of material bilingually translated in both &amp;nbsp;
&lt;br&gt;English and Japanese the eminent technologists can socialize and &amp;nbsp;
&lt;br&gt;attend training sessions.
&lt;br&gt;&lt;br&gt;Announcing the opportunity to submit papers for the PacSec 2009 &amp;nbsp;
&lt;br&gt;network security training conference. The conference will be held &amp;nbsp;
&lt;br&gt;November 4/5th in Tokyo. The conference focuses on emerging &amp;nbsp;
&lt;br&gt;information security tutorials - it is a bridge between the &amp;nbsp;
&lt;br&gt;international and Japanese information security technology communities..
&lt;br&gt;&lt;br&gt;Please make your paper proposal submissions before June 1st, 2009. &amp;nbsp;
&lt;br&gt;Slides for the papers must be submitted for translation by October 1, &amp;nbsp;
&lt;br&gt;2009 (Which, oh so rarely, happens we are going to start asking for &amp;nbsp;
&lt;br&gt;them earlier :-P --dr).
&lt;br&gt;&lt;br&gt;A some invited papers have been confirmed, but a limited number of &amp;nbsp;
&lt;br&gt;speaking slots are still available. The conference is responsible for &amp;nbsp;
&lt;br&gt;travel and accomodations for the speakers. If you have a proposal for &amp;nbsp;
&lt;br&gt;a tutorial session then please email a synopsis of the material and &amp;nbsp;
&lt;br&gt;your biography, papers and, speaking background to &amp;nbsp;. Tutorials are &amp;nbsp;
&lt;br&gt;one hour in length, but with simultaneous translation should be &amp;nbsp;
&lt;br&gt;approximately 45 minutes in English, or Japanese. Only slides will be &amp;nbsp;
&lt;br&gt;needed for the October paper deadline, full text does not have to be &amp;nbsp;
&lt;br&gt;submitted.
&lt;br&gt;&lt;br&gt;The PacSec conference consists of tutorials on technical details about &amp;nbsp;
&lt;br&gt;current issues, innovative techniques and best practices in the &amp;nbsp;
&lt;br&gt;information security realm. The audiences are a multi-national mix of &amp;nbsp;
&lt;br&gt;professionals involved on a daily basis with security work: security &amp;nbsp;
&lt;br&gt;product vendors, programmers, security officers, and network &amp;nbsp;
&lt;br&gt;administrators. We give preference to technical details and education &amp;nbsp;
&lt;br&gt;for a technical audience.
&lt;br&gt;&lt;br&gt;The conference itself is a single track series of presentations in a &amp;nbsp;
&lt;br&gt;lecture theater environment. The presentations offer speakers the &amp;nbsp;
&lt;br&gt;opportunity to showcase on-going research and collaborate with peers &amp;nbsp;
&lt;br&gt;while educating and highlighting advancements in security products and &amp;nbsp;
&lt;br&gt;techniques. The focus is on innovation, tutorials, and education &amp;nbsp;
&lt;br&gt;instead of product pitches. Some commercial content is tolerated, but &amp;nbsp;
&lt;br&gt;it needs to be backed up by a technical presenter - either giving a &amp;nbsp;
&lt;br&gt;valuable tutorial and best practices instruction or detailing &amp;nbsp;
&lt;br&gt;significant new technology in the products.
&lt;br&gt;&lt;br&gt;Paper proposals should consist of the following information:
&lt;br&gt;o
&lt;br&gt;1) Presenter, and geographical location (country of origin/passport) &amp;nbsp;
&lt;br&gt;and contact info (e-mail, postal address, phone, fax).
&lt;br&gt;2) Employer and/or affiliations.
&lt;br&gt;3) Brief biography, list of publications and papers.
&lt;br&gt;4) Any significant presentation and educational experience/background.
&lt;br&gt;5) Topic synopsis, Proposed paper title, and a one paragraph &amp;nbsp;
&lt;br&gt;description.
&lt;br&gt;6) Reason why this material is innovative or significant or an &amp;nbsp;
&lt;br&gt;important tutorial.
&lt;br&gt;7. Optionally, any samples of prepared material or outlines ready.
&lt;br&gt;8. Will you have full text available or only slides?
&lt;br&gt;9. Language of preference for submission.
&lt;br&gt;10. Please list any other publications or conferences where this &amp;nbsp;
&lt;br&gt;material has been or will be published/submitted.
&lt;br&gt;&lt;br&gt;Please include the plain text version of this information in your &amp;nbsp;
&lt;br&gt;email as well as any file, pdf, sxw, ppt, or html attachments.
&lt;br&gt;&lt;br&gt;Please forward the above information to &amp;nbsp;to be considered for &amp;nbsp;
&lt;br&gt;placement on the speaker roster.
&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;London, U.K. May 27/28 2009  &lt;a href=&quot;http://eusecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://eusecwest.com&lt;/a&gt;&lt;br&gt;Tokyo, Japan November 4/5 2009 &amp;nbsp;&lt;a href=&quot;http://pacsec.jp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pacsec.jp&lt;/a&gt;&lt;br&gt;Vancouver, Canada March 22-26 2010 &amp;nbsp;&lt;a href=&quot;http://cansecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cansecwest.com&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/EUSecWest-2009-%28May27-28%29-London-Agenda-and-PacSec-2009-%28Nov-4-5%29-Tokyo-CFP-deadline%3A-June-1-2009-tp23424746p23424746.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23315733</id>
	<title>Call for Papers Hack.lu 2009</title>
	<published>2009-04-30T05:42:46Z</published>
	<updated>2009-04-30T05:42:46Z</updated>
	<author>
		<name>hack.lu 2009 info</name>
	</author>
	<content type="html">Call for Papers Hack.lu 2009
&lt;br&gt;============================
&lt;br&gt;&lt;br&gt;The purpose of the hack.lu convention is to give an open and free
&lt;br&gt;playground where people can discuss the implication of new technologies
&lt;br&gt;in society. hack.lu is a balanced mix convention where technical and
&lt;br&gt;non-technical people can meet each other and share freely all kind of
&lt;br&gt;information. The convention will be held in the Grand-Duchy of
&lt;br&gt;Luxembourg in October 2009 (28-30.10.2008). The conference is three days
&lt;br&gt;of active discussions, presentations and workshops for sharing
&lt;br&gt;experience around new attacks, defensive techniques and information
&lt;br&gt;security (including funky experiments). We would like to announce the
&lt;br&gt;opportunity to submit papers, and/or lightning talk proposals for
&lt;br&gt;selection by the hack.lu technical review committee. This year we will
&lt;br&gt;be doing one hour talks, and some shorter talk sessions.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Scope:
&lt;br&gt;------
&lt;br&gt;&lt;br&gt;Topics of interest include, but are not limited to:
&lt;br&gt;- Software Engineering and Security
&lt;br&gt;- Honeypots/Honeynets
&lt;br&gt;- Spyware, Phishing and Botnets (Distributed attacks)
&lt;br&gt;- Newly discovered vulnerabilities in software and hardware
&lt;br&gt;- Electronic/Digital Privacy
&lt;br&gt;- Wireless Network and Security
&lt;br&gt;- Attacks on Information Systems and/or Digital Information Storage
&lt;br&gt;- Electronic Voting
&lt;br&gt;- Free Software and Security
&lt;br&gt;- Assessment of Computer, Electronic Devices and Information Systems
&lt;br&gt;- Standards for Information Security
&lt;br&gt;- Legal and Social Aspect of Information Security
&lt;br&gt;- Software Engineering and Security
&lt;br&gt;- Security in Information Retrieval
&lt;br&gt;- Network security
&lt;br&gt;- Forensics and Anti-Forensics
&lt;br&gt;- Mobile communications security and vulnerabilities
&lt;br&gt;&lt;br&gt;&lt;br&gt;Deadlines:
&lt;br&gt;----------
&lt;br&gt;&lt;br&gt;The following dates are important if you want to participate in the CfP
&lt;br&gt;&lt;br&gt;Abstract submission: no later than 15 June 2009
&lt;br&gt;Full paper submission: no later than 1st August 2009
&lt;br&gt;Notification date: mid/end of August
&lt;br&gt;&lt;br&gt;&lt;br&gt;Submission guideline:
&lt;br&gt;---------------------
&lt;br&gt;&lt;br&gt;Authors should submit a paper in English up to 5.000 words, using a
&lt;br&gt;non-proprietary and open electronic format. The program committee will
&lt;br&gt;review all papers and the author of each paper will be notified of the
&lt;br&gt;result, by electronic means. Abstract is up to 400 words. Submissions
&lt;br&gt;must be sent using the following interface: &lt;a href=&quot;http://2009.hack.lu/papers/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://2009.hack.lu/papers/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submissions should also include the following:
&lt;br&gt;1. Presenter, and geographical location (country of origin/passport)and
&lt;br&gt;contact info.
&lt;br&gt;2. Employer and/or affiliations.
&lt;br&gt;3. Brief biography, list of publications or papers.
&lt;br&gt;4. Any significant presentation and/or educational experience/background.
&lt;br&gt;5. Reason why this material is innovative or significant or an important
&lt;br&gt;tutorial.
&lt;br&gt;6. Optionally, any samples of prepared material or outlines ready.
&lt;br&gt;7. Information about if yes or no the submission has already been
&lt;br&gt;presented and where.
&lt;br&gt;&lt;br&gt;The information will be used only for the sole purpose of the hack.lu
&lt;br&gt;convention including the information on the public website. If you want
&lt;br&gt;to remain anonymous, you have the right to use a nickname.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Speakers' Privileges:
&lt;br&gt;---------------------
&lt;br&gt;&lt;br&gt;- Accommodation will be provided (3 nights).
&lt;br&gt;- Travel expenses will be covered up to a max amount.
&lt;br&gt;- Conference speakers night.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Publication and rights:
&lt;br&gt;-----------------------
&lt;br&gt;&lt;br&gt;Authors keep the full rights on their publication/papers but give an
&lt;br&gt;unrestricted right to redistribute their papers for the hack.lu
&lt;br&gt;convention and its related electronic/paper publication.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Sponsoring:
&lt;br&gt;-----------
&lt;br&gt;&lt;br&gt;If you want to support the initiative and gain visibility by sponsoring,
&lt;br&gt;please contact us by writing an e-mail to info(AT)hack.lu
&lt;br&gt;&lt;br&gt;&lt;br&gt;Web site and wiki:
&lt;br&gt;------------------
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://2009.hack.lu/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://2009.hack.lu/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Call-for-Papers-Hack.lu-2009-tp23315733p23315733.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23185978</id>
	<title>RE: Mail Honeypot Thesis</title>
	<published>2009-04-22T14:18:15Z</published>
	<updated>2009-04-22T14:18:15Z</updated>
	<author>
		<name>Ian Bradshaw</name>
	</author>
	<content type="html">I would have thought that botnets are a much greater problem than an open
&lt;br&gt;relay, which is just a couple of pcs / servers and can easily be knocked
&lt;br&gt;offline by an ISP etc.
&lt;br&gt;&lt;br&gt;Also, be careful where you run your relay ... whatever ISP your using will
&lt;br&gt;be none too happy at being blacklisted; especially since they are trying to
&lt;br&gt;provide a commercial service rather than be someone's toy. It's worth noting
&lt;br&gt;that sending SPAM is probably not legal in your country legal and definitely
&lt;br&gt;not moral, and your proposing to send a load.
&lt;br&gt;&lt;br&gt;I would have thought there is enough SPAM data in the public domain ...
&lt;br&gt;&lt;a href=&quot;http://www.projecthoneypot.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.projecthoneypot.org/&lt;/a&gt;&amp;nbsp;/
&lt;br&gt;&lt;a href=&quot;http://www.projecthoneypot.org/statistics.php&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.projecthoneypot.org/statistics.php&lt;/a&gt;&amp;nbsp;... provide a lot for example,
&lt;br&gt;and if you drop them a nice mail and explain what you're doing etc, you may
&lt;br&gt;find a handy contact and them willing to give you more information. Much
&lt;br&gt;better than creating yet another SPAM source and feeling the wrath of your
&lt;br&gt;ISP / College / Uni / Other sys admins imho.
&lt;br&gt;&lt;br&gt;I.
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23185978&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23185978&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On
&lt;br&gt;Behalf Of dotcompex
&lt;br&gt;Sent: 22 April 2009 14:55
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23185978&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;honeypots@...&lt;/a&gt;
&lt;br&gt;Subject: Mail Honeypot Thesis
&lt;br&gt;&lt;br&gt;&lt;br&gt;I'm doing mail honeypot project for my thesis. &amp;nbsp;Having a little bit problem
&lt;br&gt;in writing good report. &amp;nbsp;I hope u all can comment it so I can edit before
&lt;br&gt;submit it. &amp;nbsp;For the start, I attach my abstract.
&lt;br&gt;&lt;br&gt;Electronic mail or in short can be called email is an important
&lt;br&gt;communication method since internet were propagated in the early 1980s. 
&lt;br&gt;People have change their way of communication since the used of email
&lt;br&gt;arising. &amp;nbsp;However the efficacy of email is being endangered by spam problems
&lt;br&gt;when the Internet was opened up to the public. &amp;nbsp;As defined by Spamhaus
&lt;br&gt;Project, spam applied to Unsolicited Bulk Email. &amp;nbsp;Unsolicited means that the
&lt;br&gt;recipient has not approved for the message to be sent. &amp;nbsp;Bulk means that the
&lt;br&gt;message is sent in large quantities and indistinguishable content. &amp;nbsp;Mail
&lt;br&gt;servers that run Simple Mail Transfer Protocol (SMTP) service which are open
&lt;br&gt;relay are exposed to be abused by spam. &amp;nbsp;An open relay mail server will
&lt;br&gt;relay any messages through it. &amp;nbsp;This project will help to determine the spam
&lt;br&gt;source of origin and their contents. &amp;nbsp;Methodology used in this project is
&lt;br&gt;experimental approach. &amp;nbsp;This project will be run on Qmail mail server which
&lt;br&gt;is an open relay and tcpdump for data capturing. &amp;nbsp;The open relay mail server
&lt;br&gt;will be act as mail honeypot to attract spammers. &amp;nbsp;Hopefully this project
&lt;br&gt;can benefit others by contributing spam source of origin to be inserted in
&lt;br&gt;spam block list.
&lt;br&gt;-- 
&lt;br&gt;View this message in context:
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/Mail-Honeypot-Thesis-tp23175462p23175462.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/Mail-Honeypot-Thesis-tp23175462p23175462.html&lt;/a&gt;&lt;br&gt;Sent from the Honeypots mailing list archive at Nabble.com.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Mail-Honeypot-Thesis-tp23175462p23185978.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23185833</id>
	<title>RE: Mail Honeypot Thesis</title>
	<published>2009-04-22T14:15:14Z</published>
	<updated>2009-04-22T14:15:14Z</updated>
	<author>
		<name>Jesper Jurcenoks</name>
	</author>
	<content type="html">Hi dotcompex.
&lt;br&gt;&lt;br&gt;Make sure you don't actually relay the emails!
&lt;br&gt;Only emulate an open relay, and then accept the emails for relay, without actually relaying them.
&lt;br&gt;&lt;br&gt;If you relay then you become part of the problem, and not part of the solution.
&lt;br&gt;&lt;br&gt;There should be no need to use TCPdump to capture the email traffic originator, any normal STMP program should put the originating IP-address in the logfile. 
&lt;br&gt;&lt;br&gt;You should add a spam filter based on originating IPS to your solution so that you don't accept emails from known spammers, this way you will focus on discovering the unknown Originating IPs. If you don't then you will just be using your bandwidth on known spammers without the benefit you are seeking.
&lt;br&gt;&lt;br&gt;Honestly I don't see the research value in you discovering a few more originating IPs using known detection methods. Most of these IPs will only be spamming for a few days any way.
&lt;br&gt;&lt;br&gt;You could change the focus of your report to have several Open relays on different servers and try to determine if spammers prefer one kind of mail server over another.
&lt;br&gt;&lt;br&gt;You could also try and measure how many spammer are using SMTP over TLS(SSL) compared to unencrypted SMTP
&lt;br&gt;&lt;br&gt;This would make your thesis much more interesting to read.
&lt;br&gt;&lt;br&gt;If you are done with the experiment part, then this advise comes a bit late but I hope it helps anyway.
&lt;br&gt;&lt;br&gt;Jesper Jurcenoks
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23185833&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23185833&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of dotcompex
&lt;br&gt;Sent: Wednesday, April 22, 2009 6:55 AM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23185833&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;honeypots@...&lt;/a&gt;
&lt;br&gt;Subject: Mail Honeypot Thesis
&lt;br&gt;&lt;br&gt;&lt;br&gt;I'm doing mail honeypot project for my thesis. &amp;nbsp;Having a little bit problem
&lt;br&gt;in writing good report. &amp;nbsp;I hope u all can comment it so I can edit before
&lt;br&gt;submit it. &amp;nbsp;For the start, I attach my abstract.
&lt;br&gt;&lt;br&gt;Electronic mail or in short can be called email is an important
&lt;br&gt;communication method since internet were propagated in the early 1980s. 
&lt;br&gt;People have change their way of communication since the used of email
&lt;br&gt;arising. &amp;nbsp;However the efficacy of email is being endangered by spam problems
&lt;br&gt;when the Internet was opened up to the public. &amp;nbsp;As defined by Spamhaus
&lt;br&gt;Project, spam applied to Unsolicited Bulk Email. &amp;nbsp;Unsolicited means that the
&lt;br&gt;recipient has not approved for the message to be sent. &amp;nbsp;Bulk means that the
&lt;br&gt;message is sent in large quantities and indistinguishable content. &amp;nbsp;Mail
&lt;br&gt;servers that run Simple Mail Transfer Protocol (SMTP) service which are open
&lt;br&gt;relay are exposed to be abused by spam. &amp;nbsp;An open relay mail server will
&lt;br&gt;relay any messages through it. &amp;nbsp;This project will help to determine the spam
&lt;br&gt;source of origin and their contents. &amp;nbsp;Methodology used in this project is
&lt;br&gt;experimental approach. &amp;nbsp;This project will be run on Qmail mail server which
&lt;br&gt;is an open relay and tcpdump for data capturing. &amp;nbsp;The open relay mail server
&lt;br&gt;will be act as mail honeypot to attract spammers. &amp;nbsp;Hopefully this project
&lt;br&gt;can benefit others by contributing spam source of origin to be inserted in
&lt;br&gt;spam block list.
&lt;br&gt;-- 
&lt;br&gt;View this message in context: &lt;a href=&quot;http://www.nabble.com/Mail-Honeypot-Thesis-tp23175462p23175462.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/Mail-Honeypot-Thesis-tp23175462p23175462.html&lt;/a&gt;&lt;br&gt;Sent from the Honeypots mailing list archive at Nabble.com.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Mail-Honeypot-Thesis-tp23175462p23185833.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23175462</id>
	<title>Mail Honeypot Thesis</title>
	<published>2009-04-22T06:54:51Z</published>
	<updated>2009-04-22T06:54:51Z</updated>
	<author>
		<name>dotcompex</name>
	</author>
	<content type="html">I'm doing mail honeypot project for my thesis. &amp;nbsp;Having a little bit problem in writing good report. &amp;nbsp;I hope u all can comment it so I can edit before submit it. &amp;nbsp;For the start, I attach my abstract.
&lt;br&gt;&lt;br&gt;Electronic mail or in short can be called email is an important communication method since internet were propagated in the early 1980s. &amp;nbsp;People have change their way of communication since the used of email arising. &amp;nbsp;However the efficacy of email is being endangered by spam problems when the Internet was opened up to the public. &amp;nbsp;As defined by Spamhaus Project, spam applied to Unsolicited Bulk Email. &amp;nbsp;Unsolicited means that the recipient has not approved for the message to be sent. &amp;nbsp;Bulk means that the message is sent in large quantities and indistinguishable content. &amp;nbsp;Mail servers that run Simple Mail Transfer Protocol (SMTP) service which are open relay are exposed to be abused by spam. &amp;nbsp;An open relay mail server will relay any messages through it. &amp;nbsp;This project will help to determine the spam source of origin and their contents. &amp;nbsp;Methodology used in this project is experimental approach. &amp;nbsp;This project will be run on Qmail mail server which is an open relay and tcpdump for data capturing. &amp;nbsp;The open relay mail server will be act as mail honeypot to attract spammers. &amp;nbsp;Hopefully this project can benefit others by contributing spam source of origin to be inserted in spam block list.</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Mail-Honeypot-Thesis-tp23175462p23175462.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23126399</id>
	<title>Re: nepenthes for multiple ip addresses</title>
	<published>2009-04-19T11:56:45Z</published>
	<updated>2009-04-19T11:56:45Z</updated>
	<author>
		<name>Viktor-13</name>
	</author>
	<content type="html">Thanks for all the answers, i have profited a lot from them! Let me
&lt;br&gt;answer for each reply in one mail.
&lt;br&gt;&lt;br&gt;Kashyap Timmaraju wrote:
&lt;br&gt;&amp;gt; The reason you need arpd is because you have to bind the unused IP
&lt;br&gt;&amp;gt; addresses to a MAC address in this case it will be your MAC
&lt;br&gt;&amp;gt; address(how else can u get read those packets?) which arpd does for
&lt;br&gt;&amp;gt; you. You will have to run arpd, so all the best with your experiment!
&lt;br&gt;I have tryed farpd to get all unused IPs, but since i'm in a /24 subnet,
&lt;br&gt;i could only bind IPs from my subnet (i have forgot to mention that i'm
&lt;br&gt;e.g 192.168.1.1/24, but i'm having traffic redirected from
&lt;br&gt;192.168.0.1-192.168.255.255). It's a great package btw (thanks again Mr
&lt;br&gt;Provos :))
&lt;br&gt;&lt;br&gt;Gergely Révay wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; If there is no address translation in the routing process then you
&lt;br&gt;&amp;gt; should have alias interfaces for those IPs which you want to listen
&lt;br&gt;&amp;gt; on.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; For instance if the 192.168.1.0/24 network is redirected to your
&lt;br&gt;&amp;gt; computer then you should use a command like this:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; $ for i in `seq 2 254`; do sudo ip addr add 192.168.1.$i/24 brd + dev eth0; done
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; (or something :) )
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; In this case when nepenthes listens on 0.0.0.0 then it means it listen
&lt;br&gt;&amp;gt; on the alias IPs as well.
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;Unfortunately it's a bit more complex. My box got traffic addressed to
&lt;br&gt;currently unused IPs, but the IPs are changing every time (if someone
&lt;br&gt;get one of the IPs by DHCP, than i won't get any more traffic redirected
&lt;br&gt;to me), and i think it would cause network conflict if i would add all
&lt;br&gt;255*255 IPs to my interface (also it's a big number :)).
&lt;br&gt;&amp;gt; If there is address translation in the routing then those packet
&lt;br&gt;&amp;gt; should have your IP as their destination IP and then it should work.
&lt;br&gt;&amp;gt; If you don't know you can check it with tcpdump
&lt;br&gt;I'm not getting traffic by NAT, all traffic are simply redirected to my
&lt;br&gt;IP. But after reading your reply, i tryed to NAT all traffic locally at
&lt;br&gt;my computer, and it worked! I set iptables' nat to translate the
&lt;br&gt;destination ip of all packets, which destination ip wasn't mine
&lt;br&gt;originally, to my ip. Now nepenthes having it's log incremented by
&lt;br&gt;0.5MB/min :))).
&lt;br&gt;&lt;br&gt;The only problem, that now i lost all information about who received the
&lt;br&gt;malicious packet originally, since in the log all dest ip is mine :(. Do
&lt;br&gt;you think is that possible to write such a script that can delay the
&lt;br&gt;packets, add the originaly dest ip to my interface, move the packet
&lt;br&gt;(nepenthes scans it), than after a short delay remove the IP from my
&lt;br&gt;interface? Or if there is any simpler solution, i'm open to all
&lt;br&gt;suggestion :)
&lt;br&gt;&lt;br&gt;Viktor
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nepenthes-for-multiple-ip-addresses-tp23114051p23126399.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23124267</id>
	<title>Re: nepenthes for multiple ip addresses</title>
	<published>2009-04-19T08:11:38Z</published>
	<updated>2009-04-19T08:11:38Z</updated>
	<author>
		<name>Gergely Révay</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;If there is no address translation in the routing process then you
&lt;br&gt;should have alias interfaces for those IPs which you want to listen
&lt;br&gt;on.
&lt;br&gt;&lt;br&gt;For instance if the 192.168.1.0/24 network is redirected to your
&lt;br&gt;computer then you should use a command like this:
&lt;br&gt;&lt;br&gt;$ for i in `seq 2 254`; do sudo ip addr add 192.168.1.$i/24 brd + dev eth0; done
&lt;br&gt;&lt;br&gt;(or something :) )
&lt;br&gt;&lt;br&gt;In this case when nepenthes listens on 0.0.0.0 then it means it listen
&lt;br&gt;on the alias IPs as well.
&lt;br&gt;If there is address translation in the routing then those packet
&lt;br&gt;should have your IP as their destination IP and then it should work.
&lt;br&gt;If you don't know you can check it with tcpdump.
&lt;br&gt;&lt;br&gt;I hope I helped.
&lt;br&gt;&lt;br&gt;Good luck!
&lt;br&gt;&lt;br&gt;Geri
&lt;br&gt;&lt;br&gt;2009/4/18 Viktor &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23124267&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gecko003@...&lt;/a&gt;&amp;gt;:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I'm running nepenthes on a debian OS at an universiry network with a fix IP. I managed to get a high number of unused IP addresses from the university network administrator, all traffic from these are routed to my computer. Now i'm having 200 packet/s income rate, but nepenthes only looks for the traffic addressed to my own IP. Is there a way to make nepenthes listening for all incoming packets despite the packet destination IP is not mine?
&lt;br&gt;&amp;gt; I have a lot of IPs, and they are random, changing every time, so it's not an option to give alternate IPs to my interface.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks in advance!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Viktor
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nepenthes-for-multiple-ip-addresses-tp23114051p23124267.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23114583</id>
	<title>Re: nepenthes for multiple ip addresses</title>
	<published>2009-04-18T08:37:29Z</published>
	<updated>2009-04-18T08:37:29Z</updated>
	<author>
		<name>Sushant Sinha</name>
	</author>
	<content type="html">Did you try arpd to get packets to your box?
&lt;br&gt;&lt;br&gt;-sushant.
&lt;br&gt;&lt;br&gt;On Sat, 2009-04-18 at 17:17 +0200, Viktor wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'm running nepenthes on a debian OS at an universiry network with a fix IP. I managed to get a high number of unused IP addresses from the university network administrator, all traffic from these are routed to my computer. Now i'm having 200 packet/s income rate, but nepenthes only looks for the traffic addressed to my own IP. Is there a way to make nepenthes listening for all incoming packets despite the packet destination IP is not mine?
&lt;br&gt;&amp;gt; I have a lot of IPs, and they are random, changing every time, so it's not an option to give alternate IPs to my interface.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks in advance!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Viktor
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nepenthes-for-multiple-ip-addresses-tp23114051p23114583.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23114051</id>
	<title>nepenthes for multiple ip addresses</title>
	<published>2009-04-18T08:17:32Z</published>
	<updated>2009-04-18T08:17:32Z</updated>
	<author>
		<name>Viktor-13</name>
	</author>
	<content type="html">Hello!
&lt;br&gt;&lt;br&gt;I'm running nepenthes on a debian OS at an universiry network with a fix IP. I managed to get a high number of unused IP addresses from the university network administrator, all traffic from these are routed to my computer. Now i'm having 200 packet/s income rate, but nepenthes only looks for the traffic addressed to my own IP. Is there a way to make nepenthes listening for all incoming packets despite the packet destination IP is not mine?
&lt;br&gt;I have a lot of IPs, and they are random, changing every time, so it's not an option to give alternate IPs to my interface.
&lt;br&gt;&lt;br&gt;Thanks in advance!
&lt;br&gt;&lt;br&gt;Viktor
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nepenthes-for-multiple-ip-addresses-tp23114051p23114051.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23056881</id>
	<title>HITBSecConf2009 - Malaysia: Call for Papers</title>
	<published>2009-04-14T21:12:17Z</published>
	<updated>2009-04-14T21:12:17Z</updated>
	<author>
		<name>Praburaajan Selvarajan</name>
	</author>
	<content type="html">The Call for Papers for HITB Security Conference 2009 Malaysia is now open!
&lt;br&gt;&lt;br&gt;Talks that are more technical or that discuss new and never before seen
&lt;br&gt;attack methods are of more interest than a subject that has been covered
&lt;br&gt;several times before. Summaries not exceeding 1250 words should be
&lt;br&gt;submitted (in plain text format) to cfp -at- hackinthebox.org for review
&lt;br&gt;and possible inclusion in the programme.
&lt;br&gt;&lt;br&gt;Submissions are due no later than 31st July 2009
&lt;br&gt;&lt;br&gt;TOPICS
&lt;br&gt;&lt;br&gt;Topics of interest include, but are not limited to the following:
&lt;br&gt;&lt;br&gt;# 3G/4G Cellular Networks
&lt;br&gt;# Apple / OS X security vulnerabilities
&lt;br&gt;# SS7/Backbone telephony networks
&lt;br&gt;# VoIP security
&lt;br&gt;# Firewall technologies
&lt;br&gt;# Intrusion detection
&lt;br&gt;# Data Recovery, Forensics and Incident Response
&lt;br&gt;# HSDPA and CDMA Security
&lt;br&gt;# WIMAX Security
&lt;br&gt;# Identification and Entity Authentication
&lt;br&gt;# Network Protocol and Analysis
&lt;br&gt;# Smart Card and Physical Security
&lt;br&gt;# Virus and Worms
&lt;br&gt;# WLAN, GPS, HAM Radio, Satellite, RFID and Bluetooth Security
&lt;br&gt;# Analysis of malicious code
&lt;br&gt;# Applications of cryptographic techniques
&lt;br&gt;# Analysis of attacks against networks and machines
&lt;br&gt;# File system security
&lt;br&gt;# Security of Embedded Devices
&lt;br&gt;# Side Channel Analysis of Hardware Devices
&lt;br&gt;&lt;br&gt;PLEASE NOTE:
&lt;br&gt;&lt;br&gt;We do not accept product or vendor related pitches. If your talk
&lt;br&gt;involves an advertisement for a new product or service your company is
&lt;br&gt;offering, please do not submit.
&lt;br&gt;&lt;br&gt;Your submission should include:
&lt;br&gt;&lt;br&gt;# Name, title, address, email and phone/contact number
&lt;br&gt;# Short biography, qualification, occupation (limit 250 words)
&lt;br&gt;# Summary or abstract for your presentation (limit 1250 words)
&lt;br&gt;# Technical requirements (video, internet, wireless, audio, etc.)
&lt;br&gt;&lt;br&gt;Each non-resident speaker will receive accommodation for 2 nights/3
&lt;br&gt;days. For each non-resident speaker, HITB will cover travel expenses up
&lt;br&gt;to USD 1,200.00.
&lt;br&gt;&lt;br&gt;HITBSecConf2009 - Malaysia
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2009kl/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2009kl/&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/HITBSecConf2009---Malaysia%3A-Call-for-Papers-tp23056881p23056881.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23004638</id>
	<title>In need of LOTS of &quot;sanitized' Sebek Keystrokes</title>
	<published>2009-04-11T11:47:08Z</published>
	<updated>2009-04-11T11:47:08Z</updated>
	<author>
		<name>Blarnum, Seamus</name>
	</author>
	<content type="html">&lt;br&gt;Hey All,
&lt;br&gt;&lt;br&gt;I am trying to write a college paper on various hacker methods and I would like to know if anyone has any sanitized sebek keystroke logs I could use in my paper. All I need is the actual command inputs and any associated process information. Everything else is not required (or better sanitized for privacy sake). 
&lt;br&gt;&lt;br&gt;I have to finish my paper by the end of May for school, so anything would be deeply appreciated. I would also be willing to list your organization as a reference source for the use of the keystrokes if so desired.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&lt;br&gt;Seamus
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/In-need-of-LOTS-of-%22sanitized%27-Sebek-Keystrokes-tp23004638p23004638.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22981125</id>
	<title>Reminder: RAID 2009 CFP</title>
	<published>2009-04-09T12:13:46Z</published>
	<updated>2009-04-09T12:13:46Z</updated>
	<author>
		<name>Corrado Leita</name>
	</author>
	<content type="html">(We apologize if you receive multiple copies of this message)
&lt;br&gt;&lt;br&gt;================================================================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CALL FOR PAPERS
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RAID 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;12th International Symposium on
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Recent Advances in Intrusion Detection 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;September 23-25, 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Saint Malo, Brittany, France
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.rennes.supelec.fr/RAID2009/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rennes.supelec.fr/RAID2009/&lt;/a&gt;&lt;br&gt;&lt;br&gt;================================================================
&lt;br&gt;&lt;br&gt;&lt;br&gt;Topics:
&lt;br&gt;-------
&lt;br&gt;This symposium, the 12th in an annual series, brings together leading
&lt;br&gt;researchers and practitioners from academia, government, and industry
&lt;br&gt;to discuss issues and technologies related to intrusion detection and
&lt;br&gt;defense. The Recent Advances in Intrusion Detection (RAID)
&lt;br&gt;International Symposium series furthers advances in intrusion defense
&lt;br&gt;by promoting the exchange of ideas in a broad range of topics. As in
&lt;br&gt;previous years, all topics related to intrusion detection, prevention
&lt;br&gt;and defense systems and technologies are within scope, including but
&lt;br&gt;not limited to the following:
&lt;br&gt;&lt;br&gt;* Network and host intrusion detection and prevention
&lt;br&gt;* Anomaly and specification-based approaches
&lt;br&gt;* IDS cooperation and event correlation
&lt;br&gt;* Malware prevention, detection, analysis and containment
&lt;br&gt;* Web application security
&lt;br&gt;* Insider attack detection
&lt;br&gt;* Intrusion response, tolerance, and self protection
&lt;br&gt;* Operational experience and limitations of current approaches
&lt;br&gt;* Intrusion detection assessment and benchmarking
&lt;br&gt;* Attacks against IDS including DoS, evasion, and IDS discovery
&lt;br&gt;* Formal models, analysis, and standards
&lt;br&gt;* Deception systems and honeypots
&lt;br&gt;* Vulnerability analysis, risk assessment, and forensics
&lt;br&gt;* Adversarial machine learning for security
&lt;br&gt;* Visualization techniques
&lt;br&gt;* Special environments, including mobile and sensor networks
&lt;br&gt;* High-performance intrusion detection
&lt;br&gt;* Legal, social, and privacy issues
&lt;br&gt;* Network exfiltration detection
&lt;br&gt;* Botnet analysis, detection, and mitigation
&lt;br&gt;&lt;br&gt;Important Dates:
&lt;br&gt;----------------
&lt;br&gt;Paper submission deadline: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;April 5, 2009 (Extended until: April
&lt;br&gt;12, 2009, 23.59 PST)
&lt;br&gt;Paper acceptance or rejection: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;June &amp;nbsp;8, 2009
&lt;br&gt;Final paper camera ready copy: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;June 18, 2009
&lt;br&gt;Poster abstract submission deadline: &amp;nbsp;June 20, 2009
&lt;br&gt;Poster acceptance or rejection: &amp;nbsp; &amp;nbsp; &amp;nbsp; June 28, 2009
&lt;br&gt;&lt;br&gt;Submissions:
&lt;br&gt;------------
&lt;br&gt;RAID 2009 invites two types of submissions:
&lt;br&gt;&lt;br&gt;1. Full papers presenting mature research results or summarizing
&lt;br&gt;&amp;nbsp; &amp;nbsp;operational experience protecting or monitoring large real-world
&lt;br&gt;&amp;nbsp; &amp;nbsp;networks. Papers can be 10-20 pages long and, if accepted, they will
&lt;br&gt;&amp;nbsp; &amp;nbsp;be presented and included in the RAID 2009 proceedings published by
&lt;br&gt;&amp;nbsp; &amp;nbsp;Springer Verlag in its Lecture Notes in Computer Science
&lt;br&gt;&amp;nbsp; &amp;nbsp;(&lt;a href=&quot;http://www.springer.de/comp/lncs/index.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.springer.de/comp/lncs/index.html&lt;/a&gt;) series. Papers must be
&lt;br&gt;&amp;nbsp; &amp;nbsp;formatted according to the instructions provided by Springer Verlag
&lt;br&gt;&amp;nbsp; &amp;nbsp;(&lt;a href=&quot;http://www.springer.de/comp/lncs/authors.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.springer.de/comp/lncs/authors.html&lt;/a&gt;), and include an
&lt;br&gt;&amp;nbsp; &amp;nbsp;abstract and a list of keywords.
&lt;br&gt;&lt;br&gt;2. Posters describing innovative ideas not mature enough for a full
&lt;br&gt;&amp;nbsp; &amp;nbsp;paper and works in progress. A two-page poster abstract formatted as
&lt;br&gt;&amp;nbsp; &amp;nbsp;a full paper with an abstract must be submitted. If accepted, it
&lt;br&gt;&amp;nbsp; &amp;nbsp;will be published in the proceedings and the poster will be presented.
&lt;br&gt;&lt;br&gt;All submissions (papers and poster abstracts) must be submitted
&lt;br&gt;electronically; details will be provided on the conference
&lt;br&gt;web site. Papers should list all authors and their affiliations; in case
&lt;br&gt;of multiple authors, the contact author must be indicated (RAID does not
&lt;br&gt;require anonymized submissions). &amp;nbsp;For accepted papers, it is required
&lt;br&gt;that at least one of the authors attends the conference to present the
&lt;br&gt;paper. Further questions on the submission process may be sent to the
&lt;br&gt;program chair. &amp;nbsp;Submissions must not substantially duplicate work that
&lt;br&gt;any of the authors has published elsewhere or has submitted in parallel
&lt;br&gt;to a journal or to any other conference or workshop with proceedings.
&lt;br&gt;Simultaneous submission of the same work to multiple venues, submission
&lt;br&gt;of previously published work, and plagiarism constitute dishonesty or
&lt;br&gt;fraud. RAID, like other scientific and technical conferences and journals,
&lt;br&gt;prohibits these practices and may, on the recommendation of the program
&lt;br&gt;chair, take action against authors who have committed them.
&lt;br&gt;&lt;br&gt;Organizing Committee:
&lt;br&gt;---------------------
&lt;br&gt;General Chair: Ludovic Me (Supelec, France, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22981125&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Ludovic.Me@...&lt;/a&gt;)
&lt;br&gt;Program Chair: Engin Kirda (Eurecom, France, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22981125&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;kirda@...&lt;/a&gt;)
&lt;br&gt;Program Co-Chair: Somesh Jha (University of Wisconsin, USA, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22981125&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jha@...&lt;/a&gt;)
&lt;br&gt;Publication Chair: Davide Balzarotti (Eurecom, France,
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22981125&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;balzarotti@...&lt;/a&gt;)
&lt;br&gt;Publicity Chair: Corrado Leita (Symantec Research Europe,
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22981125&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Corrado_Leita@...&lt;/a&gt;)
&lt;br&gt;Sponsorship Chair: Christophe Bidan (Supelec, France)
&lt;br&gt;&lt;br&gt;Steering Committee:
&lt;br&gt;-------------------
&lt;br&gt;Chair: Marc Dacier (Symantec Research Europe)
&lt;br&gt;Herve Debar (France Telecom R&amp;D)
&lt;br&gt;Deborah Frincke (Pacific Northwest National Lab, USA)
&lt;br&gt;Ming-Yuh Huang (The Boeing Company, USA)
&lt;br&gt;Erland Jonsson (Chalmers)
&lt;br&gt;Wenke Lee (Georgia Institute of Technology)
&lt;br&gt;Ludovic Me (Supelec)
&lt;br&gt;Alfonso Valdes (SRI International)
&lt;br&gt;Giovanni Vigna (University of California, Santa Barbara)
&lt;br&gt;Andreas Wespi (IBM Research, Switzerland)
&lt;br&gt;S. Felix Wu (University of California, Davis)
&lt;br&gt;Diego Zamboni (IBM Research, Switzerland)
&lt;br&gt;Christopher Kruegel (University of California, Santa Barbara)
&lt;br&gt;&lt;br&gt;Program Committee:
&lt;br&gt;-------------------
&lt;br&gt;&lt;br&gt;Anil Somayaji, &amp;nbsp;Carleton University, Canada
&lt;br&gt;Benjamin Morin, Central Directorate for Information System Security (DCSSI),
&lt;br&gt;France
&lt;br&gt;Christopher Kruegel, University of California, Santa Barbara, USA
&lt;br&gt;Collin Jackson, Stanford University, USA
&lt;br&gt;Corrado Leita, Symantec Research Europe, France
&lt;br&gt;David Brumley, Carnegie Mellon University, USA
&lt;br&gt;Davide Balzarotti, Eurecom, France
&lt;br&gt;Dongyan Xu, Purdue University, USA
&lt;br&gt;Engin Kirda, Eurecom, France
&lt;br&gt;Giovanni Vigna, University of California, Santa Barbara, USA
&lt;br&gt;Guevara Noubir, North Eastern University, USA
&lt;br&gt;Guofei Gu, Texas A &amp; M University, USA
&lt;br&gt;Jaeyeon Jung, Intel Research, USA
&lt;br&gt;John Viega, Stonewall Software, USA
&lt;br&gt;Jonathan Giffin, Georgia Institute of Technology, USA
&lt;br&gt;Jouni Viinikka, Orange Labs, France
&lt;br&gt;Kathy Wang, MITRE
&lt;br&gt;Manuel Costa, Microsoft Research, Cambridge, UK
&lt;br&gt;Michael Bailey, University of Michigan, USA
&lt;br&gt;Mihai Christodorescu, IBM T.J. Watson, USA
&lt;br&gt;R. Sekar, Stoney Brook University, USA
&lt;br&gt;Radu State, University of Luxembourg, Luxembourg
&lt;br&gt;Robert Cunningham, MIT Lincoln Labs
&lt;br&gt;Robin Sommer, International Computer Science Institute, USA
&lt;br&gt;Somesh Jha, University of Wisconsin, USA
&lt;br&gt;Sotiris Ioannidis, FORTH, Greece
&lt;br&gt;Thorsten Holz, University of Mannheim, Germany
&lt;br&gt;Olivier Festor, INRIA Nancy, France
&lt;br&gt;Xuxian Jiang, North Carolina State University, USA
&lt;br&gt;&lt;br&gt;Student Scholarships:
&lt;br&gt;---------------------
&lt;br&gt;&lt;br&gt;RAID 2009 is planning to offer student scholarships to reduce
&lt;br&gt;symposium attendance costs. Students should visit the web site
&lt;br&gt;(&lt;a href=&quot;http://www.rennes.supelec.fr/RAID2009/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rennes.supelec.fr/RAID2009/&lt;/a&gt;) to learn about the possible
&lt;br&gt;availability of scholarships and application deadlines.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Reminder%3A-RAID-2009-CFP-tp22981125p22981125.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22906466</id>
	<title>Re: Stealth VM</title>
	<published>2009-04-06T02:44:40Z</published>
	<updated>2009-04-06T02:44:40Z</updated>
	<author>
		<name>Dante Signal31</name>
	</author>
	<content type="html">2008/10/6 Stuart Gilchrist-Thomas &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22906466&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stuartpaulthomas@...&lt;/a&gt;&amp;gt;:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Does anyone have any pointers to evidence or advice on hiding or reducing the detection of VM honey pots. I know of temporal issues e.g. Timing metrics can give away a VM, and that you can manually alter peripheral identities e.g. virtual network cards etc.
&lt;br&gt;&amp;gt; I've also created a company to purchase ip and hosting space to ensure a form of identity in depth. But I still lack experience in preventing detection. Can you help? Are you my only hope? ;)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Many thanks.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ---
&lt;br&gt;&amp;gt; Sent whilst mobile.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -original message-
&lt;br&gt;&amp;gt; Subject: Re: Honeypot VMs
&lt;br&gt;&amp;gt; From: pinowudi &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22906466&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pinowudi@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Date: 06/10/2008 00:13
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; HPC
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.honeyclient.org/trac&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.honeyclient.org/trac&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Jason Lewis wrote:
&lt;br&gt;&amp;gt;&amp;gt; Are there any honeypot VM resources?  I've seen the SPARSA one, but the
&lt;br&gt;&amp;gt;&amp;gt; link is dead.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; jas
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;Hi Stuart,
&lt;br&gt;&lt;br&gt;last year I wrote on my blog an article about VM detection. It's in
&lt;br&gt;spanish... but shell commands are an universal language ;-)
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://danteslab.blogspot.com/2008/03/deteccin-de-mquinas-virtuales.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://danteslab.blogspot.com/2008/03/deteccin-de-mquinas-virtuales.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;I hope you like it.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Dante
&lt;br&gt;(&lt;a href=&quot;http://danteslab.blogspot.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://danteslab.blogspot.com/&lt;/a&gt;)
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Stealth-VM-tp19836051p22906466.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22836926</id>
	<title>EUSecWest 2009 CFP (May 27/28, Deadline April 7 2009)</title>
	<published>2009-04-01T14:40:49Z</published>
	<updated>2009-04-01T14:40:49Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">Call For Papers
&lt;br&gt;&lt;br&gt;    The EUSecWest 2009 CFP is now open.
&lt;br&gt;&lt;br&gt;    Deadline is April 7th, 2009.
&lt;br&gt;&lt;br&gt;EUSecWest CALL FOR PAPERS
&lt;br&gt;&lt;br&gt;    LONDON, U.K. -- The third annual EUSecWest applied
&lt;br&gt;    technical security conference - where the eminent figures
&lt;br&gt;    in the international security industry will get together
&lt;br&gt;    share best practices and technology - will be held in
&lt;br&gt;    downtown London at the Sound Club in Leicester Square
&lt;br&gt;    on May 27/28, 2009. The most significant new discoveries
&lt;br&gt;    about computer network hack attacks and defenses,
&lt;br&gt;    commercial security solutions, and pragmatic real world
&lt;br&gt;    security experience will be presented in a series of
&lt;br&gt;    informative tutorials.
&lt;br&gt;&lt;br&gt;    The EUSecWest meeting provides international researchers
&lt;br&gt;    a relaxed, comfortable environment to learn from
&lt;br&gt;    informative tutorials on key developments in security
&lt;br&gt;    technology, and collaborate and socialize with their peers
&lt;br&gt;    in one of the world's most most important technology
&lt;br&gt;    hubs and scenic cities. The timing of the conference
&lt;br&gt;    allows international travelers to travel to Berlin for
&lt;br&gt;    FX's Ph-Neutral on the weekend, and Rennes the 
&lt;br&gt;    following week for SSTIC.
&lt;br&gt;&lt;br&gt;    We would like to announce the opportunity to submit
&lt;br&gt;    papers, and/or lightning talk proposals for selection by
&lt;br&gt;    the EUSecWest technical review committee. This year we
&lt;br&gt;    will be doing one hour talks, and some shorter talk
&lt;br&gt;    sessions.
&lt;br&gt;&lt;br&gt;    Please make your paper proposal submissions before
&lt;br&gt;    April 7th, 2009.
&lt;br&gt;&lt;br&gt;    Some invited papers have been confirmed, but a limited
&lt;br&gt;    number of speaking slots are still available. The
&lt;br&gt;    conference is responsible for travel and accommodations for
&lt;br&gt;    the speaker (one speaker airfare and one room). If you 
&lt;br&gt;    have a proposal for a tutorial session then please email 
&lt;br&gt;    a synopsis of the material and your biography, papers 
&lt;br&gt;    and, speaking background to secwest09 [at] eusecwest.com . 
&lt;br&gt;    Only slides will be needed for the paper deadline, full text 
&lt;br&gt;    does not have to be submitted - but will be accepted if 
&lt;br&gt;    available. 
&lt;br&gt;&lt;br&gt;    The EUSecWest 2009 conference consists of tutorials on
&lt;br&gt;    technical details about current issues, innovative
&lt;br&gt;    techniques and best practices in the information security
&lt;br&gt;    realm. The audiences are a multi-national mix of
&lt;br&gt;    professionals involved on a daily basis with security
&lt;br&gt;    work: security product vendors, programmers, security
&lt;br&gt;    officers, and network administrators. We give preference
&lt;br&gt;    to technical details and new education for a technical
&lt;br&gt;    audience.
&lt;br&gt;&lt;br&gt;    The conference itself is a single track series of
&lt;br&gt;    presentations in a lecture theater environment. The
&lt;br&gt;    presentations offer speakers the opportunity to showcase
&lt;br&gt;    on-going research and collaborate with peers while
&lt;br&gt;    educating and highlighting advancements in security
&lt;br&gt;    products and techniques. The focus is on innovation,
&lt;br&gt;    tutorials, and education instead of product pitches. Some
&lt;br&gt;    commercial content is tolerated, but it needs to be backed
&lt;br&gt;    up by a technical presenter - either giving a valuable
&lt;br&gt;    tutorial and best practices instruction or detailing
&lt;br&gt;    significant new technology in the products.
&lt;br&gt;&lt;br&gt;    Paper proposals should consist of the following
&lt;br&gt;    information:
&lt;br&gt;     1. Presenter, and geographical location (country of
&lt;br&gt;        origin/passport) and contact info (e-mail, postal
&lt;br&gt;        address, phone, fax).
&lt;br&gt;     2. Employer and/or affiliations.
&lt;br&gt;     3. Brief biography, list of publications and papers.
&lt;br&gt;     4. Any significant presentation and educational
&lt;br&gt;        experience/background.
&lt;br&gt;     5. Topic synopsis, Proposed paper title, and a one
&lt;br&gt;        paragraph description.
&lt;br&gt;     6. Reason why this material is innovative or significant
&lt;br&gt;        or an important tutorial.
&lt;br&gt;     7. Optionally, any samples of prepared material or
&lt;br&gt;        outlines ready.
&lt;br&gt;     8. Will you have full text available or only slides?
&lt;br&gt;     9. Language of preference for submission.
&lt;br&gt;    10. Please list any other publications or conferences
&lt;br&gt;        where this material has been or will be
&lt;br&gt;        published/submitted.
&lt;br&gt;&lt;br&gt;    Please include the plain text version of this information
&lt;br&gt;    in your email as well as any file, pdf, sxw, ppt, or html
&lt;br&gt;    attachments.
&lt;br&gt;&lt;br&gt;    Please forward the above information to secwest09 [at]
&lt;br&gt;    eusecwest.com to be considered for placement on the
&lt;br&gt;    speaker roster, or have your lightning talk scheduled. If
&lt;br&gt;    you contact anyone else at our organization please ensure
&lt;br&gt;    you also cc the submission address with your proposal or
&lt;br&gt;    it may be omitted from the review process.
&lt;br&gt;&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;London, U.K. May 27/28 2009  &lt;a href=&quot;http://eusecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://eusecwest.com&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/EUSecWest-2009-CFP-%28May-27-28%2C-Deadline-April-7-2009%29-tp22836926p22836926.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22825924</id>
	<title>CFP RAID 2009 - extended deadline</title>
	<published>2009-04-01T01:50:07Z</published>
	<updated>2009-04-01T01:50:07Z</updated>
	<author>
		<name>Corrado Leita</name>
	</author>
	<content type="html">(We apologize if you receive multiple copies of this message)
&lt;br&gt;&lt;br&gt;EXTENDED DEADLINE FOR PAPER SUBMISSION: April 12, 2009
&lt;br&gt;&lt;br&gt;================================================================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CALL FOR PAPERS
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RAID 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;12th International Symposium on
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Recent Advances in Intrusion Detection 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;September 23-25, 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Saint Malo, Brittany, France
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.rennes.supelec.fr/RAID2009/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rennes.supelec.fr/RAID2009/&lt;/a&gt;&lt;br&gt;&lt;br&gt;================================================================
&lt;br&gt;&lt;br&gt;&lt;br&gt;Topics:
&lt;br&gt;-------
&lt;br&gt;This symposium, the 12th in an annual series, brings together leading
&lt;br&gt;researchers and practitioners from academia, government, and industry
&lt;br&gt;to discuss issues and technologies related to intrusion detection and
&lt;br&gt;defense. The Recent Advances in Intrusion Detection (RAID)
&lt;br&gt;International Symposium series furthers advances in intrusion defense
&lt;br&gt;by promoting the exchange of ideas in a broad range of topics. As in
&lt;br&gt;previous years, all topics related to intrusion detection, prevention
&lt;br&gt;and defense systems and technologies are within scope, including but
&lt;br&gt;not limited to the following:
&lt;br&gt;&lt;br&gt;* Network and host intrusion detection and prevention
&lt;br&gt;* Anomaly and specification-based approaches
&lt;br&gt;* IDS cooperation and event correlation
&lt;br&gt;* Malware prevention, detection, analysis and containment
&lt;br&gt;* Web application security
&lt;br&gt;* Insider attack detection
&lt;br&gt;* Intrusion response, tolerance, and self protection
&lt;br&gt;* Operational experience and limitations of current approaches
&lt;br&gt;* Intrusion detection assessment and benchmarking
&lt;br&gt;* Attacks against IDS including DoS, evasion, and IDS discovery
&lt;br&gt;* Formal models, analysis, and standards
&lt;br&gt;* Deception systems and honeypots
&lt;br&gt;* Vulnerability analysis, risk assessment, and forensics
&lt;br&gt;* Adversarial machine learning for security
&lt;br&gt;* Visualization techniques
&lt;br&gt;* Special environments, including mobile and sensor networks
&lt;br&gt;* High-performance intrusion detection
&lt;br&gt;* Legal, social, and privacy issues
&lt;br&gt;* Network exfiltration detection
&lt;br&gt;* Botnet analysis, detection, and mitigation
&lt;br&gt;&lt;br&gt;Important Dates:
&lt;br&gt;----------------
&lt;br&gt;Paper submission deadline: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;April 5, 2009 (Extended until: April
&lt;br&gt;12, 2009, 23.59 PST)
&lt;br&gt;Paper acceptance or rejection: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;June &amp;nbsp;8, 2009
&lt;br&gt;Final paper camera ready copy: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;June 18, 2009
&lt;br&gt;Poster abstract submission deadline: &amp;nbsp;June 20, 2009
&lt;br&gt;Poster acceptance or rejection: &amp;nbsp; &amp;nbsp; &amp;nbsp; June 28, 2009
&lt;br&gt;&lt;br&gt;Submissions:
&lt;br&gt;------------
&lt;br&gt;RAID 2009 invites two types of submissions:
&lt;br&gt;&lt;br&gt;1. Full papers presenting mature research results or summarizing
&lt;br&gt;&amp;nbsp; &amp;nbsp;operational experience protecting or monitoring large real-world
&lt;br&gt;&amp;nbsp; &amp;nbsp;networks. Papers can be 10-20 pages long and, if accepted, they will
&lt;br&gt;&amp;nbsp; &amp;nbsp;be presented and included in the RAID 2009 proceedings published by
&lt;br&gt;&amp;nbsp; &amp;nbsp;Springer Verlag in its Lecture Notes in Computer Science
&lt;br&gt;&amp;nbsp; &amp;nbsp;(&lt;a href=&quot;http://www.springer.de/comp/lncs/index.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.springer.de/comp/lncs/index.html&lt;/a&gt;) series. Papers must be
&lt;br&gt;&amp;nbsp; &amp;nbsp;formatted according to the instructions provided by Springer Verlag
&lt;br&gt;&amp;nbsp; &amp;nbsp;(&lt;a href=&quot;http://www.springer.de/comp/lncs/authors.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.springer.de/comp/lncs/authors.html&lt;/a&gt;), and include an
&lt;br&gt;&amp;nbsp; &amp;nbsp;abstract and a list of keywords.
&lt;br&gt;&lt;br&gt;2. Posters describing innovative ideas not mature enough for a full
&lt;br&gt;&amp;nbsp; &amp;nbsp;paper and works in progress. A two-page poster abstract formatted as
&lt;br&gt;&amp;nbsp; &amp;nbsp;a full paper with an abstract must be submitted. If accepted, it
&lt;br&gt;&amp;nbsp; &amp;nbsp;will be published in the proceedings and the poster will be presented.
&lt;br&gt;&lt;br&gt;All submissions (papers and poster abstracts) must be submitted
&lt;br&gt;electronically; details will be provided on the conference
&lt;br&gt;web site. Papers should list all authors and their affiliations; in case
&lt;br&gt;of multiple authors, the contact author must be indicated (RAID does not
&lt;br&gt;require anonymized submissions). &amp;nbsp;For accepted papers, it is required
&lt;br&gt;that at least one of the authors attends the conference to present the
&lt;br&gt;paper. Further questions on the submission process may be sent to the
&lt;br&gt;program chair. &amp;nbsp;Submissions must not substantially duplicate work that
&lt;br&gt;any of the authors has published elsewhere or has submitted in parallel
&lt;br&gt;to a journal or to any other conference or workshop with proceedings.
&lt;br&gt;Simultaneous submission of the same work to multiple venues, submission
&lt;br&gt;of previously published work, and plagiarism constitute dishonesty or
&lt;br&gt;fraud. RAID, like other scientific and technical conferences and journals,
&lt;br&gt;prohibits these practices and may, on the recommendation of the program
&lt;br&gt;chair, take action against authors who have committed them.
&lt;br&gt;&lt;br&gt;Organizing Committee:
&lt;br&gt;---------------------
&lt;br&gt;General Chair: Ludovic Me (Supelec, France, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22825924&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Ludovic.Me@...&lt;/a&gt;)
&lt;br&gt;Program Chair: Engin Kirda (Eurecom, France, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22825924&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;kirda@...&lt;/a&gt;)
&lt;br&gt;Program Co-Chair: Somesh Jha (University of Wisconsin, USA, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22825924&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jha@...&lt;/a&gt;)
&lt;br&gt;Publication Chair: Davide Balzarotti (Eurecom, France,
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22825924&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;balzarotti@...&lt;/a&gt;)
&lt;br&gt;Publicity Chair: Corrado Leita (Symantec Research Europe,
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22825924&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Corrado_Leita@...&lt;/a&gt;)
&lt;br&gt;Sponsorship Chair: Christophe Bidan (Supelec, France)
&lt;br&gt;&lt;br&gt;Steering Committee:
&lt;br&gt;-------------------
&lt;br&gt;Chair: Marc Dacier (Symantec Research Europe)
&lt;br&gt;Herve Debar (France Telecom R&amp;D)
&lt;br&gt;Deborah Frincke (Pacific Northwest National Lab, USA)
&lt;br&gt;Ming-Yuh Huang (The Boeing Company, USA)
&lt;br&gt;Erland Jonsson (Chalmers)
&lt;br&gt;Wenke Lee (Georgia Institute of Technology)
&lt;br&gt;Ludovic Me (Supelec)
&lt;br&gt;Alfonso Valdes (SRI International)
&lt;br&gt;Giovanni Vigna (University of California, Santa Barbara)
&lt;br&gt;Andreas Wespi (IBM Research, Switzerland)
&lt;br&gt;S. Felix Wu (University of California, Davis)
&lt;br&gt;Diego Zamboni (IBM Research, Switzerland)
&lt;br&gt;Christopher Kruegel (University of California, Santa Barbara)
&lt;br&gt;&lt;br&gt;Program Committee:
&lt;br&gt;-------------------
&lt;br&gt;&lt;br&gt;Anil Somayaji, &amp;nbsp;Carleton University, Canada
&lt;br&gt;Benjamin Morin, Central Directorate for Information System Security (DCSSI),
&lt;br&gt;France
&lt;br&gt;Christopher Kruegel, University of California, Santa Barbara, USA
&lt;br&gt;Collin Jackson, Stanford University, USA
&lt;br&gt;Corrado Leita, Symantec Research Europe, France
&lt;br&gt;David Brumley, Carnegie Mellon University, USA
&lt;br&gt;Davide Balzarotti, Eurecom, France
&lt;br&gt;Dongyan Xu, Purdue University, USA
&lt;br&gt;Engin Kirda, Eurecom, France
&lt;br&gt;Giovanni Vigna, University of California, Santa Barbara, USA
&lt;br&gt;Guevara Noubir, North Eastern University, USA
&lt;br&gt;Guofei Gu, Texas A &amp; M University, USA
&lt;br&gt;Jaeyeon Jung, Intel Research, USA
&lt;br&gt;John Viega, Stonewall Software, USA
&lt;br&gt;Jonathan Giffin, Georgia Institute of Technology, USA
&lt;br&gt;Jouni Viinikka, Orange Labs, France
&lt;br&gt;Kathy Wang, MITRE
&lt;br&gt;Manuel Costa, Microsoft Research, Cambridge, UK
&lt;br&gt;Michael Bailey, University of Michigan, USA
&lt;br&gt;Mihai Christodorescu, IBM T.J. Watson, USA
&lt;br&gt;R. Sekar, Stoney Brook University, USA
&lt;br&gt;Radu State, University of Luxembourg, Luxembourg
&lt;br&gt;Robert Cunningham, MIT Lincoln Labs
&lt;br&gt;Robin Sommer, International Computer Science Institute, USA
&lt;br&gt;Somesh Jha, University of Wisconsin, USA
&lt;br&gt;Sotiris Ioannidis, FORTH, Greece
&lt;br&gt;Thorsten Holz, University of Mannheim, Germany
&lt;br&gt;Olivier Festor, INRIA Nancy, France
&lt;br&gt;Xuxian Jiang, North Carolina State University, USA
&lt;br&gt;&lt;br&gt;Student Scholarships:
&lt;br&gt;---------------------
&lt;br&gt;&lt;br&gt;RAID 2009 is planning to offer student scholarships to reduce
&lt;br&gt;symposium attendance costs. Students should visit the web site
&lt;br&gt;(&lt;a href=&quot;http://www.rennes.supelec.fr/RAID2009/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rennes.supelec.fr/RAID2009/&lt;/a&gt;) to learn about the possible
&lt;br&gt;availability of scholarships and application deadlines.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/CFP-RAID-2009---extended-deadline-tp22825924p22825924.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22681555</id>
	<title>CFP RAID 2009</title>
	<published>2009-03-24T07:18:20Z</published>
	<updated>2009-03-24T07:18:20Z</updated>
	<author>
		<name>Corrado Leita</name>
	</author>
	<content type="html">&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CALL FOR PAPERS
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RAID 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;12th International Symposium on
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Recent Advances in Intrusion Detection 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;September 23-25, 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Saint Malo, Brittany, France
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.rennes.supelec.fr/RAID2009/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rennes.supelec.fr/RAID2009/&lt;/a&gt;&lt;br&gt;&lt;br&gt;================================================================
&lt;br&gt;&lt;br&gt;&lt;br&gt;Topics:
&lt;br&gt;-------
&lt;br&gt;This symposium, the 12th in an annual series, brings together leading
&lt;br&gt;researchers and practitioners from academia, government, and industry
&lt;br&gt;to discuss issues and technologies related to intrusion detection and
&lt;br&gt;defense. The Recent Advances in Intrusion Detection (RAID)
&lt;br&gt;International Symposium series furthers advances in intrusion defense
&lt;br&gt;by promoting the exchange of ideas in a broad range of topics. As in
&lt;br&gt;previous years, all topics related to intrusion detection, prevention
&lt;br&gt;and defense systems and technologies are within scope, including but
&lt;br&gt;not limited to the following:
&lt;br&gt;&lt;br&gt;* Network and host intrusion detection and prevention
&lt;br&gt;* Anomaly and specification-based approaches
&lt;br&gt;* IDS cooperation and event correlation
&lt;br&gt;* Malware prevention, detection, analysis and containment
&lt;br&gt;* Web application security
&lt;br&gt;* Insider attack detection
&lt;br&gt;* Intrusion response, tolerance, and self protection
&lt;br&gt;* Operational experience and limitations of current approaches
&lt;br&gt;* Intrusion detection assessment and benchmarking
&lt;br&gt;* Attacks against IDS including DoS, evasion, and IDS discovery
&lt;br&gt;* Formal models, analysis, and standards
&lt;br&gt;* Deception systems and honeypots
&lt;br&gt;* Vulnerability analysis, risk assessment, and forensics
&lt;br&gt;* Adversarial machine learning for security
&lt;br&gt;* Visualization techniques
&lt;br&gt;* Special environments, including mobile and sensor networks
&lt;br&gt;* High-performance intrusion detection
&lt;br&gt;* Legal, social, and privacy issues
&lt;br&gt;* Network exfiltration detection
&lt;br&gt;* Botnet analysis, detection, and mitigation
&lt;br&gt;&lt;br&gt;Important Dates:
&lt;br&gt;----------------
&lt;br&gt;Paper submission deadline: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;April 5, 2009
&lt;br&gt;Paper acceptance or rejection: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;June &amp;nbsp;8, 2009
&lt;br&gt;Final paper camera ready copy: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;June 18, 2009
&lt;br&gt;Poster abstract submission deadline: &amp;nbsp;June 20, 2009
&lt;br&gt;Poster acceptance or rejection: &amp;nbsp; &amp;nbsp; &amp;nbsp; June 28, 2009
&lt;br&gt;&lt;br&gt;Submissions:
&lt;br&gt;------------
&lt;br&gt;RAID 2009 invites two types of submissions:
&lt;br&gt;&lt;br&gt;1. Full papers presenting mature research results or summarizing
&lt;br&gt;&amp;nbsp; &amp;nbsp;operational experience protecting or monitoring large real-world
&lt;br&gt;&amp;nbsp; &amp;nbsp;networks. Papers can be 10-20 pages long and, if accepted, they will
&lt;br&gt;&amp;nbsp; &amp;nbsp;be presented and included in the RAID 2009 proceedings published by
&lt;br&gt;&amp;nbsp; &amp;nbsp;Springer Verlag in its Lecture Notes in Computer Science
&lt;br&gt;&amp;nbsp; &amp;nbsp;(&lt;a href=&quot;http://www.springer.de/comp/lncs/index.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.springer.de/comp/lncs/index.html&lt;/a&gt;) series. Papers must be
&lt;br&gt;&amp;nbsp; &amp;nbsp;formatted according to the instructions provided by Springer Verlag
&lt;br&gt;&amp;nbsp; &amp;nbsp;(&lt;a href=&quot;http://www.springer.de/comp/lncs/authors.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.springer.de/comp/lncs/authors.html&lt;/a&gt;), and include an
&lt;br&gt;&amp;nbsp; &amp;nbsp;abstract and a list of keywords.
&lt;br&gt;&lt;br&gt;2. Posters describing innovative ideas not mature enough for a full
&lt;br&gt;&amp;nbsp; &amp;nbsp;paper and works in progress. A two-page poster abstract formatted as
&lt;br&gt;&amp;nbsp; &amp;nbsp;a full paper with an abstract must be submitted. If accepted, it
&lt;br&gt;&amp;nbsp; &amp;nbsp;will be published in the proceedings and the poster will be presented.
&lt;br&gt;&lt;br&gt;All submissions (papers and poster abstracts) must be submitted
&lt;br&gt;electronically; details will be provided on the conference
&lt;br&gt;web site. Papers should list all authors and their affiliations; in case
&lt;br&gt;of multiple authors, the contact author must be indicated (RAID does not
&lt;br&gt;require anonymized submissions). &amp;nbsp;For accepted papers, it is required
&lt;br&gt;that at least one of the authors attends the conference to present the
&lt;br&gt;paper. Further questions on the submission process may be sent to the
&lt;br&gt;program chair. &amp;nbsp;Submissions must not substantially duplicate work that
&lt;br&gt;any of the authors has published elsewhere or has submitted in parallel
&lt;br&gt;to a journal or to any other conference or workshop with proceedings.
&lt;br&gt;Simultaneous submission of the same work to multiple venues, submission
&lt;br&gt;of previously published work, and plagiarism constitute dishonesty or
&lt;br&gt;fraud. RAID, like other scientific and technical conferences and journals,
&lt;br&gt;prohibits these practices and may, on the recommendation of the program
&lt;br&gt;chair, take action against authors who have committed them.
&lt;br&gt;&lt;br&gt;Organizing Committee:
&lt;br&gt;---------------------
&lt;br&gt;General Chair: Ludovic Me (Supelec, France, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22681555&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Ludovic.Me@...&lt;/a&gt;)
&lt;br&gt;Program Chair: Engin Kirda (Eurecom, France, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22681555&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;kirda@...&lt;/a&gt;)
&lt;br&gt;Program Co-Chair: Somesh Jha (University of Wisconsin, USA, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22681555&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jha@...&lt;/a&gt;)
&lt;br&gt;Publication Chair: Davide Balzarotti (Eurecom, France,
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22681555&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;balzarotti@...&lt;/a&gt;)
&lt;br&gt;Publicity Chair: Corrado Leita (Symantec Research Europe,
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22681555&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Corrado_Leita@...&lt;/a&gt;)
&lt;br&gt;Sponsorship Chair: Christophe Bidan (Supelec, France)
&lt;br&gt;&lt;br&gt;Steering Committee:
&lt;br&gt;-------------------
&lt;br&gt;Chair: Marc Dacier (Symantec Research Europe)
&lt;br&gt;Herve Debar (France Telecom R&amp;D)
&lt;br&gt;Deborah Frincke (Pacific Northwest National Lab, USA)
&lt;br&gt;Ming-Yuh Huang (The Boeing Company, USA)
&lt;br&gt;Erland Jonsson (Chalmers)
&lt;br&gt;Wenke Lee (Georgia Institute of Technology)
&lt;br&gt;Ludovic Me (Supelec)
&lt;br&gt;Alfonso Valdes (SRI International)
&lt;br&gt;Giovanni Vigna (University of California, Santa Barbara)
&lt;br&gt;Andreas Wespi (IBM Research, Switzerland)
&lt;br&gt;S. Felix Wu (University of California, Davis)
&lt;br&gt;Diego Zamboni (IBM Research, Switzerland)
&lt;br&gt;Christopher Kruegel (University of California, Santa Barbara)
&lt;br&gt;&lt;br&gt;Program Committee:
&lt;br&gt;-------------------
&lt;br&gt;&lt;br&gt;Anil Somayaji, &amp;nbsp;Carleton University, Canada
&lt;br&gt;Benjamin Morin, Central Directorate for Information System Security (DCSSI),
&lt;br&gt;France
&lt;br&gt;Christopher Kruegel, University of California, Santa Barbara, USA
&lt;br&gt;Collin Jackson, Stanford University, USA
&lt;br&gt;Corrado Leita, Symantec Research Europe, France
&lt;br&gt;David Brumley, Carnegie Mellon University, USA
&lt;br&gt;Davide Balzarotti, Eurecom, France
&lt;br&gt;Dongyan Xu, Purdue University, USA
&lt;br&gt;Engin Kirda, Eurecom, France
&lt;br&gt;Giovanni Vigna, University of California, Santa Barbara, USA
&lt;br&gt;Guevara Noubir, North Eastern University, USA
&lt;br&gt;Guofei Gu, Texas A &amp; M University, USA
&lt;br&gt;Jaeyeon Jung, Intel Research, USA
&lt;br&gt;John Viega, Stonewall Software, USA
&lt;br&gt;Jonathan Giffin, Georgia Institute of Technology, USA
&lt;br&gt;Jouni Viinikka, Orange Labs, France
&lt;br&gt;Kathy Wang, MITRE
&lt;br&gt;Manuel Costa, Microsoft Research, Cambridge, UK
&lt;br&gt;Michael Bailey, University of Michigan, USA
&lt;br&gt;Mihai Christodorescu, IBM T.J. Watson, USA
&lt;br&gt;R. Sekar, Stoney Brook University, USA
&lt;br&gt;Radu State, University of Luxembourg, Luxembourg
&lt;br&gt;Robert Cunningham, MIT Lincoln Labs
&lt;br&gt;Robin Sommer, International Computer Science Institute, USA
&lt;br&gt;Somesh Jha, University of Wisconsin, USA
&lt;br&gt;Sotiris Ioannidis, FORTH, Greece
&lt;br&gt;Thorsten Holz, University of Mannheim, Germany
&lt;br&gt;Olivier Festor, INRIA Nancy, France
&lt;br&gt;Xuxian Jiang, North Carolina State University, USA
&lt;br&gt;&lt;br&gt;Student Scholarships:
&lt;br&gt;---------------------
&lt;br&gt;&lt;br&gt;RAID 2009 is planning to offer student scholarships to reduce
&lt;br&gt;symposium attendance costs. Students should visit the web site
&lt;br&gt;(&lt;a href=&quot;http://www.rennes.supelec.fr/RAID2009/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.rennes.supelec.fr/RAID2009/&lt;/a&gt;) to learn about the possible
&lt;br&gt;availability of scholarships and application deadlines.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/CFP-RAID-2009-tp22681555p22681555.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22667035</id>
	<title>Workshop on the Analysis of System Logs (WASL) Oct 14, 2009</title>
	<published>2009-03-23T11:52:08Z</published>
	<updated>2009-03-23T11:52:08Z</updated>
	<author>
		<name>Greg Bronevetsky</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Workshop on the Analysis of System Logs (WASL) 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.systemloganalysis.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.systemloganalysis.com&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Call for Papers
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;===============================
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;October 14, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Big Sky, MT
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(at SOSP)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;===============================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FULL PAPER SUBMISSION: Monday, June 29th, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AUTHOR NOTIFICATION: Monday, July 27, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FINAL PAPERS DUE: Monday, September 14, 2009
&lt;br&gt;--------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;System logs contain a wide variety of information about system status 
&lt;br&gt;and health,
&lt;br&gt;including events from various applications, daemons and drivers, as well 
&lt;br&gt;as sampled
&lt;br&gt;information such as resource utilization statistics. As such, these logs 
&lt;br&gt;represent a
&lt;br&gt;rich source of information for the analysis and diagnosis of system 
&lt;br&gt;problems and
&lt;br&gt;prediction of future system events. However, their lack of organization 
&lt;br&gt;and the general
&lt;br&gt;lack of semantic consistency between information from various software 
&lt;br&gt;and hardware
&lt;br&gt;vendors means that most of this information content is wasted. Indeed, 
&lt;br&gt;today's
&lt;br&gt;most popular log analysis technique is to use regular expressions to 
&lt;br&gt;either detect
&lt;br&gt;events of interest or to filter the log so that a human operator can 
&lt;br&gt;examine it manually.
&lt;br&gt;Clearly, this captures only a fraction of the information available in 
&lt;br&gt;these logs and
&lt;br&gt;does not scale to the large systems common in business and 
&lt;br&gt;supercomputing environments.
&lt;br&gt;&lt;br&gt;This workshop will focus on novel techniques for extracting 
&lt;br&gt;operationally useful
&lt;br&gt;information from existing logs and methods to improve the information 
&lt;br&gt;content of future
&lt;br&gt;logs. Topics include but are not limited to:
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Reports on publicly available sources of sample log data.
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log anonymization
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log feature detection and extraction
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Prediction of malfunction or misuse based on log data
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Statistical techniques to characterize log data
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Applications of Natural-Language Processing (NLP) to logs
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Scalable log compression
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log comparison techniques
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Methods to enhance and standardize log semantics
&lt;br&gt;&amp;nbsp; &amp;nbsp; o System diagnostic techniques
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log visualization
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Analysis of services (problem ticket) logs
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Applications of log analysis to system administration
&lt;br&gt;&lt;br&gt;Papers limited to 6 2-column pages using &amp;gt;=10pt font.
&lt;br&gt;&lt;br&gt;Workshop Chair:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Greg Bronevetsky (Lawrence Livermore National Laboratory)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22667035&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;greg@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Program Committee:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Jon Stearley, Sandia National Laboratory
&lt;br&gt;&amp;nbsp; &amp;nbsp; Bianca Schroeder, University of Toronto
&lt;br&gt;&amp;nbsp; &amp;nbsp; Sébastien Tricaud, INL
&lt;br&gt;&amp;nbsp; &amp;nbsp; Sapan Bhatia, Princeton University
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Workshop-on-the-Analysis-of-System-Logs-%28WASL%29-Oct-14%2C-2009-tp22667035p22667035.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22659450</id>
	<title>Honeynet Project GSoC - Looking For Students</title>
	<published>2009-03-23T05:45:01Z</published>
	<updated>2009-03-23T05:45:01Z</updated>
	<author>
		<name>Lance Spitzner-2</name>
	</author>
	<content type="html">Folks,
&lt;br&gt;&lt;br&gt;As some of you may already know, the Honeynet Project was selected as &amp;nbsp;
&lt;br&gt;a mentoring organization for Google's annual Summer of Code event[1]. &amp;nbsp; 
&lt;br&gt;This event, sponsored by Google, funds students to develop and share &amp;nbsp;
&lt;br&gt;opensource code with the community. If you are interested in such an &amp;nbsp;
&lt;br&gt;event, and being funded by Google, we suggest you consider one of the &amp;nbsp;
&lt;br&gt;many research and development projects sponsored by the Honeynet &amp;nbsp;
&lt;br&gt;Project. &amp;nbsp;All of these projects are honeypot related and mentored by &amp;nbsp;
&lt;br&gt;some of the top leaders in honeypot research. &amp;nbsp;Learn more at
&lt;br&gt;&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://www.honeynet.org/gsoc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.honeynet.org/gsoc&lt;/a&gt;&lt;br&gt;&lt;br&gt;Applications start Monday, 23 March through Google.
&lt;br&gt;&lt;br&gt;Thanks!
&lt;br&gt;&lt;br&gt;lance
&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;http://socghop.appspot.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://socghop.appspot.com/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Honeynet-Project-GSoC---Looking-For-Students-tp22659450p22659450.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22513151</id>
	<title>HITB2009 - Dubai: Conference Agenda &amp; Noteworthy Presentations</title>
	<published>2009-03-13T17:47:57Z</published>
	<updated>2009-03-13T17:47:57Z</updated>
	<author>
		<name>Praburaajan Selvarajan</name>
	</author>
	<content type="html">The agenda for HITBSecConf2009 - Dubai is now online along with details
&lt;br&gt;on both the conference keynote sessions. There are still another 4 more
&lt;br&gt;weeks to grab your seats to the GCC's premier network security event!
&lt;br&gt;&lt;br&gt;Keynote 1 - Philippe Langlois (Founder, Qualys / Intrinsec / TSTF)
&lt;br&gt;&amp;quot;From Hacking, Startups to HackLabs: Global Perspective and New Fields&amp;quot;
&lt;br&gt;&lt;br&gt;Keynote 2 - Mark Curphey (Director CISG, Microsoft Corp)
&lt;br&gt;&amp;quot;Security Cogs and Levers&amp;quot;
&lt;br&gt;&lt;br&gt;Other noteworthy papers:
&lt;br&gt;&lt;br&gt;# Cross Domain Leakiness: Divulging Sensitive Information and Attacking
&lt;br&gt;SSL Sessions - Chris Evans and Billy Rios
&lt;br&gt;&lt;br&gt;# VBootKit 2.0 - Attacking Windows 7 via Boot Sectors - Vipin &amp; Nitin Kumar
&lt;br&gt;&lt;br&gt;# The Reverse Engineering Intermediate Language REIL and its
&lt;br&gt;Applications - Sebastian Porst
&lt;br&gt;&lt;br&gt;# Pickpocketing mWallets: A Guide to Looting Mobile Financial Services -
&lt;br&gt;The Grugq
&lt;br&gt;&lt;br&gt;# Psychotronica: Exposure, Control, and Deceit - Nitesh Dhanjani
&lt;br&gt;&lt;br&gt;# NKill - The Internet Killboard - Anthony 'kugutsumen' Zboralski
&lt;br&gt;&lt;br&gt;This is a new tool which gives &amp;nbsp;attackers the ability to discover
&lt;br&gt;interesting relationships between seemingly unrelated hosts and
&lt;br&gt;companies and to pull vulnerable hosts for a specific domain, company or
&lt;br&gt;even an entire country!
&lt;br&gt;&lt;br&gt;===
&lt;br&gt;&lt;br&gt;Conference Agenda:
&lt;br&gt;&lt;a href=&quot;http://conference.hackinthebox.org/hitbsecconf2009dubai/agenda.htm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://conference.hackinthebox.org/hitbsecconf2009dubai/agenda.htm&lt;/a&gt;&lt;br&gt;&lt;br&gt;===
&lt;br&gt;&lt;br&gt;On a related note, the conference videos from HITB2007 Malaysia that
&lt;br&gt;were previously available only through Bit Torrent are now available for
&lt;br&gt;streaming direct from Google Video:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://video.google.com/videosearch?q=HITBSecConf2007&amp;emb=0&amp;aq=f#q=HITBSecConf2007+Malaysia&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://video.google.com/videosearch?q=HITBSecConf2007&amp;emb=0&amp;aq=f#q=HITBSecConf2007+Malaysia&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/HITB2009---Dubai%3A-Conference-Agenda---Noteworthy-Presentations-tp22513151p22513151.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22371289</id>
	<title>High interaction honeypot</title>
	<published>2009-03-06T04:10:08Z</published>
	<updated>2009-03-06T04:10:08Z</updated>
	<author>
		<name>eternity0022</name>
	</author>
	<content type="html">Hi everyone
&lt;br&gt;&lt;br&gt;I need to setup a high interaction honeypot running ssh/ftp/telnet etc services and log probes/attacks. so far all i have read involves Honeynet ROO cd but due to lack of equipments, i wont be able to use that cd. so i was wondering if anyone knew of set of software that i could use to set up my own high interaction honeypot. a set of tools to monitor ports, log keystrokes and typed commands etc..
&lt;br&gt;&lt;br&gt;any help is highly appreciated.
&lt;br&gt;&lt;br&gt;p.s im planning to setup a Linux honeypot.</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/High-interaction-honeypot-tp22371289p22371289.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22288716</id>
	<title>Workshop on the Analysis of System Logs (WASL) Oct 14, 2009</title>
	<published>2009-03-01T13:30:16Z</published>
	<updated>2009-03-01T13:30:16Z</updated>
	<author>
		<name>Greg Bronevetsky</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Workshop on the Analysis of System Logs (WASL) 2009
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Call for Papers
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;===============================
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;October 14, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Big Sky, MT
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(at SOSP)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;===============================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FULL PAPER SUBMISSION: Monday, June 29th, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AUTHOR NOTIFICATION: Monday, July 27, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FINAL PAPERS DUE: Monday, September 14, 2009
&lt;br&gt;--------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;System logs contain a wide variety of information about system status 
&lt;br&gt;and health,
&lt;br&gt;including events from various applications, daemons and drivers, as well 
&lt;br&gt;as sampled
&lt;br&gt;information such as resource utilization statistics. As such, these logs 
&lt;br&gt;represent a
&lt;br&gt;rich source of information for the analysis and diagnosis of system 
&lt;br&gt;problems and
&lt;br&gt;prediction of future system events. However, their lack of organization 
&lt;br&gt;and the general
&lt;br&gt;lack of semantic consistency between information from various software 
&lt;br&gt;and hardware
&lt;br&gt;vendors means that most of this information content is wasted. Indeed, 
&lt;br&gt;today's
&lt;br&gt;most popular log analysis technique is to use regular expressions to 
&lt;br&gt;either detect
&lt;br&gt;events of interest or to filter the log so that a human operator can 
&lt;br&gt;examine it manually.
&lt;br&gt;Clearly, this captures only a fraction of the information available in 
&lt;br&gt;these logs and
&lt;br&gt;does not scale to the large systems common in business and 
&lt;br&gt;supercomputing environments.
&lt;br&gt;&lt;br&gt;This workshop will focus on novel techniques for extracting 
&lt;br&gt;operationally useful
&lt;br&gt;information from existing logs and methods to improve the information 
&lt;br&gt;content of future
&lt;br&gt;logs. Topics include but are not limited to:
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Reports on publicly available sources of sample log data.
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log anonymization
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log feature detection and extraction
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Prediction of malfunction or misuse based on log data
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Statistical techniques to characterize log data
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Applications of Natural-Language Processing (NLP) to logs
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Scalable log compression
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log comparison techniques
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Methods to enhance and standardize log semantics
&lt;br&gt;&amp;nbsp; &amp;nbsp; o System diagnostic techniques
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Log visualization
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Analysis of services (problem ticket) logs
&lt;br&gt;&amp;nbsp; &amp;nbsp; o Applications of log analysis to system administration
&lt;br&gt;&lt;br&gt;Papers limited to 6 2-column pages using &amp;gt;=10pt font.
&lt;br&gt;&lt;br&gt;Workshop Chair:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Greg Bronevetsky (Lawrence Livermore National Laboratory)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22288716&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;greg@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Program Committee:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Jon Stearley, Sandia National Laboratory
&lt;br&gt;&amp;nbsp; &amp;nbsp; Bianca Schroeder, University of Toronto
&lt;br&gt;&amp;nbsp; &amp;nbsp; Sébastien Tricaud, INL
&lt;br&gt;&amp;nbsp; &amp;nbsp; Sapan Bhatia, Princeton University
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Workshop-on-the-Analysis-of-System-Logs-%28WASL%29-Oct-14%2C-2009-tp22288716p22288716.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22030838</id>
	<title>CanSecWest 2009 Speakers and Dojo courses (Mar 14-20)</title>
	<published>2009-02-15T18:54:24Z</published>
	<updated>2009-02-15T18:54:24Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">Final Speaker Lineup for CanSecWest 2009 (March 18-20):
&lt;br&gt;===============================================
&lt;br&gt;&lt;br&gt;The Smart-Phones Nightmare - Sergio 'shadown' Alvarez
&lt;br&gt;&lt;br&gt;Getting into the SMRAM: SMM Reloaded - Loíc Duflot
&lt;br&gt;&lt;br&gt;Network design for effective HTTP traffic filtering - Jeff &amp;quot;rfp&amp;quot; &amp;nbsp;
&lt;br&gt;Forristal, Zscaler
&lt;br&gt;&lt;br&gt;Ninja Scanning - Fyodor, Insecure.org
&lt;br&gt;&lt;br&gt;On Approaches and Tools for Automated Vulnerability Analysis - Tanmay &amp;nbsp;
&lt;br&gt;Ganacharya &amp; Nikola Livic &amp; Abhishek Singh &amp; Swapnil Bhalode &amp; Scott &amp;nbsp;
&lt;br&gt;Lambert, Microsoft
&lt;br&gt;&lt;br&gt;Kicking It Old School: No DNS Packets Were Harmed In The Making Of &amp;nbsp;
&lt;br&gt;This Presentation - Dan Kaminski, IOActive
&lt;br&gt;&lt;br&gt;Binary Clone Wars: Software Whitelisting for Malware Prevention and &amp;nbsp;
&lt;br&gt;Coordinated Incident Response. - Shane Macaulay, Sean Comeau, and &amp;nbsp;
&lt;br&gt;Derek Callaway, Security Objectives
&lt;br&gt;&lt;br&gt;.NET Rootkits - Erez Metula
&lt;br&gt;&lt;br&gt;The Evolution of Microsoft's Exploit Mitigations - Matt Miller and Tim &amp;nbsp;
&lt;br&gt;Burrell, Microsoft
&lt;br&gt;&lt;br&gt;An overview of the state of videogame console security. - Victor Muñoz
&lt;br&gt;&lt;br&gt;A Look at a Modern Mobile Security Model: Google's Android - Jon &amp;nbsp;
&lt;br&gt;Oberheide
&lt;br&gt;&lt;br&gt;Bug classes we have found in *BSD, OS X and Solaris kernels - Christer &amp;nbsp;
&lt;br&gt;Oberg and Neil Kettle, Convergent Network Solutions
&lt;br&gt;&lt;br&gt;Multiplatform Iphone/Android Shellcode, and other smart phone &amp;nbsp;
&lt;br&gt;insecurities - Alfredo Ortega and Nico Economou, Core
&lt;br&gt;&lt;br&gt;Platform-independent static binary code analysis using a meta-assembly &amp;nbsp;
&lt;br&gt;language - Sebastian Porst &amp; Thomas &amp;quot;halvar&amp;quot; Dullien, zynamics
&lt;br&gt;&lt;br&gt;Persistent BIOS Infection - Anibal Sacco &amp; Alfredo Ortega, Core
&lt;br&gt;&lt;br&gt;Decompiling Dalvik and other JavaFX - Marc Schoenefeld
&lt;br&gt;&lt;br&gt;Automated Real-time and Post Mortem Security Crash Analysis and &amp;nbsp;
&lt;br&gt;Categorization - Jason Shirk &amp; Dave Weinstein, Microsoft
&lt;br&gt;&lt;br&gt;SSL, The Sequel: MD5 collisions and EV certificates - Alexander &amp;nbsp;
&lt;br&gt;Sotirov &amp; Mike Zusman
&lt;br&gt;&lt;br&gt;Exploiting Unicode-enabled software - Chris Weber
&lt;br&gt;&lt;br&gt;Chinese Infosec &amp; Malware Overview - Wei &amp;quot;icbm&amp;quot; Zhao, 365menshen
&lt;br&gt;&lt;br&gt;Hacking Macs for Fun and Profit - Dino Dai Zovi &amp; Charlie Miller
&lt;br&gt;&lt;br&gt;...and a variety of lightning talks...
&lt;br&gt;&lt;br&gt;&lt;br&gt;Security Masters Dojo courses (March 14-17):
&lt;br&gt;====================================
&lt;br&gt;&lt;br&gt;Metasploit: Asymmetric Warfare - H D Moore, BreakingPoint Systems
&lt;br&gt;&lt;br&gt;Advanced Honeypots - Thorsten Holz
&lt;br&gt;&lt;br&gt;IPv6 Network Security - Nico Fishbach &amp; Guillaume Valadon, COLT &amp; CNRS
&lt;br&gt;&lt;br&gt;Ultimate Web Hacking (One Day Edition) - Mike Andrews, Foundstone
&lt;br&gt;&lt;br&gt;TCP/IP Network Security In Depth - Andrea Barisani, inverse path
&lt;br&gt;&lt;br&gt;Effective Fuzzing using the Peach Fuzzing Platform - Michael &amp;nbsp;
&lt;br&gt;Eddington, Leviathan Security
&lt;br&gt;&lt;br&gt;Secure Java Programming and Auditing - Marc Schoenefeld
&lt;br&gt;&lt;br&gt;Practical 802.11 WiFi (In)Security - Cédric Blancher, EADS
&lt;br&gt;&lt;br&gt;Q/SSE Qualified/ Software Security Expert Certification Bootcamp - &amp;nbsp;
&lt;br&gt;Security University
&lt;br&gt;&lt;br&gt;Q/SA Qualified Security Analyst Penetration Tester - Security University
&lt;br&gt;&lt;br&gt;Advanced Linux Hardening - Andrea Barisani &amp; Jay Beale, inverse path &amp; &amp;nbsp;
&lt;br&gt;Intelguardians
&lt;br&gt;&lt;br&gt;Physical Security and Lock Technology - Deviant Ollam
&lt;br&gt;&lt;br&gt;The Exploit Laboratory - Advanced Edition - Saumil Shah, Net-Square
&lt;br&gt;&lt;br&gt;Mastering the Network with Scapy - Phillipe Biondi, EADS
&lt;br&gt;&lt;br&gt;&lt;br&gt;Pwn2Own Contests:
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;There will be TWO Pwn2Own contests this year.
&lt;br&gt;Generous cash prize(s) for exploits will be sponsored by Tipping Point,
&lt;br&gt;and &amp;nbsp;a Sony VAIO P fresh from Japan and a new loaded Apple Macbook
&lt;br&gt;will be amongst the prizes.
&lt;br&gt;&lt;br&gt;The targets this year will be mobile smart-phones, and browsers.
&lt;br&gt;&lt;br&gt;Mobile targets:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; iPhone
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Android
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Symbian
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RIM/BlackBerry
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Windows Mobile
&lt;br&gt;&lt;br&gt;Browser Targets:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IE8
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FF3
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Safari
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Opera
&lt;br&gt;&lt;br&gt;The contest will like in previous years feature a progressively &amp;nbsp;
&lt;br&gt;expanding attack surface over the three day duration of the 
&lt;br&gt;conference. Final prizes and rules will be announced shortly.
&lt;br&gt;&lt;br&gt;Post-Conference Whistler Expedition:
&lt;br&gt;=============================
&lt;br&gt;&lt;br&gt;We have secured some rooms at good rates at the Westin in Whistler 
&lt;br&gt;and reserved a cluster of four, 3-5 bedroom, cabins for the weekend 
&lt;br&gt;after the conference. Contact &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22030838&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;dr@...&lt;/a&gt; if you wish to be included 
&lt;br&gt;in the planning, final accommodation rates will be announced shortly.
&lt;br&gt;&lt;br&gt;Conference Hotel Block:
&lt;br&gt;===================
&lt;br&gt;&lt;br&gt;The room rates at the Sheraton Wall Center hotel where the conference
&lt;br&gt;is being held have been reduced from $183 to $169, and still includes
&lt;br&gt;a waived $15/day free internet access in the rate.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Tenth Anniversary Gala Event:
&lt;br&gt;========================
&lt;br&gt;&lt;br&gt;Since this is our tenth anniversary for the conference, we will 
&lt;br&gt;be having a party on Thursday night. Venue TBD. We're pretty 
&lt;br&gt;sure there will be a cake. No word yet on whether there will 
&lt;br&gt;be dancers inside it. ;-)
&lt;br&gt;&lt;br&gt;&lt;br&gt;Day-Care Facilities will be available:
&lt;br&gt;=============================
&lt;br&gt;&lt;br&gt;As a nod to the shifting demographic of early gen. security
&lt;br&gt;researchers we will be trying a new experiment this year 
&lt;br&gt;and we will be providing day-care facilities for those 
&lt;br&gt;traveling with kids. We will try to arrange some group
&lt;br&gt;discounts with our provider once we know how many 
&lt;br&gt;kids and what ages and times will have to be 
&lt;br&gt;accommodated. If you are interested in this service
&lt;br&gt;please send a note to &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22030838&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;yuriko@...&lt;/a&gt; and let 
&lt;br&gt;her know ages and times.
&lt;br&gt;&lt;br&gt;We will try to get them started on exploit writing 
&lt;br&gt;courses for pre-schoolers :-). Does this mean 
&lt;br&gt;we are all grown up now?
&lt;br&gt;&lt;br&gt;&lt;br&gt;It promises to be another fun conference again this 
&lt;br&gt;year. See you all there.
&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;Vancouver, Canada  March 16-20 2009  &lt;a href=&quot;http://cansecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cansecwest.com&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/CanSecWest-2009-Speakers-and-Dojo-courses-%28Mar-14-20%29-tp22030838p22030838.html" />
</entry>

</feed>
