<?xml version="1.0" encoding="iso-8859-1"?>
<!-- name="generator" content="pyblosxom/1.3.2 2/13/2006" -->
<!DOCTYPE rss PUBLIC "-//Netscape Communications//DTD RSS 0.91//EN" "http://my.netscape.com/publish/formats/rss-0.91.dtd">

<rss version="0.91">
<channel>
<title>DK 'Log   </title>
<link>http://www.alienvault.com/blog/dk</link>
<description>Just a place to write down some thoughts</description>
<language>en</language>
<item>
  <title>Last blog post... on this platform :-)</title>
  <link>http://www.alienvault.com/blog/dk/last_blog_post.html</link>
  <description><![CDATA[

<p>I'm posting less and less and it's not for lack of interesting stuff to post but because of the underlying platform. I'll stop using this old site where I had (have right now) to edit html manually and will move to something much more comfortable: blogspot.com </p>
<p>See you from now on at <a href="http://alienvault.blogspot.com">alienvault.blogspot.com</a> (glad I could snatch the name ;-) ).</p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>

]]></description>
</item>

<item>
  <title>Coming soon...</title>
  <link>http://www.alienvault.com/blog/dk/ossim/2010_03_coming_soon.html</link>
  <description><![CDATA[


<p>I'm not dead nor is the blog, it's just that twitter is so much easier for busy/lazy people</p>
<p>I intend to write four more tutorial series pretty soon, namely<br/>
<ul>
<li>Netflow stuff</li>
<li>Kismet stuff</li>
<li>OpenVPN inter-component config, setup and tricks</li>
<li>Multiuser samples/setup</li>
</ul></p>
<p>
I hope to be able to bring out one every two weeks aprox, let's see how that works.
</p>

]]></description>
</item>

<item>
  <title>OSSIM 2.2 is out!</title>
  <link>http://www.alienvault.com/blog/dk/ossim/2.2.released.html</link>
  <description><![CDATA[

<p>A quick saturday update. We just released OSSIM 2.2 with a ton of new features, have a look <a href="http://www.alienvault.com/community.php?section=News#98">here</a>. New screenshots and videos up on <a href="http://www.alienvault.com">AlienVault</a> too.</p>
<p>This release is quite complex featuring a whole lot of new features as well as a rewrite of old ones. Please don't hesitate posting on the forums if you've got any doubt or catch any bug.</p>
<p>I know I haven't been very active on the forums myself (what the heck, weren't able to answer during the last months) but the whole devel team @Alienvault will make an extra effort there too in order to make this the best release we had so far. At a technical level it is without a doubt. </p>
<p>
I for myself am very excited, RSA and BSidesSF next week :-))).
</p>

]]></description>
</item>

<item>
  <title>OSSIM at RSA &apos;10. More news</title>
  <link>http://www.alienvault.com/blog/dk/personal/rsa2010.html</link>
  <description><![CDATA[

<p>
Wow, almost March and my first post this year, need to care a bit more about this. Lot of things are happening around OSSIM, AlienVault and myself these months.
</p>

<p>
First, we finished a big funding round early this year which finally will enable us to consolidate OSSIM as a leader in the SIEM space (at least that's the idea :-) ). We're going to invest a lot into development but more importantly into community care, <a href="http://www.youtube.com">documentation</a> and all those things that wrap around the product.
</p>

<p>
Another big thing will be the imminent release of 2.2, with tons of new features. Check out the documentation link above which will lead you to http://www.youtube.com/alienvaulttv.
</p>

<p>
More things related to this funding is the establishment of AlienVault USA. For a start I'll be travelling a lot between Europe and the US, attending conferences, giving talks and scoping the market over there. San Francisco Bay Area is the chosen location for this move.
</p>
<p>
For a start we'll be having a small booth at RSA 2010l, booth #553 (check the <a href="http://www.rsaconference.com/2010/usa/for-sponsors-and-exhibitors/2010-floor-plan.htm">floorplan</a>, count four booth clusters to the right from the upper left corner). I'm very excited about this, looks like this is one of the largest and most interesting security vendor conferences available, and we'll be there. (Going to be there with our CEO and VP Sales). As a said note, in order not get too harassed by spam around me I'll spend a couple of days midst week at the BSidesSF, where I hope I'll be able to do a quick lightning talk :-)
</p>
<p>
That's all for now, next time I'll be writing from the sunny beach of Santa Cruz :)))
</p>

]]></description>
</item>

<item>
  <title>Happy new year</title>
  <link>http://www.alienvault.com/blog/dk/personal/happy_2010.html</link>
  <description><![CDATA[

<p>
Just a short post in order to wish everybody a happy 2010. 2009 has been an awesome year for OSSIM and 2010 promises to be even better; hope it's been as this for all of you too. Will be updating on that after holidays.
</p>
<p>
As said, happy new year! :-)
</p>

]]></description>
</item>

<item>
  <title>Back from vacation, status update and a shameless plug :-)</title>
  <link>http://www.alienvault.com/blog/dk/personal/status_update_2009_09.html</link>
  <description><![CDATA[

<p>
School year is starting again and so were I feeling too after coming back from the beach :-). Relax time is over tho and there's a lot of exciting stuff going on around AlienVault/OSSIM.
</p>
<p>
First of all I'd like to mention our new look&feel. After releasing 2.1 we decided the web should be undergoing a long-needed revamp, so <a href="/">here it is</a>. As you may have noticed too, we unified the looks of the original <a href="http://www.ossim.net">ossim.net site</a> and integrated it into the <a href="/community.php?section=Home">community section</a>, very much like MySQL does (was inspired on them actually).
</p>
<p>
Another important addition is the new <a href="/docs/AV-OSSIM Roadmap 2009.pdf">Roadmap</a>. Now that we're becoming a serious project with a serious company behind, we've got to take care of things like these which we might have neglected in the past.<br/>
You'll see that the next major release, 2.2, is scheduled for the 15th of February 2010. We're already working on the items planned for that, and I wanted to share a quick screenshot of what will be the unified report for hosts and networks. Basically you'll be able to right click on any host anywhere on the system and get out a quick overview of anything that the system knows about it. Here are two quick screenshots (work in progress ofc):<br/>
<br/>
<center>
[ <a href="/dk/blog/images/host_report1.png">Screenshot 1</a> | 
<a href="/dk/blog/images/host_report2.png">Screenshot 2</a> ] 
</center>
</p>
<p>
Anyway, this is just one of the many improvements there will be, so stay tuned...
</p>
<p>
Now comes the shameless plug. As part of the website redesign we also started to launch the online courses and training at <a href="http://elearning.alienvault.com/">elearning.alienvault.com</a>. Right now there are only two courses available, the "OSSIM Essentials" and "Build your own plugin" ones. If this initiative succeeds we'll continue to invest into it and prepare all the others, which in the end should cover all the material covered by the presential courses.<br/>
Prices are really cheap for promotion, 50 euro for around 3 or 4 hours worth of training, and although I'm biased I think they really do a good job in introducing OSSIM to those who're new to it, even if they're lacking deep computer or security skills.<br/>
So, if yuou're interested or know someone who could be, please give it a try. It's worth the money, we put a ton of work into it and it will help support your favourite SIM *grin*.
</p>
<p>
And here ends the plug and the post. I'm working right now on a plugin wizard which I'll be talking about soon. Once finished it will raise the amount of plugins available for OSSIM by around 2000 ;-)
</p>

]]></description>
</item>

<item>
  <title>AlienVault/OSSIM Job Opening: Documentation Writer required.</title>
  <link>http://www.alienvault.com/blog/dk/ossim/documentation_writer_job_offering.html</link>
  <description><![CDATA[

<p>
Hello all,
</p>
<p>
we're looking for somebody to assist us in the elaboration of
documentation around OSSIM, it's components and Open Source Security
in general. We require strong knowledge both in English written skills
as well as experience on OSSIM. We are willing to pay on a per-work
basis up to 3000 or 4000 . a month, with an option to get a permanent
contract if the initial work is satisfying.
</p>

<p>
I don't want to sound harsh, but the two aforementioned requirements
are a must and a strong filter. The english has to be perfect (much
better than mine of course :-) ) and knowledge of OSSIM has to be
deep, based on interest and/or experience already present before
reading this job offering. I mean, even if your english is perfect
don't try to download OSSIM, check out a couple of things and apply, or
if you know lots and lots about OSSIM don't start with an intensive
english course.
</p>

<p>
If you're interested we'd like you to send in a sample of your work
along with a curriculum vitae. We don't care about your nationality or
where you are located. the payment will remain the same of course. The
sample we're asking for would be to document the current alarm section
(Incidents->Alarms). Think about a user that's new to OSSIM, clicks on
the help in order to see what that alarm panel means and gets to that
document you've written. The desired document format would be pdf,
although when documentation gets live some sort of wiki is going to be
used. Remember, there are three things that should excel in this
sample:
</p>
<p>
<ul>
<li>We should raise our eyebrows in awe at your english written skills.
<li>We should be impressed by the deep knowledge of OSSIM that we can
see in those words.
<li>On the other hand, this is no technical document, it should be clear
for a new OSSIM user with little or no previous SIEM experience.
</ul>
</p>

<p>
Please send this sample to "jcasal" and "dk", both at the
alienvault.com domain. If you include "OSSIM Documentation Writer" in
the subject you'll ensure it will reach us asap :-).
</p>
<p>
Good luck!
</p>

]]></description>
</item>

<item>
  <title>Little BiG Planet tribute</title>
  <link>http://www.alienvault.com/blog/dk/personal/elmo_lbp_fun.html</link>
  <description><![CDATA[

<p>
If you haven't played <a href="http://www.littlebigplanet.com/">Little BiG Planet</a> before I must say it's an incredible fun, original and refreshing game to play. A bit short tho but it's supposed to benefit from community content, which I haven't tested.<br/>
Warning: don't read any further if you're under 18 (or was it 21?) and/or don't have much of a sense of humour.
</p>
<p>
This morning while walking back to my seat I had a look at how our poor Elmo ended after the whole financial crisis staff, and he resembled a bit of the sackman in LBP. Here's a pic of him:
</p>
<center><a href="/dk/blog/images/elmo_lpb.jpg"><img src="/dk/blog/images/elmo_lbp_thmb.png"></a></center>
<p>
There's a whole bunch of addons we've unlocked for him, ranging from the AntiSwineFluMask to the beach sandals, his flags denoting various political and sexual orientations, his lupanar flyer or his RJ45 directly into the brain.
</p>
<p>
See you at the webinar this thursady ;-)
</p>

]]></description>
</item>

<item>
  <title>Next webinar: Thursday the 30th of July</title>
  <link>http://www.alienvault.com/blog/dk/ossim/webinar_2009_07.html</link>
  <description><![CDATA[

<p>
Just before vacation we're going to do <a href="https://www1.gotomeeting.com/register/841736921">another webinar</a> in order to introduce our recently released version 2.1. It's very similar to the previous two we've done, so if you've already attended I'd suggest skipping this one (we're going to vary the content often) but for those who've missed it: meet you the 30th :-)
</p>

]]></description>
</item>

<item>
  <title>Can OSSIM be considered a SIEM? Is it enterprise ready?</title>
  <link>http://www.alienvault.com/blog/dk/personal/is_ossim_an_open_source_siem.html</link>
  <description><![CDATA[

<p>
The story starts as following. A couple of years ago Dr. <a href="http://www.chuvakin.org" class=ossim_blue>Anton Chuvakin</a> (for those who might not know him a well renowned security professional and speaker) made a <a href="http://www.matasano.com/log/661/pro-forma-06-punditry-results/" class=ossim_blue> prediction for 2006</a>: that a Credible Open-Source SIM would not arrive.
<br/>
<br/>
A year later he said this goal hasn't been reached (as predicted). I remember being quite pissed off and upset at that time, but his point was right. Development had been slow, we didn't have resources and everything was a bit stalled. But that has changed and AlienVault is about two years old now, we made a huge step forward and I think OSSIM is nowadays more than S/MB as well as Enteprise ready. (And sadly our resources are still very limited compared of those which Arcsight, Symantec or others might have).
</p>

<p>
Yesterday I followed a couple of quick twitter exchanges where I'd like to quote the most significant ones:
<ul>
<li><a href="http://twitter.com/andrewsmhay/statuses/2226650021">I agree but S/M of SMB probably won't have the capabilities to run something like OSSIM and it's not robust enough for Ent.</a></li>
<li><a href="http://twitter.com/falconsview/statuses/2224200091">@anton_chuvakin mind you, I simply asked if OSSIM had the potential, not that it was there yet... as always, I wonder, isn't there a better way?</a></li>
<li><a href="http://twitter.com/anton_chuvakin/statuses/2224135569">@falconsview Re: opn src #SIEM Well, show me a sizable deployment (and not one hand-built by its creators) and I will believe you.</a></li>
<li><a href="http://twitter.com/dkarg/statuses/2227864643">@anton_chuvakin Will you change your mind about opensource SIEM if I get you access to a sizable deployment not created by it's authors ? :P</a></li>
<li><a href="http://twitter.com/anton_chuvakin/statuses/2228545449">@dkarg Re: open src #SIEM Yes, I probably will.</a></li>
</ul>
</p>
<p>
So, there it is, <a href="http://www.andrewhay.ca/">Andrew Hay</a> (another renowned security expert) and Anton say that:
<br/>
<br/>
<ol>
<li>OSSIM is not a SIEM.</li>
<li>OSSIM is too difficult for S/MB and not reliable enough for the Enterprise</li>
</ol>
<br/>
Well. Guess I'll have to prove them wrong ;-). And on top I'm not pissed off, so I guess I'm growing up :-)).
</p>
<p>
So what do I need? I for myself have received news/feedback of pretty big OSSIM installations and have had my hands on another bunch of them. Ranging from 100 person Real Estate companies to >40000pc governmnet environments with distributed deployments and thousands of events per second (this last one using the COSS version of course). But, the point as mentioned by Anton is that we don't have our hands in it, the testimonial has to come from someone who's got a deployment running not managed by us. Both S/MB as well as large enterprise deployments are valid since there are two points to prove. I'd really like to hear from a large company which is supposedly using Splunk+OSSIM, can't say the name but that would be a good example :-).
</p>
<p>
So, if any of you reading this is in that situation please let Mr. Chuvakin and Mr. Hay know about it so they hopefully can change their minds on the subject. There's contact information on their respective homepages. Otherwise I'll have to eat my words and admit that OSSIM is no Open Source SIEM (like in The Matrix, "there's no spoon").
</p>
<p>
Thanks in advance for any help :-)
</p>
<p>
PS: BTW, we did a first run of the webinar yesterday, thanks everybody for assisting and apologies for the, well, mishappenings. I got quite nervous, next demo will be better.
</p>
<p>
Edit 2009/06/20: Fixed a misunderstanding on who predicted what, see the comments.
</p>


]]></description>
</item>

</channel>
</rss>
