<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Jack Whitsitt: Art and Security in Washington, DC</title>
	<atom:link href="http://sintixerr.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://sintixerr.wordpress.com</link>
	<description>An Artist&#039;s take on National Critical Infrastructure Protection, Enterprise Architecture, Information Security, (and some art)</description>
	<lastBuildDate>Fri, 20 Jan 2012 13:26:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='sintixerr.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Jack Whitsitt: Art and Security in Washington, DC</title>
		<link>http://sintixerr.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://sintixerr.wordpress.com/osd.xml" title="Jack Whitsitt: Art and Security in Washington, DC" />
	<atom:link rel='hub' href='http://sintixerr.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Cyber Security in Transportation: Agenda Update</title>
		<link>http://sintixerr.wordpress.com/2011/09/23/842/</link>
		<comments>http://sintixerr.wordpress.com/2011/09/23/842/#comments</comments>
		<pubDate>Fri, 23 Sep 2011 15:36:28 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[CIP]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Washington DC]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[apt]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Control systems]]></category>
		<category><![CDATA[Critical Infrastructure Protection]]></category>
		<category><![CDATA[cyber security conference]]></category>
		<category><![CDATA[federal government]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[national infrastructure protection plan]]></category>
		<category><![CDATA[nipp]]></category>
		<category><![CDATA[outreach]]></category>
		<category><![CDATA[private/public partnership]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[stuxnet]]></category>
		<category><![CDATA[summit]]></category>
		<category><![CDATA[transportation conference]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=842</guid>
		<description><![CDATA[UPDATE: Please use the following link for the current agenda. The one in the post is outdated: http://sintixerr.files.wordpress.com/2011/10/cyber-program_1020.pdf Progress! As you can see below, we&#8217;ve confirmed several additional speakers such as Tony Stramella from the NSA and Steve Carmel from Maersk (who was a fantastic speaker last year &#8211; he talked about his experiences with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=842&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3><span style="color:#800080;">UPDATE: Please use the following link for the current agenda. The one in the post is outdated:</span> <a href="http://sintixerr.files.wordpress.com/2011/10/cyber-program_1020.pdf">http://sintixerr.files.wordpress.com/2011/10/cyber-program_1020.pdf</a></h3>
<p>Progress! As you can see below, we&#8217;ve confirmed several additional speakers such as Tony Stramella from the <a href="http://www.nsa.gov/" target="_blank">NSA</a> and Steve Carmel from Maersk (who was a fantastic speaker last year &#8211; he talked about his experiences with <a href="http://en.wikipedia.org/wiki/Maersk_Alabama_hijacking" target="_blank">maritime piracy and pirates</a>! Did I mention he talked about pirates??).</p>
<p>The Offensive perspective panel (<a href="http://www.theregister.co.uk/2008/09/08/scada_exploit_released/" target="_blank">Kevin Finisterre</a>, <a href="http://reversemode.com" target="_blank">Ruben Santamarta/Reversemode</a>, and hopefully <a href="http://www.sans.org/security-training/instructors/Joshua-Wright" target="_blank">Josh Wright</a>) is going to rock out with some talented vulnerability researchers and <a href="http://www.scmagazineus.com/mark-fabro-president-and-chief-security-scientist-lofty-perch/article/136622/" target="_blank">Mark Fabro </a>will do his always brilliant job of improving the discourse. </p>
<p>We&#8217;ll be excited to hear <a href="http://securityblog.verizonbusiness.com/2010/07/28/2010-dbir-released" target="_blank">Bryan Sartin</a> discuss the past year&#8217;s data breaches and front-line experts in the field let us know how the stuff you&#8217;ve heard in the news might apply to you (<a href="https://www.infosecisland.com/blogview/15675-Infosec-Islands-Scot-Terban-Replaces-Aaron-Barr-at-DEFCON.html" target="_blank">Scot Terban</a>, <a href="http://en.wikipedia.org/wiki/Stuxnet" target="_blank">Liam from Symantec</a>, and the now-short-haired <a href="http://www.scmagazineus.com/adam-meyers-principal-information-assurance-division-sra-international/article/146700/" target="_blank">Adam Meyers</a>). </p>
<p>Boeing and Darryl Song from <a href="http://www.volpe.dot.gov" target="_blank">Volpe</a> are going to dish on transportation-specific concerns, and the CTO of the <a href="http://www.cia.gov" target="_blank">CIA</a> will drive home the need for security to be data-centric. </p>
<p><a href="http://madsecinc.com" target="_blank">Mike Murray</a> will be both entertaining and captivating &#8211; even if I dont know his talk yet &#8211; and <a href="http://meritology.com" target="_blank">Russell Thomas </a>will bring a much needed formal perspective to risk management and cyber security. </p>
<p><a href="http://www.comptia.org/documents/bios/aj_gray.htm" target="_blank">Patrick Gray</a> gives a lightning fast, but insightful presentation on social media, <a href="http://www.pwc.com/en_US/us/public-sector/assets/integrated_governance.pdf" target="_blank">Jack Johnson </a>will help us understand financial issues facing organizations today, and Amit Yoran will talk about&#8230;whatever. He&#8217;s just a smart guy.</p>
<p><strong>Hope you can make it. If you&#8217;re interested in attending, the registration link is here: <a href="http://sintixerr.files.wordpress.com/2011/09/summitinviteandagendan5.pdf">Invitation</a>.</strong></p>
<p>(Please, if you&#8217;re a vendor and plan on selling, we&#8217;ll take a pretty dim view of that at this particular conference. )</p>
<table class="MsoNormalTable" style="width:302pt;border-collapse:collapse;" width="403" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr style="height:12pt;">
<td style="width:302pt;border:solid windowtext 1pt;border-right:solid black 1pt;background:#4F6228;height:12pt;padding:0 5.4pt;" colspan="5" width="403">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;color:white;">November 1</span></p>
</td>
</tr>
<tr style="height:11.25pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:yellow;height:11.25pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Talk</span></strong></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:yellow;height:11.25pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Speaker 1</span></strong></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:yellow;height:11.25pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Speaker 2</span></strong></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:yellow;height:11.25pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Speaker 3</span></strong></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:yellow;height:11.25pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Moderator</span></strong></p>
</td>
</tr>
<tr style="height:42pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#FCD5B4;height:42pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Introductory Remarks</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#FCD5B4;height:42pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Dr. Emma Garrison-Alexander, TSA CIO</span></p>
</td>
<td style="width:177pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#BFBFBF;height:42pt;padding:0 5.4pt;" rowspan="3" colspan="3" width="236">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;"> </span></p>
</td>
</tr>
<tr style="height:31.5pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#FCD5B4;height:31.5pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Keynote</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#FCD5B4;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Anthony Stramella, NSA</span></p>
</td>
</tr>
<tr style="height:42pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#99CCFF;height:42pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Verizon Data Breach Incident Report</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:42pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Bryan Sartin/ Verizon Business</span></p>
</td>
</tr>
<tr style="height:11.25pt;">
<td style="width:302pt;border-top:none;border-left:solid windowtext 1pt;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#F2DDDC;height:11.25pt;padding:0 5.4pt;" colspan="5" width="403">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Break</span></strong></p>
</td>
</tr>
<tr style="height:31.5pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#CCFFCC;height:31.5pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Industry Case Study 1: Boeing</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#CCFFCC;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Mike Garrett/ Boeing</span></p>
</td>
<td style="width:177pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#BFBFBF;height:31.5pt;padding:0 5.4pt;" colspan="3" width="236">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;"> </span></p>
</td>
</tr>
<tr style="height:31.5pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Panel: Offensive Perspectives</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Kevin Finisterre</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Ruben <span class="SpellE">Santamarta</span></span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Josh Wright (Tentative)</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Mark Fabro</span></p>
</td>
</tr>
<tr style="height:11.25pt;">
<td style="width:302pt;border-top:none;border-left:solid windowtext 1pt;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#F2DDDC;height:11.25pt;padding:0 5.4pt;" colspan="5" width="403">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Lunch</span></strong></p>
</td>
</tr>
<tr style="height:21pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#FF99CC;height:21pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Social Media</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#FF99CC;height:21pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Patrick Gray/Cisco</span></p>
</td>
<td style="width:177pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#BFBFBF;height:21pt;padding:0 5.4pt;" colspan="3" width="236">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;"> </span></p>
</td>
</tr>
<tr style="height:42pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#CC99FF;height:42pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Panel: Maritime</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#CC99FF;height:42pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Steve Carmel, <span class="SpellE">Mearsk</span></span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#CC99FF;height:42pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">RDML Robert Day, USCG</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#CC99FF;height:42pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">RADM James Watson, USCG</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#CC99FF;height:42pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">TBD (Speaker)</span></p>
</td>
</tr>
<tr style="height:11.25pt;">
<td style="width:302pt;border-top:none;border-left:solid windowtext 1pt;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#F2DDDC;height:11.25pt;padding:0 5.4pt;" colspan="5" width="403">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Break 1B</span></strong></p>
</td>
</tr>
<tr style="height:42pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#99CCFF;height:42pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Panel: Threats in the News</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:42pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Scot <span class="SpellE">Terban</span><br />
(Anonymous)</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:42pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Liam O <span class="SpellE">Murchu</span><br />
/ Symantec (<span class="SpellE">Stuxnet</span>)</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:42pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Adam Meyers (APT)</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:42pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">TBD/ Industry</span></p>
</td>
</tr>
<tr style="height:53.25pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#CCFFCC;height:53.25pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Industry Case Study 2: Transportation<br />
Control Systems</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#CCFFCC;height:53.25pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Darryl Song/ Volpe</span></p>
</td>
<td style="width:177pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#BFBFBF;height:53.25pt;padding:0 5.4pt;" colspan="3" width="236">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;"> </span></p>
</td>
</tr>
<tr style="height:12pt;">
<td style="width:66pt;height:12pt;padding:0 5.4pt;" width="88"> </td>
<td style="width:59pt;height:12pt;padding:0 5.4pt;" width="79"> </td>
<td style="width:59pt;height:12pt;padding:0 5.4pt;" width="79"> </td>
<td style="width:59pt;height:12pt;padding:0 5.4pt;" width="79"> </td>
<td style="width:59pt;height:12pt;padding:0 5.4pt;" width="79"> </td>
</tr>
<tr style="height:12pt;">
<td style="width:302pt;border:solid windowtext 1pt;border-right:solid black 1pt;background:#4F6228;height:12pt;padding:0 5.4pt;" colspan="5" width="403">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;color:white;">November 2</span></p>
</td>
</tr>
<tr style="height:12pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:yellow;height:12pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Talk</span></strong></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:yellow;height:12pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Speaker 1</span></strong></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:yellow;height:12pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Speaker 2</span></strong></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:yellow;height:12pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Speaker 3</span></strong></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:yellow;height:12pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Moderator</span></strong></p>
</td>
</tr>
<tr style="height:21pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#FCD5B4;height:21pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Introductory Remarks</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#FCD5B4;height:21pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">TBD</span></p>
</td>
<td style="width:177pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#BFBFBF;height:21pt;padding:0 5.4pt;" rowspan="3" colspan="3" width="236">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;"> </span></p>
</td>
</tr>
<tr style="height:42pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#FCD5B4;height:42pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Keynote </span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#FCD5B4;height:42pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Vice Admiral Parker/ USCG</span></p>
</td>
</tr>
<tr style="height:11.25pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#CC99FF;height:11.25pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">DHS CARMA</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#CC99FF;height:11.25pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">TBD</span></p>
</td>
</tr>
<tr style="height:11.25pt;">
<td style="width:302pt;border-top:none;border-left:solid windowtext 1pt;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#F2DDDC;height:11.25pt;padding:0 5.4pt;" colspan="5" width="403">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Break</span></strong></p>
</td>
</tr>
<tr style="height:31.5pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Panel: Executive Perspectives</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Amit <span class="SpellE">Yoran</span>/<br />
<span class="SpellE">Netwitness</span></span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Gus Hunt/CTO of CIA</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">TBD/ Industry</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">TBD/ Industry</span></p>
</td>
</tr>
<tr style="height:52.5pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#CC99FF;height:52.5pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">TSA &amp; DHS Joint Sector<br />
Collaboration</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#CC99FF;height:52.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">TSA Cyber security Awareness &amp;<br />
Outreach Branch</span></p>
</td>
<td style="width:177pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#BFBFBF;height:52.5pt;padding:0 5.4pt;" colspan="3" width="236">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;"> </span></p>
</td>
</tr>
<tr style="height:11.25pt;">
<td style="width:302pt;border-top:none;border-left:solid windowtext 1pt;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#F2DDDC;height:11.25pt;padding:0 5.4pt;" colspan="5" width="403">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Lunch</span></strong></p>
</td>
</tr>
<tr style="height:31.5pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#FF99CC;height:31.5pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Users &amp; Awareness</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#FF99CC;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Mike Murray/MAD Security</span></p>
</td>
<td style="width:177pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#BFBFBF;height:31.5pt;padding:0 5.4pt;" rowspan="2" colspan="3" width="236">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;"> </span></p>
</td>
</tr>
<tr style="height:21pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#CCFFCC;height:21pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Industry Case Study 3: TBD</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#CCFFCC;height:21pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">TBD</span></p>
</td>
</tr>
<tr style="height:11.25pt;">
<td style="width:302pt;border-top:none;border-left:solid windowtext 1pt;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#F2DDDC;height:11.25pt;padding:0 5.4pt;" colspan="5" width="403">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><strong><span style="font-size:8pt;font-family:Verdana,sans-serif;">Break</span></strong></p>
</td>
</tr>
<tr style="height:31.5pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Panel: Risk Management</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Jack Johnson/ PWC</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Russell Thomas</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">TBD/ Industry</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#99CCFF;height:31.5pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Jack Whitsitt</span></p>
</td>
</tr>
<tr style="height:21.75pt;">
<td style="width:66pt;border:solid windowtext 1pt;border-top:none;background:#CCFFCC;height:21.75pt;padding:0 5.4pt;" width="88">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">Industry Case Study 4: TBD</span></p>
</td>
<td style="width:59pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid windowtext 1pt;background:#CCFFCC;height:21.75pt;padding:0 5.4pt;" width="79">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;">TBD</span></p>
</td>
<td style="width:177pt;border-top:none;border-left:none;border-bottom:solid windowtext 1pt;border-right:solid black 1pt;background:#BFBFBF;height:21.75pt;padding:0 5.4pt;" colspan="3" width="236">
<p class="MsoNormal" style="margin-bottom:.0001pt;text-align:center;line-height:normal;" align="center"><span style="font-size:8pt;font-family:Verdana,sans-serif;"> </span></p>
</td>
</tr>
</tbody>
</table>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/cip/'>CIP</a>, <a href='http://sintixerr.wordpress.com/category/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/category/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/category/government/'>government</a>, <a href='http://sintixerr.wordpress.com/category/hacking/'>hacking</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/risk-management/'>risk management</a>, <a href='http://sintixerr.wordpress.com/category/local/washington-dc/'>Washington DC</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/anonymous/'>anonymous</a>, <a href='http://sintixerr.wordpress.com/tag/apt/'>apt</a>, <a href='http://sintixerr.wordpress.com/tag/awareness/'>awareness</a>, <a href='http://sintixerr.wordpress.com/tag/computer-security/'>Computer Security</a>, <a href='http://sintixerr.wordpress.com/tag/control-systems/'>Control systems</a>, <a href='http://sintixerr.wordpress.com/tag/critical-infrastructure-protection/'>Critical Infrastructure Protection</a>, <a href='http://sintixerr.wordpress.com/tag/cyber-security-conference/'>cyber security conference</a>, <a href='http://sintixerr.wordpress.com/tag/federal-government/'>federal government</a>, <a href='http://sintixerr.wordpress.com/tag/hackers/'>hackers</a>, <a href='http://sintixerr.wordpress.com/tag/hacking/'>hacking</a>, <a href='http://sintixerr.wordpress.com/tag/national-infrastructure-protection-plan/'>national infrastructure protection plan</a>, <a href='http://sintixerr.wordpress.com/tag/nipp/'>nipp</a>, <a href='http://sintixerr.wordpress.com/tag/outreach/'>outreach</a>, <a href='http://sintixerr.wordpress.com/tag/privatepublic-partnership/'>private/public partnership</a>, <a href='http://sintixerr.wordpress.com/tag/risk/'>risk</a>, <a href='http://sintixerr.wordpress.com/tag/stuxnet/'>stuxnet</a>, <a href='http://sintixerr.wordpress.com/tag/summit/'>summit</a>, <a href='http://sintixerr.wordpress.com/tag/transportation-conference/'>transportation conference</a>, <a href='http://sintixerr.wordpress.com/tag/vulnerabilities/'>vulnerabilities</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/842/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/842/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/842/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/842/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/842/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/842/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/842/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/842/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/842/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/842/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/842/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/842/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/842/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/842/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=842&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2011/09/23/842/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Cyber Security in Transportation Summit</title>
		<link>http://sintixerr.wordpress.com/2011/09/15/cyber-security-in-transportation-summit/</link>
		<comments>http://sintixerr.wordpress.com/2011/09/15/cyber-security-in-transportation-summit/#comments</comments>
		<pubDate>Thu, 15 Sep 2011 11:37:38 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[conference speaking]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[District of Columbia]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[virginia]]></category>
		<category><![CDATA[Washington DC]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[Cyber Security in Transportation Summit]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[executives]]></category>
		<category><![CDATA[information sharing]]></category>
		<category><![CDATA[nipp]]></category>
		<category><![CDATA[outreach]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=827</guid>
		<description><![CDATA[UPDATE: Please see this link for the most current agenda. The one in the post is outdated: http://sintixerr.files.wordpress.com/2011/10/cyber-program_1020.pdf So, one of the things I get to do as part of my job which has been pretty exciting is to put together the agenda for our 2nd annual Cyber Security in Transportation summit. It&#8217;s happening November 1 &#38; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=827&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3><span style="color:#800080;">UPDATE: Please see this link for the most current agenda. The one in the post is outdated: <a href="http://sintixerr.files.wordpress.com/2011/10/cyber-program_1020.pdf">http://sintixerr.files.wordpress.com/2011/10/cyber-program_1020.pdf</a></span></h3>
<p>So, one of the things I get to do as part of my job which has been pretty exciting is to put together the agenda for our 2nd annual Cyber Security in Transportation summit. It&#8217;s happening November 1 &amp; 2 this year in the DC area and is going to be full of outstanding talks for all ages and backgrounds. ;) The summit is aimed at executives and decision makers from within the transportation industry who might be effected by cyber security or whos actions may affect the security of their organizations. We&#8217;re covering general cyber security themes as well as transportation specific ones. If you&#8217;re in the transportation sector &#8211; pipeline, aviation, freight rail, mass transit, highway &amp; motor carrier &#8211; and want to attend, let me know at <a href="mailto:sintixerr@gmail.com">sintixerr@gmail.com</a>.</p>
<p>The tentative agenda currently looks like this:</p>
<p><strong><span style="font-size:14pt;line-height:115%;font-family:Arial,sans-serif;">Summit Schedule (Click for Larger)</span></strong></p>
<div class="WordSection1">
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:16pt;line-height:115%;font-family:Arial,sans-serif;"> <a href="http://sintixerr.files.wordpress.com/2011/09/cybersectransagenda21.jpg"><img class="alignleft size-medium wp-image-830" title="cybersectransagenda2" src="http://sintixerr.files.wordpress.com/2011/09/cybersectransagenda21.jpg?w=231&#038;h=300" alt="" width="231" height="300" /></a></span></strong></p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"><strong></strong> </p>
<p class="MsoNormalCxSpMiddle"><strong></strong> </p>
<p class="MsoNormalCxSpMiddle"><strong></strong> </p>
<p class="MsoNormalCxSpMiddle"><strong></strong> </p>
<p class="MsoNormalCxSpMiddle"><strong></strong> </p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:16pt;line-height:115%;font-family:Arial,sans-serif;">AGENDA DESCRIPTIONS</span></strong></p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:14pt;line-height:115%;font-family:Arial,sans-serif;">Industry Case Studies </span></strong></p>
<p class="MsoNormalCxSpMiddle"><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Four discussions of transportation-specific cyber security concerns and perspectives: Incidents, Best Practices that worked, Lessons Learned, Soap Box Scenarios , etc. </span><strong></strong></p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:14pt;line-height:115%;font-family:Arial,sans-serif;">Public/Private Partnership </span></strong></p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Sector Collaboration</span></strong></p>
<p class="MsoNormalCxSpMiddle"><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Based on outcomes of this summer’s Transportation Cyber Security Exercise</span></p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Panel: Maritime</span></strong></p>
<p class="MsoNormalCxSpMiddle"><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Representatives of the Maritime mode will discuss  topics of common interest</span></p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">TBD DHS</span></strong></p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:14pt;line-height:115%;font-family:Arial,sans-serif;">General Cyber Security Awareness Talks &amp; Panels</span></strong></p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Panel: Offensive Perspectives</span></strong></p>
<p class="MsoNormalCxSpMiddle"><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Non-technical perspectives from well-known offensive researchers</span></p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Panel: Threats in the News</span></strong></p>
<p class="MsoNormalCxSpMiddle"><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Current threats in the news such as APT, <span class="SpellE">Stuxnet</span>, and Anonymous</span></p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Panel: Executive Perspectives</span></strong></p>
<p class="MsoNormalCxSpMiddle"><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Concerns and solutions in today’s environments</span></p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Panel: Risk Management</span></strong></p>
<p class="MsoNormalCxSpMiddle"><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Cybersecurity impacts on business risk management</span></p>
<p class="MsoNormalCxSpMiddle"> </p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Verizon Data Breach Incident Report</span></strong></p>
<p class="MsoNormalCxSpMiddle"><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">An empirical overview of current trends</span></p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Social Networking</span></strong></p>
<p class="MsoNormalCxSpMiddle"><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Ups, downs, concerns and impacts of social networking on cyber security</span></p>
<p class="MsoNormalCxSpMiddle"><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Users and Awareness</span></strong></p>
<p class="MsoNormalCxSpMiddle"><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Exploration of the most critical aspect of cyber security: Users</span></p>
<p><strong><span style="font-size:12pt;line-height:115%;font-family:Arial,sans-serif;"> </span></strong><strong></strong><span style="color:#ffffff;"><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;">Verizon Data Breach Incident Report: Bryan Sartin/Verizon Business   <br />
Industry Case Study 1: Boeing Mike Garrett/Boeing   <br />
Panel: Offensive Perspectives: Kevin Finisterre Ruben Santamarta  Mark Fabro<br />
Social Media: Patrick Gray/CISCO   <br />
Panel: Maritime Stakeholders  (USCG &amp; Industry)   <br />
Panel: Threats in the News: Scot Terban (Anonymous) Liam O Murchu / Symantec (Stuxnet)  (APT) <br />
Industry Case Study 2: Transportation Control Systems Darryl Song/Volpe   <br />
Keynote:  Vice Admiral Parker/ USCG   <br />
DHS     <br />
Panel: Executive Perspectives: Amit Yoran/Netwitness Gus Hunt/CTO of CIA  <br />
Sector Collaboration   <br />
Users &amp; Awareness Mike Murray/MAD Security      <br />
Panel: Risk Management Jack Johnson/PWC Russell Thomas  Jack Whitsitt</span></strong></span><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;"> </span></strong><strong><span style="font-size:10pt;line-height:115%;font-family:Arial,sans-serif;"> </span></strong></p>
</div>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/conference-speaking/'>conference speaking</a>, <a href='http://sintixerr.wordpress.com/category/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/category/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/category/local/district-of-columbia/'>District of Columbia</a>, <a href='http://sintixerr.wordpress.com/category/art/events/'>Events</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/risk-management/'>risk management</a>, <a href='http://sintixerr.wordpress.com/category/local/virginia/'>virginia</a>, <a href='http://sintixerr.wordpress.com/category/local/washington-dc/'>Washington DC</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/2011/'>2011</a>, <a href='http://sintixerr.wordpress.com/tag/awareness/'>awareness</a>, <a href='http://sintixerr.wordpress.com/tag/conference/'>conference</a>, <a href='http://sintixerr.wordpress.com/tag/cyber-security-in-transportation-summit/'>Cyber Security in Transportation Summit</a>, <a href='http://sintixerr.wordpress.com/tag/cybersecurity/'>cybersecurity</a>, <a href='http://sintixerr.wordpress.com/tag/executives/'>executives</a>, <a href='http://sintixerr.wordpress.com/tag/information-sharing/'>information sharing</a>, <a href='http://sintixerr.wordpress.com/tag/nipp/'>nipp</a>, <a href='http://sintixerr.wordpress.com/tag/outreach/'>outreach</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/827/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/827/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/827/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/827/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/827/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/827/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/827/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/827/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/827/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/827/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/827/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/827/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/827/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/827/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=827&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2011/09/15/cyber-security-in-transportation-summit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>

		<media:content url="http://sintixerr.files.wordpress.com/2011/09/cybersectransagenda21.jpg?w=231" medium="image">
			<media:title type="html">cybersectransagenda2</media:title>
		</media:content>
	</item>
		<item>
		<title>NATO-Georgia conference on Emerging Security Challenges : My Talk and Thoughts</title>
		<link>http://sintixerr.wordpress.com/2011/07/11/nato-georgia-conference-on-emerging-security-challenges-my-talk-and-thoughts/</link>
		<comments>http://sintixerr.wordpress.com/2011/07/11/nato-georgia-conference-on-emerging-security-challenges-my-talk-and-thoughts/#comments</comments>
		<pubDate>Mon, 11 Jul 2011 12:57:46 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[conference speaking]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[foreign travel]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Awareness as a Vulnerability]]></category>
		<category><![CDATA[Energy Security]]></category>
		<category><![CDATA[Georgia]]></category>
		<category><![CDATA[Klimburg]]></category>
		<category><![CDATA[NATO]]></category>
		<category><![CDATA[Tbilisi]]></category>
		<category><![CDATA[Whitsitt]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=812</guid>
		<description><![CDATA[Recently, I was invited to speak on a panel in Tbilisi, Georgia at a NATO-Georgia Conference on Emerging Security Challenges put on by the NATO Energy Security Section, Emerging Security Challenges Division.  The topic was Energy Security, including Cyber Threats to Infrastructure (Moderated by Mr. Michael Rühle, Head, Energy Security Section, Emerging Security Challenges Division, NATO). [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=812&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Recently, I was invited to speak on a panel in <a href="http://en.wikipedia.org/wiki/Tbilisi" target="_blank">Tbilisi, Georgia</a> at a <a href="http://www.nato.int/cps/en/natolive/index.htm" target="_blank">NATO</a>-Georgia Conference on Emerging Security Challenges put on by the NATO Energy Security Section, <a href="http://www.nato.int/cps/en/natolive/news_65107.htm" target="_blank">Emerging Security Challenges Division</a>.  The topic was <strong>Energy Security, including Cyber Threats to Infrastructure</strong> (Moderated by Mr. Michael Rühle, Head, Energy Security Section, Emerging Security Challenges Division, NATO).</p>
<p>You can find a copy of my presentation here: <a href="http://sintixerr.files.wordpress.com/2011/07/natotbilisiswhitsitt.pptx">http://sintixerr.files.wordpress.com/2011/07/natotbilisiswhitsitt.pptx</a> </p>
<p>When writing &#8211; and delivering the presentation &#8211; I found it difficult to support both the scope of the panel as described &#8211; Energy Specific SCADA threats/vulnerabilities &#8211; while at the same time meeting the audience&#8217;s need for a higher level view of the problem.  I definitely need to work more on bridging the gap between the technical realities of what we do and the knowledge/perspective of policy makers&#8230;but that was always going to be hard&#8230;if it was easy, it would happen more often. :)</p>
<p>As for the rest of the conference, there were a number of presentations given, but I was most impressed by <a href="http://www.oiip.ac.at/index.php?id=15&amp;no_cache=1&amp;tx_wecstaffdirectory_pi1%5Bcurstaff%5D=17&amp;L=1" target="_blank">Alexander Klimburg&#8217;s </a>take. He spoke about the intersection between attribution difficulties in cyber space and recent talk about kinetic response to attacks by nation states. Policy discussions seem to be moving, according to Alexander, in a direction which results in rapid, somewhat automated, escalation of hostilities between nations in the event of a cyber attack which seems to have come from another nation.  With the confidence in attribution being as low as it is &#8211; and with such a high probability of non-state actors being involved &#8211; this type of escalation becomes probablematic and ill-advised. Alexander&#8217;s talk proposed creating confidence building measures between states and non-state cyber attack actors, building in enough of a policy buffer to allow thoughtful responses to attacks, and having the media &#8220;name and shame&#8221; attackers where confidence isn&#8217;t 100% as a deterrent.</p>
<p>I don&#8217;t completely agree with all of the details, but philosophically, I think he was on point. </p>
<p>What I also found interesting about the conference was that the same conclusions were drawn at the end of this conference that are drawn at the end of every other cyber conference:</p>
<ul>
<li>More information sharing is needed</li>
<li>Public/Private Partnerships are important and difficult</li>
<li>Cyber is a real threat</li>
<li>Large organizations can help solve some, but not all problems in cyber security</li>
<li>There needs to be clearer definition of roles and responsibilities</li>
</ul>
<p>Someone in the audience rightly asked: &#8220;Yes, that all is obvious, but how do we do it?&#8221;</p>
<p>That&#8217;s a perfect question, and one I ask constantly.  I&#8217;ll say again: You can&#8217;t just say &#8220;cyber security is a problem&#8221; and expect to implement a plan to solve it; you can only speculate as to what types of efforts might be involved.  The problem needs to be defined in a much more structured, specific manner than we have so far (in my mind, using threat models which link risks to strategic business objectives from cyber systems to tactical risks to those cyber systems&#8230;at some point I&#8217;ll post a model for that here).</p>
<p>That all said, the trip was fantastic:</p>
<p>My NATO and Georgian hosts were gracious, professional, and intelligent. The locals were a lo of fun &#8211; I spent one evening with three random Tbilisians (one cute bartender, a guy who claimed to be a male model and was explaining the story of the city&#8217;s founding in broken english and by waving his arms up and down like a giant bird, and a US expat helping to start a lab). The country was beautiful; I particularly loved some of the crypts on the floor of a church in <a href="http://en.wikipedia.org/wiki/Mtskheta" target="_blank">Mtskheta</a> (the script was beautiful&#8230;I suggest checking out Georgian writing).</p>
<p>Thanks to Julijus for inviting me to speak. I was very grateful for the opportunity.</p>
<p>&nbsp;</p>
<p><span style="color:#ff0000;">(Edit: This is a pretty rough draft of this blog post. It may change significantly and I want to add many more thoughts, but I wanted to get it out before it became OBE.)</span></p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/conference-speaking/'>conference speaking</a>, <a href='http://sintixerr.wordpress.com/category/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/category/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/category/foreign-travel/'>foreign travel</a>, <a href='http://sintixerr.wordpress.com/category/government/'>government</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/risk/'>risk</a>, <a href='http://sintixerr.wordpress.com/category/risk-management/'>risk management</a>, <a href='http://sintixerr.wordpress.com/category/scada/'>SCADA</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/awareness-as-a-vulnerability/'>Awareness as a Vulnerability</a>, <a href='http://sintixerr.wordpress.com/tag/energy-security/'>Energy Security</a>, <a href='http://sintixerr.wordpress.com/tag/georgia/'>Georgia</a>, <a href='http://sintixerr.wordpress.com/tag/klimburg/'>Klimburg</a>, <a href='http://sintixerr.wordpress.com/tag/nato/'>NATO</a>, <a href='http://sintixerr.wordpress.com/tag/tbilisi/'>Tbilisi</a>, <a href='http://sintixerr.wordpress.com/tag/whitsitt/'>Whitsitt</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/812/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/812/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/812/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/812/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/812/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/812/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/812/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/812/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/812/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/812/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/812/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/812/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/812/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/812/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=812&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2011/07/11/nato-georgia-conference-on-emerging-security-challenges-my-talk-and-thoughts/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Error, Will Robinson, Error: Implications of Rate vs Instance in Cyber Security</title>
		<link>http://sintixerr.wordpress.com/2011/04/03/error-will-robinson-error-implications-of-rate-vs-instance-in-cyber-security/</link>
		<comments>http://sintixerr.wordpress.com/2011/04/03/error-will-robinson-error-implications-of-rate-vs-instance-in-cyber-security/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 18:49:16 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[CIP]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Enterprise Security Architecture]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[error rates]]></category>
		<category><![CDATA[fixing security]]></category>
		<category><![CDATA[national cyber security]]></category>
		<category><![CDATA[rate reduction]]></category>
		<category><![CDATA[strategy]]></category>
		<category><![CDATA[sustainable improvements]]></category>
		<category><![CDATA[time based security]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=771</guid>
		<description><![CDATA[(More mature thoughts on RDOSing&#8230;) If you have one error, you fix it and move on. If you have the same error again, you fix it &#8220;better&#8221; and move on. But if you keep having a variety of errors at a steady or increasing rate, you stop looking at the causes of individual errors and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=771&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em>(More mature thoughts on RDOSing&#8230;)</em></p>
<p>If you have one error, you fix it and move on.</p>
<p>If you have the same error again, you fix it &#8220;better&#8221; and move on.</p>
<p>But if you keep having a variety of errors at a steady or increasing rate, you stop looking at the causes of individual errors and look at your basic business practices.</p>
<p>Cyber Security problems are errors. Cyber Security problems are systems or data doing things their owners and society do not with them to do.</p>
<p>Cyber Security errors keep occurring despite being fixed individually.</p>
<p>New types of cyber security errors are occurring over time as new systems are built, as data changes, and as new use cases develop.</p>
<p>By the time we fix our past errors, we’ve created new ones.</p>
<p>Let’s stop focusing national and organizational programs on fixing individual cyber security errors  &#8211; or even fixing common classes of cyber security errors.</p>
<p>Instead, let’s focus on reducing cyber security error rates in general.</p>
<p>To reduce the rate of cyber security errors, non-cyber specific business practices must be evaluated to determine where cyber security errors are being introduced.</p>
<p><strong>Hmm. This sounds a lot like business management and quality control, not cyber. </strong></p>
<p><strong>Yes, it does.</strong></p>
<p>Tackling individual cyber security errors in our critical infrastructure without reducing error rates will assure failure.</p>
<p>Tackling error rates will create long term, sustainable success by freeing up the vast, unnecessary number of resources we&#8217;ve allocated to individual problems to better use through the reduction of the number of errors which have to be dealt with in the first place.</p>
<p>Stop wasting so many resources. :)</p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/cip/'>CIP</a>, <a href='http://sintixerr.wordpress.com/category/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/category/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/category/enterprise-security-architecture/'>Enterprise Security Architecture</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/risk/'>risk</a>, <a href='http://sintixerr.wordpress.com/category/risk-management/'>risk management</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/tag/error-rates/'>error rates</a>, <a href='http://sintixerr.wordpress.com/tag/fixing-security/'>fixing security</a>, <a href='http://sintixerr.wordpress.com/tag/national-cyber-security/'>national cyber security</a>, <a href='http://sintixerr.wordpress.com/tag/rate-reduction/'>rate reduction</a>, <a href='http://sintixerr.wordpress.com/tag/strategy/'>strategy</a>, <a href='http://sintixerr.wordpress.com/tag/sustainable-improvements/'>sustainable improvements</a>, <a href='http://sintixerr.wordpress.com/tag/time-based-security/'>time based security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/771/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/771/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/771/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/771/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/771/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/771/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/771/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/771/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/771/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/771/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/771/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/771/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/771/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/771/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=771&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2011/04/03/error-will-robinson-error-implications-of-rate-vs-instance-in-cyber-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Why Normal People Skip Cyber Security Talks &amp; How to Make Them Better</title>
		<link>http://sintixerr.wordpress.com/2011/02/12/why-normal-people-skip-cyber-security-talks-how-to-make-them-better/</link>
		<comments>http://sintixerr.wordpress.com/2011/02/12/why-normal-people-skip-cyber-security-talks-how-to-make-them-better/#comments</comments>
		<pubDate>Sat, 12 Feb 2011 17:04:49 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[CIP]]></category>
		<category><![CDATA[conference speaking]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[delivery]]></category>
		<category><![CDATA[hacker conferences]]></category>
		<category><![CDATA[hints]]></category>
		<category><![CDATA[normal people]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=757</guid>
		<description><![CDATA[Some friends of mine were recently speaking on a cyber security panel at a non-computer-geek conference. While they got a higher than expected number of attendees, it was still lower than they would have liked. While watching some of the other panelists crash, burn, and then bury themselves at the center of the earth, they came [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=757&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Some friends of mine were recently speaking on a cyber security panel at a non-computer-geek conference. While they got a higher than expected number of attendees, it was still lower than they would have liked. While watching some of the other panelists crash, burn, and then bury themselves at the center of the earth, they came up with a list of pointers for making cyber security talks more palatable based on specific failures they saw (whether humorous or serious). They were off-the-cuff, but I thought they make up a good list. This is part 1. Comments? Thoughts? Additions? :)</p>
<ol>
<li>Talking over your audience’s head is mean.  No one cares how smart you are unless you can make them just as smart on your topic in 20 minutes or less. <strong></strong></li>
<li>Speaking of 20 minutes. Stay on the time clock. Wasting 15 minutes of someone else&#8217;s time is presumptuous and rude.<strong></strong></li>
<li>Having a Slide Extravaganza doesn&#8217;t make you a good presenter.  Slides are talking points, nothing more. By the 98<sup>th</sup> slide, your audience will hate you.<strong></strong></li>
<li>Engage. If people opt to read their horoscope on their l33t Droids rather than watching you in person, your presentation sucks.<strong></strong></li>
<li>Tone. If you have a terrible voice, amplifying it on a  microphone is just plain mean. Record yourself ahead of time and listen to it. Adjust accordingly. <strong></strong></li>
<li>Hair Matters. <strong></strong></li>
<li>Thanking everyone for thanking the thank you people gets redundant. Appreciation is one thing &#8211; but it&#8217;s not the academy awards.    <strong></strong></li>
<li>Pick one point. Maybe two. Not 438. Your audience is not Neo. They will not be able to learn Kung Fu<strong></strong></li>
<li>Relevance. Know the audience and have a backup plan if no one can relate to what you&#8217;re talking about. Otherwise, you&#8217;re just filling space.<strong></strong></li>
<li>Smile. If it’s supposed to be a joke and you frown, your audience might not get the cue to laugh<strong></strong></li>
<li>If you smile while you make a joke, and the audience still doesn’t laugh, see “know the audience” (or &#8220;talking over your audience&#8217;s head&#8221;).<strong></strong></li>
<li>Look nice. There are enough cave trolls in the audience. Give people something better to look at.<strong></strong></li>
<li>Be a wingman. If one of your colleagues is getting ogled by above-mentioned cave troll &#8211; be sure to intervene on her behalf. Especially if the cave troll is of unspecified gender<strong></strong></li>
<li>Don&#8217;t let friends sit in the back row and make you laugh unless they’re part of your shtick. Especially on a panel when it’s not your turn.<strong></strong></li>
<li>Bring pillows. If you&#8217;re going to put people to sleep, they may as well be comfortable.<br />
    <strong></strong></li>
</ol>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/cip/'>CIP</a>, <a href='http://sintixerr.wordpress.com/category/conference-speaking/'>conference speaking</a>, <a href='http://sintixerr.wordpress.com/category/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/category/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/professional/'>Professional</a>, <a href='http://sintixerr.wordpress.com/category/security/'>security</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/tag/delivery/'>delivery</a>, <a href='http://sintixerr.wordpress.com/tag/hacker-conferences/'>hacker conferences</a>, <a href='http://sintixerr.wordpress.com/tag/hints/'>hints</a>, <a href='http://sintixerr.wordpress.com/tag/normal-people/'>normal people</a>, <a href='http://sintixerr.wordpress.com/tag/presentation/'>presentation</a>, <a href='http://sintixerr.wordpress.com/tag/speaking/'>speaking</a>, <a href='http://sintixerr.wordpress.com/tag/technology/'>technology</a>, <a href='http://sintixerr.wordpress.com/tag/tips/'>tips</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/757/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/757/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/757/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/757/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/757/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/757/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/757/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/757/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/757/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/757/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/757/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/757/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/757/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/757/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=757&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2011/02/12/why-normal-people-skip-cyber-security-talks-how-to-make-them-better/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Follow-up: Ender&#8217;s Shadow Describes RDoS&#8217;ing</title>
		<link>http://sintixerr.wordpress.com/2010/08/29/follow-up-enders-shadow-describes-rdosing/</link>
		<comments>http://sintixerr.wordpress.com/2010/08/29/follow-up-enders-shadow-describes-rdosing/#comments</comments>
		<pubDate>Mon, 30 Aug 2010 04:28:51 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[CIP]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Enterprise Security Architecture]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Critical Infrastructure Protection]]></category>
		<category><![CDATA[ender's game]]></category>
		<category><![CDATA[failure]]></category>
		<category><![CDATA[HSPD-7]]></category>
		<category><![CDATA[nipp]]></category>
		<category><![CDATA[orson scott card]]></category>
		<category><![CDATA[parable]]></category>
		<category><![CDATA[responder denial of service]]></category>
		<category><![CDATA[sci-fi]]></category>
		<category><![CDATA[science fiction]]></category>
		<category><![CDATA[strategy]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=735</guid>
		<description><![CDATA[Growing up, a lot of my sci-fi reading focused on old classic works by Asimov, Clarke, Heinlein, Campbell, Pohl, etc. For some reason, I missed the 80&#8242;s almost completely. Specifically, I missed Ender&#8217;s Game until just this past month. So, I&#8217;ve been catching up. As of tonight, I&#8217;ve just finished &#8220;Ender&#8217;s Shadow&#8221;. My thoughts on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=735&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Growing up, a lot of my sci-fi reading focused on old classic works by Asimov, Clarke, Heinlein, <a href="http://en.wikipedia.org/wiki/John_W._Campbell" target="_blank">Campbell</a>, <a href="http://www.fantasticfiction.co.uk/p/frederik-pohl/gold-at-starbows-end.htm" target="_blank">Pohl</a>, etc. For some reason, I missed the 80&#8242;s almost completely. Specifically, I missed <a href="http://www.amazon.com/Enders-Game-Ender-Book-1/dp/0812550706" target="_blank">Ender&#8217;s Game</a> until just this past month. So, I&#8217;ve been catching up. As of tonight, I&#8217;ve just finished &#8220;Ender&#8217;s Shadow&#8221;. My thoughts on the book (and series) overall are beyond the scope of this blog, but there was a series of passages early on that I think resonate closely with my <a href="http://sintixerr.wordpress.com/2010/08/05/were-being-rdosd-responder-denial-of-service-wheres-the-product-for-that/" target="_blank">last post here</a>, and with my overall feeling that we need a real strategy for changing the odds on the cyber security playing field altogether instead of just building up defenses linearly. Let me know if you agree?</p>
<blockquote><p><span style="color:#000000;"><br />
<span style="color:#000000;">“He could come from anywhere &#8211; from anywhere all at once. So we run into the classic problem of defense, cubed. The farther out you deploy your defenses, the more of them you have to have, and if your resources are limited, you soon have more fortifications than you can man. What good are based on moons, Jupiter, or Saturn, or Neptune, when the enemy doesn’t even have to come in on the plane of the ecliptic? He can bypass all our fortifications. The way Nimitz and MacArthur used two-dimensional island-hopping against the defense in depth of the Japanese in WWII. Only our enemy can work in three dimensions. Therefore we cannot possibly maintain defense in depth..”</span></span></p>
<p><span style="color:#000000;">“So even if we intercept 99 of 100 attacking squadrons, he only has to get one squadron through to cause terrible destruction.  We saw how much territory a single ship could scour when they first showed up.  Get ten ships to us for a single day, and if they spread us out enough, they’d have a lot more than a day and they would wipe out our most important centers. “</span></p>
<p><span style="color:#000000;">“I don’t think there is a solution. There is no point in trying to defend at all. So the only strategy that makes any sense at all is an all-out attack.”</span></p></blockquote>
<p>I&#8217;ll let you all think through the implications of these passages and get back to me.</p>
<p>On another, related, topic, I have a question: A lot of us are quick to reference Sun Tzu&#8217;s Art of War in cyber security, but I havent seen (or havent recognized &#8211; I  might just be ignorant here) many attempts to use known historic, strategic war/battle thinkers in our industry much beyond Sun. Is there anything else &#8211; or anyone else &#8211; we should be looking at from a classic &#8220;war&#8221; perspective that we&#8217;re not already? Who? Why? Who/What am I missing? Is it relevant to ask?</p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/cip/'>CIP</a>, <a href='http://sintixerr.wordpress.com/category/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/category/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/category/enterprise-security-architecture/'>Enterprise Security Architecture</a>, <a href='http://sintixerr.wordpress.com/category/hacking/'>hacking</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/risk-management/'>risk management</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/critical-infrastructure-protection/'>Critical Infrastructure Protection</a>, <a href='http://sintixerr.wordpress.com/tag/enders-game/'>ender's game</a>, <a href='http://sintixerr.wordpress.com/tag/failure/'>failure</a>, <a href='http://sintixerr.wordpress.com/tag/hspd-7/'>HSPD-7</a>, <a href='http://sintixerr.wordpress.com/tag/nipp/'>nipp</a>, <a href='http://sintixerr.wordpress.com/tag/orson-scott-card/'>orson scott card</a>, <a href='http://sintixerr.wordpress.com/tag/parable/'>parable</a>, <a href='http://sintixerr.wordpress.com/tag/responder-denial-of-service/'>responder denial of service</a>, <a href='http://sintixerr.wordpress.com/tag/sci-fi/'>sci-fi</a>, <a href='http://sintixerr.wordpress.com/tag/science-fiction/'>science fiction</a>, <a href='http://sintixerr.wordpress.com/tag/strategy/'>strategy</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/735/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/735/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/735/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/735/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/735/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/735/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/735/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/735/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/735/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/735/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/735/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/735/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/735/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/735/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=735&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/08/29/follow-up-enders-shadow-describes-rdosing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>We&#8217;re being RDoS&#8217;d! (Responder Denial of Service) Where&#8217;s the product for that?</title>
		<link>http://sintixerr.wordpress.com/2010/08/05/were-being-rdosd-responder-denial-of-service-wheres-the-product-for-that/</link>
		<comments>http://sintixerr.wordpress.com/2010/08/05/were-being-rdosd-responder-denial-of-service-wheres-the-product-for-that/#comments</comments>
		<pubDate>Thu, 05 Aug 2010 19:12:39 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[business architecture]]></category>
		<category><![CDATA[CIP]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Enterprise Architecture]]></category>
		<category><![CDATA[Enterprise Security Architecture]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[bad security]]></category>
		<category><![CDATA[cert]]></category>
		<category><![CDATA[denial of service]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[ORM]]></category>
		<category><![CDATA[perimeter]]></category>
		<category><![CDATA[rant]]></category>
		<category><![CDATA[RDOS]]></category>
		<category><![CDATA[responder denial of service]]></category>
		<category><![CDATA[security architecture]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=727</guid>
		<description><![CDATA[Earlier this week, I started back up at TSA supporting their private sector critical infrastructure responsibilities under HSPD-7 and the NIPP.  Being new (well, new again), I just had to get on some of my recurring soap boxes.  One of them was our doomed-to-failure to security approaches.  (Nice to start off on an optimistic foot [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=727&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Earlier this week, I started back up at TSA supporting their private sector critical infrastructure responsibilities under HSPD-7 and the NIPP.  Being new (well, new again), I just had to get on some of my recurring soap boxes.  One of them was our doomed-to-failure to security approaches.  (Nice to start off on an optimistic foot yeh?)  Pretty soon, the conversation narrowed down to the role of CERTs and incident response. In the middle of trying to explain how sending a bunch of guys in trenches to combat an enemy who could nuke from thousands of miles away was a waste of time, I had a revelation: The &#8220;bad guys&#8221;, with complete cooperation with the &#8220;good guys&#8221;, are creating a denial of service condition across the country and planet:<strong> a Responder Denial of Service &#8211; or, an &#8220;RDOS&#8221;.</strong></p>
<p>What exactly is an RDoS? It works a lot like a syn-flood, which spins up a whole lot of blank connection attempts to a server. The server must receive these connections, wait for awhile to see if valid data arrives, then close them. The thing is, because the sender knows the connections are blank (and using things like botnets and such), it can generate a lot more connection attempts than the server can handle. Eventually, the server gets so busy that it fails to respond to real connections.</p>
<p>Now, think of how we handle &#8220;security&#8221;.  We religiously and studiously avoid building hardened, defensible systems from the ground up and rely on fixes, patches, and incident responders to cope with the eventual problems later (hoping all the while &#8211; in vain &#8211; that the attacks never come).</p>
<p>What we end up with, by and large, are systems that are so poorly constructed that it takes a large amount of effort to detect, confirm, respond to, and recover from attacks.  Further, while attackers can fairly easily attack multiple systems simultaneously, we require dedicated defenders/responses for much smaller groups of systems (or even individual systems).  This leaves us with an &#8220;RDoS&#8221;. Our security philosophies leave so much open that we can never, ever sufficiently resource our defenses at an adequate level. Everyone is occupied. Just ask your incident response vendors, teams, and CERT&#8217;s (over beers, of course), about their available resources vs the demand for their services, vs the large iceberg of incidents under the water that aren&#8217;t even talked about yet.</p>
<p>As I&#8217;ve said before: Good guys &#8211; you, we, have failed and will continue to fail if we keep going down this same road.  We can&#8217;t win until we change strategies completely. We need to embrace our failure and build systems which are defensible from the inside, which are measurably effective against operational/business objectives,  and which assume, from the get go, that sections and components have, are, and will continue  to be compromised. This hacking perimeters on, giving lip service to change control, and our complete inability to integrate cyber into our ORM and our ORM into our business decision making is a waste of time and resources. We&#8217;d be better off spending the money and time elsewhere if we&#8217;re going to keep doing security as badly as we do it now.</p>
<p>If anyone disagrees with this post, I&#8217;d LOVE to hear a rational argument as to why. (Really!)</p>
<p><strong>(UPDATE: 08/06/10)</strong></p>
<p>I really think some of <a href="http://www.shmoo.com/~gdead/Site/Home.html" target="_blank">Bruce Potter&#8217;s</a> <a href="http://www.infosecblog.org/2009/02/shmoocon-2009-day-1/" target="_blank">remarks</a> at <a href="http://www.shmoocon.org/index.php" target="_blank">Shmoocon</a> in 2009 are pertinent here:</p>
<blockquote><p><span style="color:#993366;"><em>People are getting owned <span style="text-decoration:underline;">a lot</span>.<br />
<span style="text-decoration:underline;">Trends</span></em></span></p>
<ul>
<li><span style="color:#993366;"><em>Increased success in getting past our defenses</em></span></li>
<li><span style="color:#993366;"><em>Increasingly malicious motivations.   The bad guys aren’t after web  defacements</em></span></li>
<li><span style="color:#993366;"><em>In spite of the above, we haven’t changed our methods.   Its a lot  of the same</em></span></li>
<li><span style="color:#993366;"><em>Spear phishing and drive-bys are unabated.</em></span></li>
</ul>
<p><span style="color:#993366;"><em>What we have is a Maginot line…in depth<br />
Of 66 million websites indexed by Google, 5 percent had drivebys.<br />
These sites with drivebys weren’t just the risky underbelly of the web.   It was every category of website.   I don’t think that is surprising to  anyone who has paid attention to security.<br />
These findings were <a href="http://usenix.org/events/sec08/tech/provos.html">published last  year in in USENIX</a>.<br />
The malicious content on these sites was then scanned using three top  Antivirus vendors.   The best detection rate among these three vendors  was only 75%.   The worst was 30%.  These are untargeted attacks.   Imagine the ability of an attack targeted at your organization to cut  through your antivirus defenses.<br />
<span style="text-decoration:underline;">So What do you do?</span></em><em><br />
NAC?    Most people don’t have that deployed even if they’ve bought it.<br />
Firewall Internally?<br />
Token authentication?<br />
Change jobs?</em></span></p></blockquote>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/business-architecture/'>business architecture</a>, <a href='http://sintixerr.wordpress.com/category/cip/'>CIP</a>, <a href='http://sintixerr.wordpress.com/category/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/category/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/category/enterprise-architecture/'>Enterprise Architecture</a>, <a href='http://sintixerr.wordpress.com/category/enterprise-security-architecture/'>Enterprise Security Architecture</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/professional/network-security/'>Network Security</a>, <a href='http://sintixerr.wordpress.com/category/risk-management/'>risk management</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/bad-security/'>bad security</a>, <a href='http://sintixerr.wordpress.com/tag/cert/'>cert</a>, <a href='http://sintixerr.wordpress.com/tag/denial-of-service/'>denial of service</a>, <a href='http://sintixerr.wordpress.com/tag/dos/'>DOS</a>, <a href='http://sintixerr.wordpress.com/tag/incident-response/'>Incident Response</a>, <a href='http://sintixerr.wordpress.com/tag/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/tag/orm/'>ORM</a>, <a href='http://sintixerr.wordpress.com/tag/perimeter/'>perimeter</a>, <a href='http://sintixerr.wordpress.com/tag/rant/'>rant</a>, <a href='http://sintixerr.wordpress.com/tag/rdos/'>RDOS</a>, <a href='http://sintixerr.wordpress.com/tag/responder-denial-of-service/'>responder denial of service</a>, <a href='http://sintixerr.wordpress.com/tag/risk-management/'>risk management</a>, <a href='http://sintixerr.wordpress.com/tag/security-architecture/'>security architecture</a>, <a href='http://sintixerr.wordpress.com/tag/vulnerability-management/'>vulnerability management</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/727/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/727/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/727/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/727/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/727/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/727/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/727/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/727/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/727/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/727/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/727/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/727/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/727/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/727/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=727&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/08/05/were-being-rdosd-responder-denial-of-service-wheres-the-product-for-that/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Open Source Neurosky Mindset Server, Quartz Composer Client, and Tutorial</title>
		<link>http://sintixerr.wordpress.com/2010/07/26/open-source-neurosky-mindset-server-quartz-composer-client-and-tutorial/</link>
		<comments>http://sintixerr.wordpress.com/2010/07/26/open-source-neurosky-mindset-server-quartz-composer-client-and-tutorial/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 00:06:24 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA["Quartz Composer"]]></category>
		<category><![CDATA[art]]></category>
		<category><![CDATA[artist]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[information visualization]]></category>
		<category><![CDATA[objective-c]]></category>
		<category><![CDATA[Open-source]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[artwork]]></category>
		<category><![CDATA[bio-feedback]]></category>
		<category><![CDATA[brain]]></category>
		<category><![CDATA[brain waves]]></category>
		<category><![CDATA[client]]></category>
		<category><![CDATA[cocoa]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[demo]]></category>
		<category><![CDATA[example]]></category>
		<category><![CDATA[mind]]></category>
		<category><![CDATA[mindset]]></category>
		<category><![CDATA[neurosky]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[tutorial]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=707</guid>
		<description><![CDATA[Per previous posts, I am making some free software available here (although it’s somewhat niche): A Mac OS X Distributed Objects server for the Neurosky brain wave reading Mindset and a Quartz Composer plug-in client for the server. (If you have neither OS X nor the Mindset, you might want to wait for a future [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=707&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Per previous posts, I am making some free software available here (although it’s somewhat niche): A Mac OS X <a href="http://developer.apple.com/mac/library/documentation/Cocoa/Conceptual/DistrObjects/DistrObjects.html" target="_blank">Distributed Objects</a> server for the <a href="http://neurosky.com" target="_blank">Neurosky</a> brain wave reading <a href="http://gizmodo.com/5184287/neurosky-mindset-hands+on-brainwave-gameplay" target="_blank">Mindset</a> and a <a href="http://en.wikipedia.org/wiki/Quartz_Composer" target="_blank">Quartz Composer</a> plug-in client for the server. (If you have neither OS X nor the Mindset, you might want to wait for a future post where I talk more about how the brain wave art project is coming.)</p>
<p>This post will also serve as a brief introduction to what it would take for you to write your own Cocoa client for the server. But, If you just want the software, you can get it here:</p>
<ul>
<li><a href="http://jackwhitsitt.com/mindset/MindsetServerApp.zip">Server Application</a> (and <a href="http://jackwhitsitt.com/mindset/MindsetServer_Src.zip">source code / Xcode Project</a>)</li>
<li><a href="http://jackwhitsitt.com/mindset/MindSetQCClientplugin.zip">Quartz Composer Plug-In Client</a> (and <a href="http://jackwhitsitt.com/mindset/MindSetQCClientPlugIn_Src.zip">source code / Xcode Project</a>)</li>
</ul>
<p>Notes:</p>
<ul>
<li>To install the client for Quartz Composer, close QC and copy the .plugin file to: <em>&#8220;/Library/Graphics/Quartz Composer Plugins&#8221;.</em> When you next open QC, you should find it in your Patch Library listed as “MindSetQCClient”.  Usage of the patch should be obvious,</li>
<li>The server shouldn’t need to start first as long as the client periodically checks for a vended object, but when troubleshooting it’s probably a good idea to start the server, then the client.</li>
<li>The server needs the Thinkgear bundle in same directory as the server app. (I’m not including the Thinkgear bundle, it’s available from the Neurosky website for free as part of their developer stuff.</li>
<li>Neurosky documentation has instructions for how to figure out what serial port your mindset is on, iirc.  The default for the server is the one I use.</li>
<li>I&#8217;ve borrowed so heavily from a hodge-podge of tutorials and examples, that I&#8217;m not going to include a license for the code. Use it as you will.</li>
</ul>
<p>.</p>
<p>So, onward to the tutorial/implementation details:</p>
<p>.</p>
<h2>Distributed Object Mindset Server and Client</h2>
<p>This server is intended to be a little easier to use than some of the connection methods Neurosky provides (at least in my mind). It grabs data from the Mindset and provides it to Cocoa client applications (such as my Quartz Composer plug-in) by using Objective-C / Cocoa&#8217;s Distributed Objects interprocess messaging capability.</p>
<p>To access the Mindset data, the client must create an NSConnection to “JacksMindsetServer”. This gives it access to a vended object which supports the following very simple protocol (this protocol will have to be included in your client header file):</p>
<p><em><br />
</em></p>
<p style="padding-left:30px;"><em>@protocol PassingMindData</em></p>
<p style="padding-left:30px;"><em>-(int) getDataCount;</em></p>
<p style="padding-left:30px;"><em>-(NSArray *)getOldestData;</em></p>
<p style="padding-left:30px;"><em>-(void)removeOldestData;</em></p>
<p style="padding-left:30px;"><em>@end</em></p>
<p style="padding-left:30px;">
<p style="padding-left:30px;"><em><br />
</em></p>
<p>Creating the connection to the vended object which uses that protocol is simple and requires only a short bit of code:</p>
<p style="padding-left:30px;"><em>if (!sharedObject)</em></p>
<p style="padding-left:30px;"><em>{</em></p>
<p style="padding-left:60px;"><em>NSString *_host = nil;</em></p>
<p style="padding-left:60px;"><em>sharedObject = (id &lt;PassingMindData&gt;)[[NSConnection rootProxyForConnectionWithRegisteredName:@"JacksMindsetServer" host:_host] retain];</em></p>
<p style="padding-left:30px;"><em>}</em></p>
<p style="padding-left:30px;">
<p style="padding-left:30px;"><em><br />
</em></p>
<p>You should now have an object called &#8220;sharedObject&#8221; which allows all of the methods specified by the &#8220;PassingMindData&#8221; protocol created above and which will pass the data from the mindset server to your code. To do so, the primary method is &#8220;getOldestData&#8221;. Calling this method will return an array of the oldest line of values from the Mindset and getDataCount returns the number of lines currently queued.</p>
<p>The returned array contains ordered NSNumbers representing each type of value available from the mindset. The array elements can always be accessed in the following order:</p>
<ul>
<li>Attention (0)</li>
<li>Meditation (1)</li>
<li>Raw (2)</li>
<li>Delta (3)</li>
<li>Theta (4)</li>
<li>Alpha1 (5)</li>
<li>Alpha2 (6)</li>
<li>Beta1 (7)</li>
<li>Beta2 (8)</li>
<li>Gamma (9)</li>
<li>Gamma2 (10)</li>
<li>SignalQuality (11)</li>
</ul>
<p>The client is left to access these elements as it pleases from the NSArray object returned by getOldestData. The server also relies on the client to remove the original data from the server as soon as it grabs it by calling “removeOldestData” on &#8220;sharedObject&#8221;.  (If the client does not call this, there is no auto-cleanup by the server until it’s stopped or exits and the client will not be able to access new data.)</p>
<p>If multiple lines of data are queued, getOldestData and removeOldestData should be executed repeatedly. A simple example would be:</p>
<p><em>if ([sharedObject getDataCount] &gt; 0)</em></p>
<p><em>{</em></p>
<p style="padding-left:30px;"><em>mindDataLine = [NSArray arrayWithArray:[sharedObject getOldestData]];</em></p>
<p style="padding-left:30px;"><em>[self setOutputAttention:[[mindDataLine objectAtIndex:0] doubleValue]];</em></p>
<p style="padding-left:30px;"><em>[sharedObject removeOldestData];</em></p>
<p><em>}</em></p>
<p>That’s really it.  How to write a server is out of the scope of this post, but Neurosky has some great documentation and have provided examples from which I have –heavily&#8211;  borrowed.</p>
<p>Let me know if you have questions or need further explanation. I&#8217;m going to continue to work on the art project with this stuff and will post more about that later.</p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/category/art/'>art</a>, <a href='http://sintixerr.wordpress.com/category/artist/'>artist</a>, <a href='http://sintixerr.wordpress.com/category/code/'>code</a>, <a href='http://sintixerr.wordpress.com/category/information-visualization/'>information visualization</a>, <a href='http://sintixerr.wordpress.com/category/objective-c/'>objective-c</a>, <a href='http://sintixerr.wordpress.com/category/open-source/'>Open-source</a>, <a href='http://sintixerr.wordpress.com/category/os-x/'>os x</a>, <a href='http://sintixerr.wordpress.com/category/programming/'>programming</a>, <a href='http://sintixerr.wordpress.com/category/technology/'>technology</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/tag/art/'>art</a>, <a href='http://sintixerr.wordpress.com/tag/artwork/'>artwork</a>, <a href='http://sintixerr.wordpress.com/tag/bio-feedback/'>bio-feedback</a>, <a href='http://sintixerr.wordpress.com/tag/brain/'>brain</a>, <a href='http://sintixerr.wordpress.com/tag/brain-waves/'>brain waves</a>, <a href='http://sintixerr.wordpress.com/tag/client/'>client</a>, <a href='http://sintixerr.wordpress.com/tag/cocoa/'>cocoa</a>, <a href='http://sintixerr.wordpress.com/tag/data/'>data</a>, <a href='http://sintixerr.wordpress.com/tag/demo/'>demo</a>, <a href='http://sintixerr.wordpress.com/tag/example/'>example</a>, <a href='http://sintixerr.wordpress.com/tag/mind/'>mind</a>, <a href='http://sintixerr.wordpress.com/tag/mindset/'>mindset</a>, <a href='http://sintixerr.wordpress.com/tag/neurosky/'>neurosky</a>, <a href='http://sintixerr.wordpress.com/tag/objective-c/'>objective-c</a>, <a href='http://sintixerr.wordpress.com/tag/server/'>server</a>, <a href='http://sintixerr.wordpress.com/tag/tutorial/'>tutorial</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/707/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=707&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/07/26/open-source-neurosky-mindset-server-quartz-composer-client-and-tutorial/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Brain Wave Art Demo #2</title>
		<link>http://sintixerr.wordpress.com/2010/07/04/brain-wave-art-demo-2/</link>
		<comments>http://sintixerr.wordpress.com/2010/07/04/brain-wave-art-demo-2/#comments</comments>
		<pubDate>Sun, 04 Jul 2010 21:34:37 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA["Quartz Composer"]]></category>
		<category><![CDATA[art]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[data visualization]]></category>
		<category><![CDATA[interactive]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[objective-c]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[Projects]]></category>
		<category><![CDATA[self-portrait]]></category>
		<category><![CDATA[visualize]]></category>
		<category><![CDATA[api]]></category>
		<category><![CDATA[artwork]]></category>
		<category><![CDATA[brain waves]]></category>
		<category><![CDATA[mind reading]]></category>
		<category><![CDATA[mindset]]></category>
		<category><![CDATA[mixed media]]></category>
		<category><![CDATA[neurosky]]></category>
		<category><![CDATA[sci-fi]]></category>
		<category><![CDATA[science fiction]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=701</guid>
		<description><![CDATA[Longer, more detailed post to follow &#8211; with free code and everything &#8211; but I wanted to post a video of art being made with my brainwaves: In this demo (which is a significant step further than my last), my project selects between a series of images, merges them, moves them, and adds various visual [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=701&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Longer, more detailed post to follow &#8211; with free code and everything &#8211; but I wanted to post a video of art being made with my brainwaves:</p>
<div class='embed-vimeo' style='text-align:center;'><iframe src='http://player.vimeo.com/video/13069637' width='400' height='300' frameborder='0'></iframe></div>
<p>In this demo (which is a significant step further than my last), my  project selects between a series of images, merges them, moves them, and  adds various visual effects based only on input from my brain waves (as  measured by a <a href="http://sintixerr.wordpress.com/2010/07/04/brain-wave-art-demo-2/" target="_blank">Neurosky</a> Mindset). All images &#8211; both drawings and photos &#8211;  were made by me.  Depending on when I run this, the images selected and  how they&#8217;re merged vary significantly. In this case, only a small  subset were selected. Other times, there is a wider variety. It&#8217;s  important to note that often, this has created pairings and mergings  that are fantastically cool looking.  The Next step, creating a self  portrait video of me sleeping with a curved screen over top of me  projecting what my mind does with this while I sleep.</p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/category/art/'>art</a>, <a href='http://sintixerr.wordpress.com/category/art/source-material/cyberspace/'>cyberspace</a>, <a href='http://sintixerr.wordpress.com/category/data-visualization/'>data visualization</a>, <a href='http://sintixerr.wordpress.com/category/art/technique/style/interactive/'>interactive</a>, <a href='http://sintixerr.wordpress.com/category/art/technique/media/'>Media</a>, <a href='http://sintixerr.wordpress.com/category/objective-c/'>objective-c</a>, <a href='http://sintixerr.wordpress.com/category/programming/'>programming</a>, <a href='http://sintixerr.wordpress.com/category/art/projects/'>Projects</a>, <a href='http://sintixerr.wordpress.com/category/art/category/self-portrait/'>self-portrait</a>, <a href='http://sintixerr.wordpress.com/category/visualize/'>visualize</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/api/'>api</a>, <a href='http://sintixerr.wordpress.com/tag/art/'>art</a>, <a href='http://sintixerr.wordpress.com/tag/artwork/'>artwork</a>, <a href='http://sintixerr.wordpress.com/tag/brain-waves/'>brain waves</a>, <a href='http://sintixerr.wordpress.com/tag/mind-reading/'>mind reading</a>, <a href='http://sintixerr.wordpress.com/tag/mindset/'>mindset</a>, <a href='http://sintixerr.wordpress.com/tag/mixed-media/'>mixed media</a>, <a href='http://sintixerr.wordpress.com/tag/neurosky/'>neurosky</a>, <a href='http://sintixerr.wordpress.com/tag/sci-fi/'>sci-fi</a>, <a href='http://sintixerr.wordpress.com/tag/science-fiction/'>science fiction</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/701/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/701/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/701/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/701/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/701/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/701/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/701/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/701/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/701/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/701/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/701/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/701/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/701/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/701/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=701&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/07/04/brain-wave-art-demo-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Heads-Up: I&#8217;ll be talking at the EnergySec conference in Denver this year!</title>
		<link>http://sintixerr.wordpress.com/2010/07/02/heads-up-ill-be-talking-at-the-energysec-conference-in-denver-this-year/</link>
		<comments>http://sintixerr.wordpress.com/2010/07/02/heads-up-ill-be-talking-at-the-energysec-conference-in-denver-this-year/#comments</comments>
		<pubDate>Sat, 03 Jul 2010 04:37:40 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[CIP]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[admission]]></category>
		<category><![CDATA[CIKR]]></category>
		<category><![CDATA[Denver]]></category>
		<category><![CDATA[Energy]]></category>
		<category><![CDATA[EnergySec Conference]]></category>
		<category><![CDATA[inadequate]]></category>
		<category><![CDATA[national]]></category>
		<category><![CDATA[talk]]></category>
		<category><![CDATA[technologist]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=691</guid>
		<description><![CDATA[So, with what is quite interesting timing, (and thanks, in no small part to Twitter), I just found out a couple of days ago that I&#8217;ll be giving a talk at EnergySec This year.  The tentative title is: &#8220;A Technologist&#8217;s Admission of Inadequacy: The executive&#8217;s role in National Cyber Security&#8221;. I&#8217;d really like to use [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=691&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So, with what is quite interesting timing, (and thanks, in no small part to <a href="http://twitter.com/sintixerr" target="_blank">Twitter</a>), I just found out a couple of days ago that I&#8217;ll be giving a talk at <a href="http://www.energysec.org/" target="_blank">EnergySec</a> This year.  The tentative title is: <strong>&#8220;A Technologist&#8217;s Admission of Inadequacy: The executive&#8217;s role in National Cyber Security&#8221;.</strong><br />
I&#8217;d really like to use this opportunity as a platform for some of my concerns, as a technologist, about how we&#8217;re treating cyber security as a technical problem &#8211; at an operational level, at a strategic business level, and at a legislative level. I&#8217;ve touched on these concerns before in this blog, but I&#8217;m really excited about the chance to do it in person in front of a lot of other smart people who are actively working cyber security problems.</p>
<p>Thinking out loud, I wrote this earlier:</p>
<blockquote><p>One of my interests, part of my future role, and with a perspective grounded in building/designing ways to detect badness / working on ICS-CERT, is in combating our habit of defining security in technical terms or on relying on technologists to &#8220;fix it&#8221;without ever defining what &#8220;it&#8221; is.  A secure system is one that does no more and no less than the people who have ownership and stake in it wish it to do- and that&#8217;s a business rule/decision/appetite.  As a technologist, if you ask me to secure your systems and let me define what that means, I&#8217;ll fail.  (ie: There is no &#8220;evil&#8221; flag in TCP). I&#8217;d like to make a plea for organizations to define security through risks to interrelated cross-sector business and social requirements (and associated appetites) before spending so much effort to create technical security plans, standards, controls, laws. An army without a defined mission can be potent just based on size and power, but one that has a mission and defined goals is much, much better.</p></blockquote>
<p>I&#8217;m sure I&#8217;ll evolve what I actually want to say between now and September, but that&#8217;s where my head is now.</p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/cip/'>CIP</a>, <a href='http://sintixerr.wordpress.com/category/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/category/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/professional/'>Professional</a>, <a href='http://sintixerr.wordpress.com/category/risk-management/'>risk management</a>, <a href='http://sintixerr.wordpress.com/category/scada/'>SCADA</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/2010/'>2010</a>, <a href='http://sintixerr.wordpress.com/tag/admission/'>admission</a>, <a href='http://sintixerr.wordpress.com/tag/cikr/'>CIKR</a>, <a href='http://sintixerr.wordpress.com/tag/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/tag/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/tag/denver/'>Denver</a>, <a href='http://sintixerr.wordpress.com/tag/energy/'>Energy</a>, <a href='http://sintixerr.wordpress.com/tag/energysec-conference/'>EnergySec Conference</a>, <a href='http://sintixerr.wordpress.com/tag/inadequate/'>inadequate</a>, <a href='http://sintixerr.wordpress.com/tag/national/'>national</a>, <a href='http://sintixerr.wordpress.com/tag/talk/'>talk</a>, <a href='http://sintixerr.wordpress.com/tag/technologist/'>technologist</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/691/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/691/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/691/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/691/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/691/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/691/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/691/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/691/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/691/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/691/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/691/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/691/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/691/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/691/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=691&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/07/02/heads-up-ill-be-talking-at-the-energysec-conference-in-denver-this-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Did You Know? The United States has an Industrial Control Systems (SCADA) CERT (ICS-CERT)</title>
		<link>http://sintixerr.wordpress.com/2010/07/02/did-you-know-the-united-states-have-an-industrial-control-systems-scada-cert-ics-cert/</link>
		<comments>http://sintixerr.wordpress.com/2010/07/02/did-you-know-the-united-states-have-an-industrial-control-systems-scada-cert-ics-cert/#comments</comments>
		<pubDate>Sat, 03 Jul 2010 04:25:18 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[CIP]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SEM]]></category>
		<category><![CDATA[cert]]></category>
		<category><![CDATA[CIKR]]></category>
		<category><![CDATA[CSSP]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[dhs]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[HSPD-7]]></category>
		<category><![CDATA[ics-cert]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[industrial control systems]]></category>
		<category><![CDATA[NCCIC]]></category>
		<category><![CDATA[Public]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=687</guid>
		<description><![CDATA[Well, I&#8217;ve been waiting awhile to be able to write this (see future post).  Finally, I can: It&#8217;s always interesting dealing with the somewhat schizophrenic nature of government messaging.  While I understand the constraints, the risks, and the realities of trying to run a free-for-the-private sector service that actually DOES something in the government, it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=687&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em>Well, I&#8217;ve been waiting awhile to be able to write this (see future post).  Finally, I can:</em></p>
<p>It&#8217;s always interesting dealing with the somewhat schizophrenic nature of government messaging.  While I understand the constraints, the risks, and the realities of trying to run a free-for-the-private sector service that actually DOES something in the government, it was always a little disheartening to hear (or read) people suggest that the government wasn&#8217;t doing anything for some of our cyber security problems, that it didnt have the services available, or &#8220;Well, I heard DHS started ICS-CERT, but I think they shut it down?&#8221; And, with the media so often just not getting it &#8211; and people so often not doing basic research &#8211; this happened more frequently than it should.  So, now that I&#8217;m in the role of customer here (and not on the floor there), I can finally say:</p>
<p><strong>If you&#8217;re an asset owner, a vendor, a service provider, a customer, or otherwise a stakeholder in private sector or government critical infrastructure / key resources, you should be aware of <a href="http://www.us-cert.gov/control_systems/" target="_blank">CSSP</a> and <a href="http://www.us-cert.gov/control_systems/ics-cert/" target="_blank">ICS-CERT</a> </strong>(ICS-CERT has been functioning, in its current form, since earlier this year)<strong>.</strong></p>
<p>To start with: The Control Systems Security Program (CSSP) is an offering out of <a href="http://en.wikipedia.org/wiki/United_States_Department_of_Homeland_Security" target="_blank">Homeland Security</a> which:</p>
<blockquote><p><em>&#8220;attempts to&#8230;reduce  industrial control system risks within and across all critical  infrastructure and key resource sectors by coordinating efforts among  federal, state, local, and tribal governments, as well as industrial  control systems owners, operators and vendors. The CSSP coordinates  activities to reduce the likelihood of success and severity of impact of  a cyber attack against critical infrastructure control systems through  risk-mitigation activities.&#8221;</em></p></blockquote>
<p>This includes providing a FREE cyber security assessment tool, onsite assessment visits, and the well-run Industrial Control Systems Joint Working Group (<a href="http://www.us-cert.gov/control_systems/icsjwg/index.html" target="_blank">ICSJWG</a>) and its associated conferences. CSSP also provides a variety of <a href="http://www.us-cert.gov/control_systems/cstraining.html" target="_blank">free-training</a> in Control Systems Security, both locally in DC as well as, for it&#8217;s hands-on Red/Blue Team training,  in Idaho Falls.</p>
<p>Then, providing a tactical operational arm to the more strategic CSSP, ICS-CERT is a fully functioning free CERT service for your CIKR organizations. ICS-CERT will, as part of its mission:</p>
<blockquote>
<ol>
<li>Provide onsite fly-away technical incident response</li>
<li>Perform digital media analysis on media potentially affected by an incident</li>
<li>Coordinate the responsible release of vulnerabilities (involving third party researchers, vendors, etc.)</li>
<li>Provide timely situational awareness</li>
<li>Coordinate national response, via its seats in the National Cybersecurity Communications and Integration Center <a href="http://gcn.com/articles/2009/10/30/dhs-new-national-cybersecurity-operations-center.aspx" target="_blank">(NCCIC)</a>, with US-CERT, NCC, Law Enforcement, and other organizations.</li>
</ol>
</blockquote>
<p>All you have to do, basically, is ask.  They&#8217;ve assisted, during my tenure, quite a few organizations &#8211; large and small &#8211; and continue to do so.</p>
<p><em>(Importantly, ICS-CERT has neither a law-enforcement NOR a regulatory function. Their mission is to assist you in defending yourselves and responding to incidents. Your data is, and remains, yours, in any interaction with them. )</em></p>
<p>And you thought the government doesn&#8217;t do anything for cyber security :)</p>
<p>To contact ICS-CERT:</p>
<ul>
<li>Call the ICS-CERT Watch Floor: 1-877-776-7585</li>
<li>Email regarding ICS related cyber activity: <a href="mailto:ics-cert@dhs.gov">ics-cert@dhs.gov</a></li>
</ul>
<p>Their website is: http://ics-cert.org</p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/cip/'>CIP</a>, <a href='http://sintixerr.wordpress.com/category/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/category/government/'>government</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/professional/network-security/'>Network Security</a>, <a href='http://sintixerr.wordpress.com/category/professional/'>Professional</a>, <a href='http://sintixerr.wordpress.com/category/risk/'>risk</a>, <a href='http://sintixerr.wordpress.com/category/security/'>security</a>, <a href='http://sintixerr.wordpress.com/category/sem/'>SEM</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/cert/'>cert</a>, <a href='http://sintixerr.wordpress.com/tag/cikr/'>CIKR</a>, <a href='http://sintixerr.wordpress.com/tag/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/tag/cssp/'>CSSP</a>, <a href='http://sintixerr.wordpress.com/tag/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/tag/dhs/'>dhs</a>, <a href='http://sintixerr.wordpress.com/tag/free/'>free</a>, <a href='http://sintixerr.wordpress.com/tag/government/'>government</a>, <a href='http://sintixerr.wordpress.com/tag/hspd-7/'>HSPD-7</a>, <a href='http://sintixerr.wordpress.com/tag/ics-cert/'>ics-cert</a>, <a href='http://sintixerr.wordpress.com/tag/incident-response/'>Incident Response</a>, <a href='http://sintixerr.wordpress.com/tag/industrial-control-systems/'>industrial control systems</a>, <a href='http://sintixerr.wordpress.com/tag/nccic/'>NCCIC</a>, <a href='http://sintixerr.wordpress.com/tag/public/'>Public</a>, <a href='http://sintixerr.wordpress.com/tag/research/'>research</a>, <a href='http://sintixerr.wordpress.com/tag/scada/'>SCADA</a>, <a href='http://sintixerr.wordpress.com/tag/service/'>Service</a>, <a href='http://sintixerr.wordpress.com/tag/vulnerabilities/'>vulnerabilities</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/687/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=687&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/07/02/did-you-know-the-united-states-have-an-industrial-control-systems-scada-cert-ics-cert/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Brainwave Art Talk for Digital Capital Week</title>
		<link>http://sintixerr.wordpress.com/2010/06/15/brainwave-art-talk-for-digital-capital-week/</link>
		<comments>http://sintixerr.wordpress.com/2010/06/15/brainwave-art-talk-for-digital-capital-week/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 14:32:51 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA["Quartz Composer"]]></category>
		<category><![CDATA[art]]></category>
		<category><![CDATA[artist]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[cyberpunk]]></category>
		<category><![CDATA[data visualization]]></category>
		<category><![CDATA[District of Columbia]]></category>
		<category><![CDATA[information visualization]]></category>
		<category><![CDATA[Local]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[Projects]]></category>
		<category><![CDATA[Source Material]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[Washington DC]]></category>
		<category><![CDATA[brain]]></category>
		<category><![CDATA[brainwaves]]></category>
		<category><![CDATA[DCWeek]]></category>
		<category><![CDATA[Digital Capital Week]]></category>
		<category><![CDATA[eeg]]></category>
		<category><![CDATA[HacDC]]></category>
		<category><![CDATA[lightning talk]]></category>
		<category><![CDATA[mindset]]></category>
		<category><![CDATA[neurosky]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[visualization]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=683</guid>
		<description><![CDATA[Via HacDC and as part of Digital Capital Week, I&#8217;ll be giving a lightning talk this Saturday the 19th on using your brainwaves to make art while you sleep. I&#8217;ll include either a video of the &#8220;first draft&#8221; of the art, or a live demo.  This is a follow-up talk to one I gave this [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=683&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Via <a href="http://hacdc.org/" target="_blank">HacDC</a> and as part of <a href="http://digitalcapitalweek.org/" target="_blank">Digital Capital Week</a>, I&#8217;ll be giving a <a href="http://wiki.hacdc.org/index.php/LightningTalks" target="_blank">lightning talk</a> this Saturday the 19th on using your brainwaves to make art while you sleep. I&#8217;ll include either a video of the &#8220;first draft&#8221; of the art, or a live demo.  This is a follow-up talk to one I gave this past February.</p>
<p>The talks start at 4:45 and go for an hour (or a little over) and you can find us at:</p>
<blockquote><p>Mount Vernon Place United Methodist Church<br />
900 Massachusetts Ave NW, Washington DC</p></blockquote>
<p>If you want to hear more about consumer-grade fun with using your brainwaves to manipulate the world around you, come check it out!</p>
<p>The current speaker lineup is:</p>
<ul>
<li>Look Ma, No Wires (Michael Panfield)</li>
<li>Sysadmins: Have smartphone, will travel (Betsy Nichols and Andrei Tchijov)</li>
<li>AI: Three most common reactions (Bradford Barr)</li>
<li> ??? (Alan McCosh)</li>
<li>Writ Large: scaling a Cartesian robot (Dan Barlow)</li>
<li>Urban Data Access: How communication builds communities (Will Holcomb)</li>
<li>Fast Creativity: Using the DNA of Improvisational Comedy to Foster Ideas Fast (Shawn Westfall)</li>
<li>While you sleep: Making Art with your mind (and a little code) (Jack Whitsitt)</li>
</ul>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/category/art/'>art</a>, <a href='http://sintixerr.wordpress.com/category/artist/'>artist</a>, <a href='http://sintixerr.wordpress.com/category/code/'>code</a>, <a href='http://sintixerr.wordpress.com/category/cyberpunk/'>cyberpunk</a>, <a href='http://sintixerr.wordpress.com/category/data-visualization/'>data visualization</a>, <a href='http://sintixerr.wordpress.com/category/local/district-of-columbia/'>District of Columbia</a>, <a href='http://sintixerr.wordpress.com/category/information-visualization/'>information visualization</a>, <a href='http://sintixerr.wordpress.com/category/local/'>Local</a>, <a href='http://sintixerr.wordpress.com/category/art/technique/performance/'>performance</a>, <a href='http://sintixerr.wordpress.com/category/programming/'>programming</a>, <a href='http://sintixerr.wordpress.com/category/art/projects/'>Projects</a>, <a href='http://sintixerr.wordpress.com/category/art/source-material/'>Source Material</a>, <a href='http://sintixerr.wordpress.com/category/technology/'>technology</a>, <a href='http://sintixerr.wordpress.com/category/local/washington-dc/'>Washington DC</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/art/'>art</a>, <a href='http://sintixerr.wordpress.com/tag/artist/'>artist</a>, <a href='http://sintixerr.wordpress.com/tag/brain/'>brain</a>, <a href='http://sintixerr.wordpress.com/tag/brainwaves/'>brainwaves</a>, <a href='http://sintixerr.wordpress.com/tag/dcweek/'>DCWeek</a>, <a href='http://sintixerr.wordpress.com/tag/digital-capital-week/'>Digital Capital Week</a>, <a href='http://sintixerr.wordpress.com/tag/eeg/'>eeg</a>, <a href='http://sintixerr.wordpress.com/tag/hacdc/'>HacDC</a>, <a href='http://sintixerr.wordpress.com/tag/lightning-talk/'>lightning talk</a>, <a href='http://sintixerr.wordpress.com/tag/mindset/'>mindset</a>, <a href='http://sintixerr.wordpress.com/tag/neurosky/'>neurosky</a>, <a href='http://sintixerr.wordpress.com/tag/presentation/'>presentation</a>, <a href='http://sintixerr.wordpress.com/tag/visualization/'>visualization</a>, <a href='http://sintixerr.wordpress.com/tag/wireless/'>wireless</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/683/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/683/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/683/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/683/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/683/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/683/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/683/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=683&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/06/15/brainwave-art-talk-for-digital-capital-week/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Redefining reality through redefinition of words: 0days</title>
		<link>http://sintixerr.wordpress.com/2010/04/13/redefining-reality-through-redefinition-of-language-0days/</link>
		<comments>http://sintixerr.wordpress.com/2010/04/13/redefining-reality-through-redefinition-of-language-0days/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 21:54:16 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Ontologies]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[a river in africa]]></category>
		<category><![CDATA[cert]]></category>
		<category><![CDATA[circ]]></category>
		<category><![CDATA[cirt]]></category>
		<category><![CDATA[definitions]]></category>
		<category><![CDATA[denial]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[ontology]]></category>
		<category><![CDATA[rambling]]></category>
		<category><![CDATA[thoughts]]></category>
		<category><![CDATA[vulnerabiities]]></category>
		<category><![CDATA[vulnerability window]]></category>
		<category><![CDATA[zero day]]></category>
		<category><![CDATA[zero days]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=675</guid>
		<description><![CDATA[So I was sitting with a group of people recently &#8211; experts, as it were &#8211; discussing &#8220;bad things on the internet&#8221;.  Someone turned over his shoulder back towards us and asked &#8220;So, what exactly is a 0day?&#8221; In context, he was asking &#8220;Where does the term come from&#8221; because, in the conversation, it was [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=675&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So I was sitting with a group of people recently &#8211; experts, as it were &#8211; discussing &#8220;bad things on the internet&#8221;.  Someone turned over his shoulder back towards us and asked <em>&#8220;So, what exactly is a 0day?&#8221; </em> In context, he was asking &#8220;Where does the term come from&#8221; because, in the conversation, it was being used to describe some exploits that we, as the &#8220;good guys&#8221;, all knew about &#8211; and had for some time.   The answer he got disturbed me a bit: &#8220;Exploits and vulnerabilities that have not been patched.&#8221;</p>
<p><strong>Really?</strong></p>
<p>What gives? 0days/0-days/zero days used to mean (generally speaking) those exploits of which neither  the vendor nor the &#8220;good guys&#8221; knew anything about. Ie, &#8220;zero days&#8221; had  passed since a solution -could have- begun being developed.   I like <a href="http://netsecurity.about.com/od/newsandeditorial1/a/aazeroday.htm" target="_blank">About.com&#8217;s phrasing</a>:</p>
<p><em>&#8220;A zero day exploit is when the exploit for the vulnerability is created  before, or on the same day as the vulnerability is learned about by the  vendor.&#8221;</em></p>
<p><strong>A flaw that the vendor and the response community have known about for months but which the vendor hasn&#8217;t addressed is NOT a 0day -</strong><strong> it&#8217;s an unpatched problem </strong>:P (There are cases where the time from the issue being known about until the vendor patches it has exceeded, in some cases, a decade.)</p>
<p>I&#8217;m trying to figure out how we got to this perceived definition and I wonder if it&#8217;s <em>our refusal to come to grips with the fact that there are hundreds/thousands of security flaws running around out there that &#8220;the bad guys&#8221; know about (and use) that the &#8220;good guys&#8221; dont have a clue about. </em> We run around patching things like if only we could just reduce the time it takes to patch systems to near-zero that somehow we would be measurably more secure.</p>
<p><strong>If we just write out the truly severe part of the vulnerability window  &#8211; where there are vulnerabilities and exploits we don&#8217;t know about &#8211; from our language/definitions, it won&#8217;t exist right? </strong></p>
<p>Right?</p>
<p>Bueller?</p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/category/government/'>government</a>, <a href='http://sintixerr.wordpress.com/category/hacking/'>hacking</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/professional/network-security/'>Network Security</a>, <a href='http://sintixerr.wordpress.com/category/ontologies/'>Ontologies</a>, <a href='http://sintixerr.wordpress.com/category/professional/'>Professional</a>, <a href='http://sintixerr.wordpress.com/category/security/'>security</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/0-day/'>0-day</a>, <a href='http://sintixerr.wordpress.com/tag/0day/'>0day</a>, <a href='http://sintixerr.wordpress.com/tag/a-river-in-africa/'>a river in africa</a>, <a href='http://sintixerr.wordpress.com/tag/cert/'>cert</a>, <a href='http://sintixerr.wordpress.com/tag/circ/'>circ</a>, <a href='http://sintixerr.wordpress.com/tag/cirt/'>cirt</a>, <a href='http://sintixerr.wordpress.com/tag/definitions/'>definitions</a>, <a href='http://sintixerr.wordpress.com/tag/denial/'>denial</a>, <a href='http://sintixerr.wordpress.com/tag/exploits/'>exploits</a>, <a href='http://sintixerr.wordpress.com/tag/language/'>language</a>, <a href='http://sintixerr.wordpress.com/tag/ontology/'>ontology</a>, <a href='http://sintixerr.wordpress.com/tag/rambling/'>rambling</a>, <a href='http://sintixerr.wordpress.com/tag/thoughts/'>thoughts</a>, <a href='http://sintixerr.wordpress.com/tag/vulnerabiities/'>vulnerabiities</a>, <a href='http://sintixerr.wordpress.com/tag/vulnerability-window/'>vulnerability window</a>, <a href='http://sintixerr.wordpress.com/tag/zero-day/'>zero day</a>, <a href='http://sintixerr.wordpress.com/tag/zero-days/'>zero days</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/675/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/675/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/675/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/675/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/675/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/675/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/675/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/675/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/675/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/675/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/675/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/675/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/675/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/675/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=675&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/04/13/redefining-reality-through-redefinition-of-language-0days/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Nothing is clearly better than something, sometimes: A Security Parable</title>
		<link>http://sintixerr.wordpress.com/2010/04/08/nothing-is-clearly-better-than-something-sometimes-a-security-parable/</link>
		<comments>http://sintixerr.wordpress.com/2010/04/08/nothing-is-clearly-better-than-something-sometimes-a-security-parable/#comments</comments>
		<pubDate>Fri, 09 Apr 2010 03:40:40 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[business architecture]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[0wned]]></category>
		<category><![CDATA[analogy]]></category>
		<category><![CDATA[architecture]]></category>
		<category><![CDATA[getting owned]]></category>
		<category><![CDATA[nothing]]></category>
		<category><![CDATA[parable]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk profile]]></category>
		<category><![CDATA[something]]></category>
		<category><![CDATA[straw man]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=665</guid>
		<description><![CDATA[Say you want to buy a car to take your 5 kids and spouse around town. Now, suppose you start looking for a good, safe van with low gas mileage that fits the whole family and is relatively cheap. $20k? sure.  Ok, now what if you go out to buy this van&#8230;.but oh no! All [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=665&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Say you want to buy a car to take your 5 kids and spouse around town. Now, suppose you start looking for a good, safe van with low gas mileage that fits the whole family and is relatively cheap. $20k? sure.  Ok, now what if you go out to buy this van&#8230;.but oh no! All you can find are corvette dealers selling $100,000 cars!!!</p>
<p>Would you buy a corvette? Hells no. You&#8217;d wait until you found something that met your minimum requirements: Moving the family around. If you got the vette, you would have gotten something that, even if it fit &#8220;some&#8221; of your requirements (moving some people around), doesn&#8217;t  fit enough of them to actually solve the problem. Furthermore, if you did get the vette, you probably wouldnt be able to afford the van so your problem would go on even longer than if you hadnt gotten the corvette.</p>
<p>Welcome to the kind of security that says &#8220;we should do more of what we&#8217;ve been doing, even though we know the architectures don&#8217;t work&#8230;<strong>because something is better than nothing.</strong>&#8220;  We can&#8217;t continue to add on layer after layer of security at ever  increasing cost when no number of those layers, as modeled today, will  ever get us to a comfortable place.  Getting owned by X% fewer people is still getting owned and doesn&#8217;t really change your risk profile unless X is a much bigger number than today&#8217;s most common best practices get us.</p>
<p>Nothing is ever perfect, so I&#8217;m not suggesting no one should take action until they find a perfect solution. Rather, I&#8217;m suggesting we all take a close look at our solution sets and look at how good they&#8217;re ever going to get at the end of the day and make decisions appropriately. When selecting a &#8220;50%&#8221; solution architecture for $Y, dont get caught thinking $Yx2 will get you a 100% solution with the same architecture:)</p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/business-architecture/'>business architecture</a>, <a href='http://sintixerr.wordpress.com/category/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/category/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/professional/network-security/'>Network Security</a>, <a href='http://sintixerr.wordpress.com/category/professional/'>Professional</a>, <a href='http://sintixerr.wordpress.com/category/risk-management/'>risk management</a>, <a href='http://sintixerr.wordpress.com/category/security/'>security</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/0wned/'>0wned</a>, <a href='http://sintixerr.wordpress.com/tag/analogy/'>analogy</a>, <a href='http://sintixerr.wordpress.com/tag/architecture/'>architecture</a>, <a href='http://sintixerr.wordpress.com/tag/cyber-security/'>Cyber Security</a>, <a href='http://sintixerr.wordpress.com/tag/getting-owned/'>getting owned</a>, <a href='http://sintixerr.wordpress.com/tag/nothing/'>nothing</a>, <a href='http://sintixerr.wordpress.com/tag/parable/'>parable</a>, <a href='http://sintixerr.wordpress.com/tag/risk/'>risk</a>, <a href='http://sintixerr.wordpress.com/tag/risk-profile/'>risk profile</a>, <a href='http://sintixerr.wordpress.com/tag/security/'>security</a>, <a href='http://sintixerr.wordpress.com/tag/something/'>something</a>, <a href='http://sintixerr.wordpress.com/tag/straw-man/'>straw man</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/665/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=665&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/04/08/nothing-is-clearly-better-than-something-sometimes-a-security-parable/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Industrial Control Systems CERT (ICS-CERT) has a newish website</title>
		<link>http://sintixerr.wordpress.com/2010/03/03/industrial-control-systems-cert-ics-cert-has-a-newish-website/</link>
		<comments>http://sintixerr.wordpress.com/2010/03/03/industrial-control-systems-cert-ics-cert-has-a-newish-website/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 19:14:14 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[Control Systems Security Program]]></category>
		<category><![CDATA[CSSP]]></category>
		<category><![CDATA[Cyber]]></category>
		<category><![CDATA[dhs]]></category>
		<category><![CDATA[Emergency]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Homeland Security]]></category>
		<category><![CDATA[ics-cert]]></category>
		<category><![CDATA[Idaho National Lab]]></category>
		<category><![CDATA[Incidents]]></category>
		<category><![CDATA[industrial control systems]]></category>
		<category><![CDATA[INL]]></category>
		<category><![CDATA[organization]]></category>
		<category><![CDATA[process control]]></category>
		<category><![CDATA[program]]></category>
		<category><![CDATA[response]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=660</guid>
		<description><![CDATA[I normally don&#8217;t have much to say here about my day job (partly why you&#8217;ve seen more of a focus on art), but I thought (since I&#8217;d been previously linking to the DHS Control Systems Security Program pages) that it was worth mentioning that ICS-CERT has its own website these days: http://ics-cert.org Take a look [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=660&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I normally don&#8217;t have much to say here about my day job (partly why you&#8217;ve seen more of a focus on art), but I thought (since I&#8217;d been previously linking to the DHS Control Systems Security Program pages) that it was worth mentioning that<a href="www.us-cert.gov/control_systems/pdf/ICS-CERT_Fact_Sheet_02c.pdf" target="_blank"> ICS-CERT</a> has its own website these days: <a href="http://ics-cert.org" target="_blank">http://ics-cert.org </a></p>
<p>Take a look at it if you&#8217;re in the control systems / SCADA and security/emergency space (particularly with regard, but not limited, to cyber).</p>
<p><em>Edit/Update: Now that I&#8217;m no longer there, I do have a brief take on the subject and a summary of information <a href="http://sintixerr.wordpress.com/2010/07/02/did-you-know-the-united-states-have-an-industrial-control-systems-scada-cert-ics-cert/" target="_blank">HERE</a></em></p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/critical-infrastructure/'>Critical Infrastructure</a>, <a href='http://sintixerr.wordpress.com/category/government/'>government</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/professional/'>Professional</a>, <a href='http://sintixerr.wordpress.com/category/risk/'>risk</a>, <a href='http://sintixerr.wordpress.com/category/scada/'>SCADA</a>, <a href='http://sintixerr.wordpress.com/category/security/'>security</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/attack/'>Attack</a>, <a href='http://sintixerr.wordpress.com/tag/computer/'>computer</a>, <a href='http://sintixerr.wordpress.com/tag/control-systems-security-program/'>Control Systems Security Program</a>, <a href='http://sintixerr.wordpress.com/tag/cssp/'>CSSP</a>, <a href='http://sintixerr.wordpress.com/tag/cyber/'>Cyber</a>, <a href='http://sintixerr.wordpress.com/tag/dhs/'>dhs</a>, <a href='http://sintixerr.wordpress.com/tag/emergency/'>Emergency</a>, <a href='http://sintixerr.wordpress.com/tag/hackers/'>hackers</a>, <a href='http://sintixerr.wordpress.com/tag/homeland-security/'>Homeland Security</a>, <a href='http://sintixerr.wordpress.com/tag/ics-cert/'>ics-cert</a>, <a href='http://sintixerr.wordpress.com/tag/idaho-national-lab/'>Idaho National Lab</a>, <a href='http://sintixerr.wordpress.com/tag/incidents/'>Incidents</a>, <a href='http://sintixerr.wordpress.com/tag/industrial-control-systems/'>industrial control systems</a>, <a href='http://sintixerr.wordpress.com/tag/inl/'>INL</a>, <a href='http://sintixerr.wordpress.com/tag/organization/'>organization</a>, <a href='http://sintixerr.wordpress.com/tag/process-control/'>process control</a>, <a href='http://sintixerr.wordpress.com/tag/program/'>program</a>, <a href='http://sintixerr.wordpress.com/tag/response/'>response</a>, <a href='http://sintixerr.wordpress.com/tag/risk/'>risk</a>, <a href='http://sintixerr.wordpress.com/tag/scada/'>SCADA</a>, <a href='http://sintixerr.wordpress.com/tag/security/'>security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/660/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=660&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/03/03/industrial-control-systems-cert-ics-cert-has-a-newish-website/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Off Topic: Juried into DCist Exposed 2010, Come out to see March 6</title>
		<link>http://sintixerr.wordpress.com/2010/02/28/off-topic-juried-into-dcist-exposed-2010-come-out-to-see-march-6/</link>
		<comments>http://sintixerr.wordpress.com/2010/02/28/off-topic-juried-into-dcist-exposed-2010-come-out-to-see-march-6/#comments</comments>
		<pubDate>Sun, 28 Feb 2010 17:22:18 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[art]]></category>
		<category><![CDATA[DCist]]></category>
		<category><![CDATA[District of Columbia]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Gallery]]></category>
		<category><![CDATA[Local]]></category>
		<category><![CDATA[Other Artists]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Photo]]></category>
		<category><![CDATA[Photography]]></category>
		<category><![CDATA[Washington DC]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[DCist Exposed]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[Jack Whitsitt]]></category>
		<category><![CDATA[juried]]></category>
		<category><![CDATA[liquor tasting]]></category>
		<category><![CDATA[long view gallery]]></category>
		<category><![CDATA[open bar]]></category>
		<category><![CDATA[Paivi Salonen]]></category>
		<category><![CDATA[show]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=655</guid>
		<description><![CDATA[Not really appropriate for this blog, but I&#8217;m pretty lazy about updating my art-only one: Paivi and I were juried into (along with many other talented local photographers) the DCist Exposed show this year and the opening is Saturday, March 6. Come see it, if you&#8217;re in town and free.  My selected photo was: Official [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=655&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Not really appropriate for this blog, but I&#8217;m pretty lazy about updating my art-only one: Paivi and I were juried into (along with many other talented local photographers) the DCist Exposed show this year and the opening is Saturday, March 6. Come see it, if you&#8217;re in town and free.  My selected photo was:</p>
<p style="text-align:center;"><a href="http://farm4.static.flickr.com/3607/3412542907_7297d2c95e_b.jpg" target="_blank"><img class="aligncenter" src="http://farm4.static.flickr.com/3607/3412542907_7297d2c95e_b.jpg" alt="" width="394" height="314" /></a></p>
<p>Official press release follows:</p>
<p>&#8212;</p>
<p><em><span style="color:#808080;"><span style="font-family:Times New Roman;">Washington, DC &#8212; </span><a href="http://www.dcist.com/" target="_blank"><span style="font-family:Times New Roman;"> DCist.com</span></a><span style="font-family:Times New Roman;"> is pleased to announce its fourth annual <strong>DCist Exposed Photography Show</strong>, at <a href="http://www.longviewgallerydc.com/" target="_blank">Long View Gallery</a>, running March 6 to 21, 2010. </span><span style="font-family:Times New Roman;">Out of over 1,000 individual entries submitted through Flickr.com, 47 winning images were selected by a panel of judges to be included in this year&#8217;s DCist Exposed exhibit.</span><span style="font-family:Times New Roman;"> DCist.com prides itself on engaging and promoting emerging local photographers through its daily use of images from the popular, reader-generated <a href="http://www.flickr.com/groups/dcist/pool" target="_blank">DCist Flickr photo pool</a>.  Each day, DCist.com selects photos from the pool for use in its daily coverage of local news, arts and entertainment, food and sports.</span></span></em></p>
<p><em><span style="color:#808080;"><span style="font-family:Times New Roman;"> </span><span style="font-family:Times New Roman;">This year&#8217;s opening reception will be bigger and better than ever, to be held <strong>Saturday, March 6, 2010 from 6 to 10 p.m.</strong> At the bar, mixologist Scott Palmer from <a href="http://www.dino-dc.com/" target="_blank">Dino</a> will have a special punch, Leopold Brothers will host a liquor tasting, and Pabst Blue Ribbon will hold down the fort with plenty of beer.  <a href="http://www.nagerestaurant.com/" target="_blank">Nage</a> will provide hor&#8217;dourves, while DJs v:shal kanwar and Sequoia spin tunes.  Reception is $5 per guest at the door.</span></span></em></p>
<p><span style="color:#808080;"><em><span style="font-family:Times New Roman;">Long View Gallery is located at 1234 9th St. NW,</span><span style="font-family:Times New Roman;"> just a few blocks from the Mt. Vernon/Convention Center Metro. </span><span style="font-family:Times New Roman;"> The 2009 DCist Exposed event welcomed over 1,000 people on opening night, and with this even larger venue, we expect our biggest crowd ever.</span><span style="font-family:Times New Roman;"> </span></em><span style="font-family:Times New Roman;"><em>All photographs selected and displayed at DCist Exposed will be for sale at prices well below traditional gallery shows.  Regular gallery hours are Wednesday-Saturday, 11 a.m. to 6 p.m., and Sunday, 12 to 5 p.m.</em><br />
</span></span></p>
<blockquote><p><span style="color:#808080;"><span style="font-family:Times New Roman;"> </span></span></p>
<p><span style="color:#808080;"><span style="font-family:Times New Roman;"><br />
</span></span></p>
<p><span style="font-family:Times New Roman;"><span style="color:#808080;">The 2010 DCist Exposed Photography Show is sponsored by <a href="http://tenmilessquare.com/events" target="_blank">Ten Miles Square</a>, <a href="http://www.pinklineproject.com/" target="_blank">Pink Line Project</a>, and <a href="http://www.pabstblueribbon.com/" target="_blank">Pabst Blue Ribbon</a>.</span><br />
</span></p></blockquote>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/art/'>art</a>, <a href='http://sintixerr.wordpress.com/category/dcist/'>DCist</a>, <a href='http://sintixerr.wordpress.com/category/local/district-of-columbia/'>District of Columbia</a>, <a href='http://sintixerr.wordpress.com/category/art/events/'>Events</a>, <a href='http://sintixerr.wordpress.com/category/art/events/gallery/'>Gallery</a>, <a href='http://sintixerr.wordpress.com/category/local/'>Local</a>, <a href='http://sintixerr.wordpress.com/category/other-artists/'>Other Artists</a>, <a href='http://sintixerr.wordpress.com/category/personal/'>Personal</a>, <a href='http://sintixerr.wordpress.com/category/art/source-material/photo/'>Photo</a>, <a href='http://sintixerr.wordpress.com/category/photography/'>Photography</a>, <a href='http://sintixerr.wordpress.com/category/local/washington-dc/'>Washington DC</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/2010/'>2010</a>, <a href='http://sintixerr.wordpress.com/tag/art/'>art</a>, <a href='http://sintixerr.wordpress.com/tag/dcist-exposed/'>DCist Exposed</a>, <a href='http://sintixerr.wordpress.com/tag/event/'>event</a>, <a href='http://sintixerr.wordpress.com/tag/jack-whitsitt/'>Jack Whitsitt</a>, <a href='http://sintixerr.wordpress.com/tag/juried/'>juried</a>, <a href='http://sintixerr.wordpress.com/tag/liquor-tasting/'>liquor tasting</a>, <a href='http://sintixerr.wordpress.com/tag/long-view-gallery/'>long view gallery</a>, <a href='http://sintixerr.wordpress.com/tag/open-bar/'>open bar</a>, <a href='http://sintixerr.wordpress.com/tag/paivi-salonen/'>Paivi Salonen</a>, <a href='http://sintixerr.wordpress.com/tag/photo/'>Photo</a>, <a href='http://sintixerr.wordpress.com/tag/photography/'>Photography</a>, <a href='http://sintixerr.wordpress.com/tag/show/'>show</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/655/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/655/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/655/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/655/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/655/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/655/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/655/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/655/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/655/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/655/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/655/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/655/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/655/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/655/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=655&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/02/28/off-topic-juried-into-dcist-exposed-2010-come-out-to-see-march-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>

		<media:content url="http://farm4.static.flickr.com/3607/3412542907_7297d2c95e_b.jpg" medium="image" />
	</item>
		<item>
		<title>Pkviz Packet Visualization Animator Source Code Available</title>
		<link>http://sintixerr.wordpress.com/2010/02/20/pkviz-packet-visualization-animator-source-code-available/</link>
		<comments>http://sintixerr.wordpress.com/2010/02/20/pkviz-packet-visualization-animator-source-code-available/#comments</comments>
		<pubDate>Sat, 20 Feb 2010 20:46:29 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[code]]></category>
		<category><![CDATA[data visualization]]></category>
		<category><![CDATA[GPL]]></category>
		<category><![CDATA[Graphing]]></category>
		<category><![CDATA[IDS Monitoring]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[information visualization]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[objective-c]]></category>
		<category><![CDATA[Open-source]]></category>
		<category><![CDATA[OSX]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[Projects]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[visualize]]></category>
		<category><![CDATA[animate]]></category>
		<category><![CDATA[animation]]></category>
		<category><![CDATA[bytes]]></category>
		<category><![CDATA[display]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[draw]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[graph]]></category>
		<category><![CDATA[packet]]></category>
		<category><![CDATA[packets]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[pkviz]]></category>
		<category><![CDATA[project]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[source code]]></category>
		<category><![CDATA[structure]]></category>
		<category><![CDATA[tcpdump]]></category>
		<category><![CDATA[visualization]]></category>
		<category><![CDATA[xcode]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=637</guid>
		<description><![CDATA[All - I finally decided to put the Xcode project and associated source for pkviz up for free download and license it under GPL v3. I&#8217;ve created a google code page for it HERE. You can grab a stand alone zip of the source/project HERE. (I&#8217;ve never used SVN before, so what&#8217;s up at the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=637&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>All -</p>
<p>I finally decided to put the Xcode project and associated source for <a href="http://sintixerr.wordpress.com/pkviz-packet-visualizer-and-animator/" target="_blank">pkviz</a> up for free download and license it under <a href="http://www.gnu.org/copyleft/gpl.html" target="_blank">GPL v3</a>.</p>
<p>I&#8217;ve created a google code page for it <a href="http://code.google.com/p/pkviz/" target="_blank">HERE</a>.</p>
<p>You can grab a stand alone zip of the source/project <strong><a href="http://jackwhitsitt.com/pkviz_project_src.zip" target="_blank">HERE</a>. </strong></p>
<p><em>(I&#8217;ve never used SVN before, so what&#8217;s up at the google code page might periodically be fubared, so you might want to start with the zip)</em><strong><br />
</strong></p>
<p>Feel free to download, comment, and please -contribute-. This was my first Objective-C app and first Xcode project, so if it&#8217;s a mess&#8230;well&#8230;deal or help? :)</p>
<p>Just remember the google code page if you want to post some updates or questions.</p>
<p>I&#8217;ve also made some haphazard notes to help people understand the code:</p>
<p>&#8212;&#8211;</p>
<p><em>The aquireData class handles reading the tcpdump text file. It uses Core Data to store the data. If I had to do it over, I wouldn&#8217;t have used Core Data&#8230;but it is what it is.  You can find the data model by double-clicking pkviz_DataModel under the Models folder in the project in Xcode.</em></p>
<p><em>pkGraphView is a subclass of NSView that I use to handle the layers, which are done in Core Animation (easy enough to understand). The view has a delegate function (drawLayer) which I handle in the layerDelegate class to deal with drawing the paths for each layer.</em></p>
<p><em>Everything else is handled by transformData &#8211; it&#8217;s pretty much my controller.</em></p>
<p><em>Rough flow:</em></p>
<p><em>the Load button tells aquireData to parse tcpdump and store in a core data context</em></p>
<p><em>The launch button kicks off transform data, which pulls in the data from the core data context, sticks it into an array, launches a thread to pop out individual packets, and then tells the view when it&#8217;s read to display another packet.  Everything else stops, starts, adjusts the current packet referenced, or aids this animation loop process.</em></p>
<p><em>The main array of packets in transformData is bytepakposSet.  It is an array of packet arrays. packet arrays contain arrays of bytes with 2 values in them: bytevalue, and byteposition</em></p>
<p><em>so, if you wanted to access the third packet in bytepakposSet and see what the byte value of the first byte stored is, you&#8217;d do:</em></p>
<p><em> </em>[[[[bytepakposSet objectAtIndex:2] objectAtIndex:0] objectAtIndex:0] intValue];<em></em></p>
<p><em>if you wanted to get the byte value and position returned in an array:</em></p>
<p><em></em>[[bytepakposSet objectAtIndex:2] objectAtIndex:0]<em></em></p>
<p><em>Core Data doesnt return objects in order, so you dont know ahead of time what order the bytes are in the packet, youll have to sort them by position in packet first. You can find position:<br />
</em><br />
[[[[bytepakposSet objectAtIndex:2] objectAtIndex:0] objectAtIndex:1] intValue];</p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/code/'>code</a>, <a href='http://sintixerr.wordpress.com/category/data-visualization/'>data visualization</a>, <a href='http://sintixerr.wordpress.com/category/gpl/'>GPL</a>, <a href='http://sintixerr.wordpress.com/category/graphing/'>Graphing</a>, <a href='http://sintixerr.wordpress.com/category/ids-monitoring/'>IDS Monitoring</a>, <a href='http://sintixerr.wordpress.com/category/information-security/'>Information Security</a>, <a href='http://sintixerr.wordpress.com/category/information-visualization/'>information visualization</a>, <a href='http://sintixerr.wordpress.com/category/professional/network-security/'>Network Security</a>, <a href='http://sintixerr.wordpress.com/category/objective-c/'>objective-c</a>, <a href='http://sintixerr.wordpress.com/category/open-source/'>Open-source</a>, <a href='http://sintixerr.wordpress.com/category/osx/'>OSX</a>, <a href='http://sintixerr.wordpress.com/category/programming/'>programming</a>, <a href='http://sintixerr.wordpress.com/category/art/projects/'>Projects</a>, <a href='http://sintixerr.wordpress.com/category/technology/'>technology</a>, <a href='http://sintixerr.wordpress.com/category/visualize/'>visualize</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/animate/'>animate</a>, <a href='http://sintixerr.wordpress.com/tag/animation/'>animation</a>, <a href='http://sintixerr.wordpress.com/tag/bytes/'>bytes</a>, <a href='http://sintixerr.wordpress.com/tag/display/'>display</a>, <a href='http://sintixerr.wordpress.com/tag/download/'>download</a>, <a href='http://sintixerr.wordpress.com/tag/draw/'>draw</a>, <a href='http://sintixerr.wordpress.com/tag/free/'>free</a>, <a href='http://sintixerr.wordpress.com/tag/gpl/'>GPL</a>, <a href='http://sintixerr.wordpress.com/tag/graph/'>graph</a>, <a href='http://sintixerr.wordpress.com/tag/open-source/'>Open-source</a>, <a href='http://sintixerr.wordpress.com/tag/packet/'>packet</a>, <a href='http://sintixerr.wordpress.com/tag/packets/'>packets</a>, <a href='http://sintixerr.wordpress.com/tag/pcap/'>pcap</a>, <a href='http://sintixerr.wordpress.com/tag/pkviz/'>pkviz</a>, <a href='http://sintixerr.wordpress.com/tag/project/'>project</a>, <a href='http://sintixerr.wordpress.com/tag/security/'>security</a>, <a href='http://sintixerr.wordpress.com/tag/source-code/'>source code</a>, <a href='http://sintixerr.wordpress.com/tag/structure/'>structure</a>, <a href='http://sintixerr.wordpress.com/tag/tcpdump/'>tcpdump</a>, <a href='http://sintixerr.wordpress.com/tag/visualization/'>visualization</a>, <a href='http://sintixerr.wordpress.com/tag/visualize/'>visualize</a>, <a href='http://sintixerr.wordpress.com/tag/xcode/'>xcode</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/637/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/637/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/637/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/637/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/637/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/637/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/637/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/637/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/637/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/637/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/637/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/637/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/637/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/637/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=637&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/02/20/pkviz-packet-visualization-animator-source-code-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Doing a Lightning Talk at HacDC Feb 23,2010 on BrainQuartz</title>
		<link>http://sintixerr.wordpress.com/2010/02/20/doing-a-lightning-talk-at-hacdc-fed-232010-on-brainquartz/</link>
		<comments>http://sintixerr.wordpress.com/2010/02/20/doing-a-lightning-talk-at-hacdc-fed-232010-on-brainquartz/#comments</comments>
		<pubDate>Sat, 20 Feb 2010 20:46:01 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA["Quartz Composer"]]></category>
		<category><![CDATA[art]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[data visualization]]></category>
		<category><![CDATA[District of Columbia]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[information visualization]]></category>
		<category><![CDATA[Local]]></category>
		<category><![CDATA[music]]></category>
		<category><![CDATA[objective-c]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[Projects]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[visualize]]></category>
		<category><![CDATA[Washington DC]]></category>
		<category><![CDATA[api]]></category>
		<category><![CDATA[brain]]></category>
		<category><![CDATA[brainwaves]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[explain]]></category>
		<category><![CDATA[HacDC]]></category>
		<category><![CDATA[lightning talks]]></category>
		<category><![CDATA[mind]]></category>
		<category><![CDATA[minset]]></category>
		<category><![CDATA[neurosky]]></category>
		<category><![CDATA[short]]></category>
		<category><![CDATA[talk]]></category>
		<category><![CDATA[visualization]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=644</guid>
		<description><![CDATA[All, I&#8217;ll be giving a quick (5 minute) introduction to using Neurosky&#8217;s Mindset API to do cool stuff with your brainwaves &#8211; like making art while you sleep :) &#8211; on 02/23/10 @7:30pm as part of HacDC&#8217;s Lightning Talks (featuring 12 speakers for 5 minutes each).  For the introduction, I&#8217;ll be using the simple Objective-C [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=644&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>All, I&#8217;ll be giving a quick (5 minute) introduction to using <a href="http://www.neurosky.com/" target="_blank">Neurosky&#8217;s</a> Mindset API to do cool stuff with your brainwaves &#8211; like making art while you sleep :) &#8211; on 02/23/10 @7:30pm as part of <a href="http://wiki.hacdc.org/index.php?title=LightningTalks" target="_blank">HacDC&#8217;s Lightning Talks</a> (featuring 12 speakers for 5 minutes each).  For the introduction, I&#8217;ll be using the simple Objective-C server and custom written Quartz Composer plug-in client to display a visualization that response to both your brainwaves and ambient noise/music together. Come out and see!</p>
<p>Check out the example proof-of-code video I did below (a longer post to come tomorrow):</p>
<div class='embed-vimeo' style='text-align:center;'><iframe src='http://player.vimeo.com/video/9484157' width='400' height='300' frameborder='0'></iframe></div>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/category/art/'>art</a>, <a href='http://sintixerr.wordpress.com/category/code/'>code</a>, <a href='http://sintixerr.wordpress.com/category/data-visualization/'>data visualization</a>, <a href='http://sintixerr.wordpress.com/category/local/district-of-columbia/'>District of Columbia</a>, <a href='http://sintixerr.wordpress.com/category/art/events/'>Events</a>, <a href='http://sintixerr.wordpress.com/category/information-visualization/'>information visualization</a>, <a href='http://sintixerr.wordpress.com/category/local/'>Local</a>, <a href='http://sintixerr.wordpress.com/category/music/'>music</a>, <a href='http://sintixerr.wordpress.com/category/objective-c/'>objective-c</a>, <a href='http://sintixerr.wordpress.com/category/programming/'>programming</a>, <a href='http://sintixerr.wordpress.com/category/art/projects/'>Projects</a>, <a href='http://sintixerr.wordpress.com/category/technology/'>technology</a>, <a href='http://sintixerr.wordpress.com/category/visualize/'>visualize</a>, <a href='http://sintixerr.wordpress.com/category/local/washington-dc/'>Washington DC</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/tag/api/'>api</a>, <a href='http://sintixerr.wordpress.com/tag/brain/'>brain</a>, <a href='http://sintixerr.wordpress.com/tag/brainwaves/'>brainwaves</a>, <a href='http://sintixerr.wordpress.com/tag/event/'>event</a>, <a href='http://sintixerr.wordpress.com/tag/explain/'>explain</a>, <a href='http://sintixerr.wordpress.com/tag/hacdc/'>HacDC</a>, <a href='http://sintixerr.wordpress.com/tag/lightning-talks/'>lightning talks</a>, <a href='http://sintixerr.wordpress.com/tag/mind/'>mind</a>, <a href='http://sintixerr.wordpress.com/tag/minset/'>minset</a>, <a href='http://sintixerr.wordpress.com/tag/neurosky/'>neurosky</a>, <a href='http://sintixerr.wordpress.com/tag/short/'>short</a>, <a href='http://sintixerr.wordpress.com/tag/talk/'>talk</a>, <a href='http://sintixerr.wordpress.com/tag/visualization/'>visualization</a>, <a href='http://sintixerr.wordpress.com/tag/visualize/'>visualize</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/644/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=644&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/02/20/doing-a-lightning-talk-at-hacdc-fed-232010-on-brainquartz/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Quartz Composer Webcam Audio Visualizer Video Demos Available</title>
		<link>http://sintixerr.wordpress.com/2010/02/13/quartz-composer-webcam-audio-visualizer-video-demos-available/</link>
		<comments>http://sintixerr.wordpress.com/2010/02/13/quartz-composer-webcam-audio-visualizer-video-demos-available/#comments</comments>
		<pubDate>Sat, 13 Feb 2010 07:02:45 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA["Quartz Composer"]]></category>
		<category><![CDATA[art]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[music]]></category>
		<category><![CDATA[OSX]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[Projects]]></category>
		<category><![CDATA[Technique]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[artistic]]></category>
		<category><![CDATA[audio]]></category>
		<category><![CDATA[composition]]></category>
		<category><![CDATA[demo]]></category>
		<category><![CDATA[examples]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[visualizer]]></category>
		<category><![CDATA[webcam]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=630</guid>
		<description><![CDATA[As promised in the previous post, here are demo videos of my three new Quartz Composer Webcam Audio Visualizer compositions. I&#8217;m being a bit silly in them, but that&#8217;s because I dont have an external webcam or anything else more artistic to point it at tonight. In the future, I might do a real non-demo [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=630&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As promised in the previous post, here are demo videos of my <a href="http://sintixerr.wordpress.com/quartz-composer-downloads/" target="_blank">three new Quartz Composer Webcam Audio Visualizer compositions</a>. I&#8217;m being a bit silly in them, but that&#8217;s because I dont have an external webcam or anything else more artistic to point it at tonight. In the future, I might do a real non-demo piece of art with one or more of these. No promises, though.  Next post will be about security, though, I swear. :)</p>
<div class='embed-vimeo' style='text-align:center;'><iframe src='http://player.vimeo.com/video/9419711' width='400' height='300' frameborder='0'></iframe></div>
<div class='embed-vimeo' style='text-align:center;'><iframe src='http://player.vimeo.com/video/9419705' width='400' height='300' frameborder='0'></iframe></div>
<div class='embed-vimeo' style='text-align:center;'><iframe src='http://player.vimeo.com/video/9419687' width='400' height='300' frameborder='0'></iframe></div>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/category/art/'>art</a>, <a href='http://sintixerr.wordpress.com/category/art/technique/media/digital/'>digital</a>, <a href='http://sintixerr.wordpress.com/category/music/'>music</a>, <a href='http://sintixerr.wordpress.com/category/osx/'>OSX</a>, <a href='http://sintixerr.wordpress.com/category/art/technique/performance/'>performance</a>, <a href='http://sintixerr.wordpress.com/category/art/projects/'>Projects</a>, <a href='http://sintixerr.wordpress.com/category/art/technique/'>Technique</a>, <a href='http://sintixerr.wordpress.com/category/technology/'>technology</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/tag/art/'>art</a>, <a href='http://sintixerr.wordpress.com/tag/artistic/'>artistic</a>, <a href='http://sintixerr.wordpress.com/tag/audio/'>audio</a>, <a href='http://sintixerr.wordpress.com/tag/composition/'>composition</a>, <a href='http://sintixerr.wordpress.com/tag/demo/'>demo</a>, <a href='http://sintixerr.wordpress.com/tag/examples/'>examples</a>, <a href='http://sintixerr.wordpress.com/tag/free/'>free</a>, <a href='http://sintixerr.wordpress.com/tag/mac/'>mac</a>, <a href='http://sintixerr.wordpress.com/tag/os-x/'>os x</a>, <a href='http://sintixerr.wordpress.com/tag/programming/'>programming</a>, <a href='http://sintixerr.wordpress.com/tag/video/'>video</a>, <a href='http://sintixerr.wordpress.com/tag/visualizer/'>visualizer</a>, <a href='http://sintixerr.wordpress.com/tag/webcam/'>webcam</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/630/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=630&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/02/13/quartz-composer-webcam-audio-visualizer-video-demos-available/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>New Webcam Audio Visualizing Compositions Available for Download</title>
		<link>http://sintixerr.wordpress.com/2010/02/07/new-webcam-audio-visualizing-compositions-available-for-download/</link>
		<comments>http://sintixerr.wordpress.com/2010/02/07/new-webcam-audio-visualizing-compositions-available-for-download/#comments</comments>
		<pubDate>Sun, 07 Feb 2010 18:38:32 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA["Quartz Composer"]]></category>
		<category><![CDATA[art]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[music]]></category>
		<category><![CDATA[OSX]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[Projects]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[visualize]]></category>
		<category><![CDATA[audio]]></category>
		<category><![CDATA[compositions]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[examples]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[quartz compositions]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[visualization]]></category>
		<category><![CDATA[visualizer]]></category>
		<category><![CDATA[VJ]]></category>
		<category><![CDATA[webcam]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=625</guid>
		<description><![CDATA[Well, the HacDC Hacker&#8217;s Lounge event/party got canceled &#8211; which was too bad. However, I did write some valuable code and make some pretty cool looking new compositions. The code isn&#8217;t ready for release, but I did put up the compositions and they&#8217;re available for free download here: http://sintixerr.wordpress.com/quartz-composer-downloads/ I don&#8217;t have video for them [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=625&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Well, the HacDC Hacker&#8217;s Lounge event/party got canceled &#8211; which was too bad. However, I did write some valuable code and make some pretty cool looking new compositions. The code isn&#8217;t ready for release, but I did put up the compositions and they&#8217;re available for free download here: <a href="http://sintixerr.wordpress.com/quartz-composer-downloads/" target="_blank">http://sintixerr.wordpress.com/quartz-composer-downloads/</a></p>
<p>I don&#8217;t have video for them yet (maaaybe later today), so you&#8217;ll just have to try them out for yourself. I actually like all three of these much more than the original.</p>
<p>Remember, OS X / Quartz Composer only.</p>
<p>( Hmm. I guess I should write a viewer for these so you don&#8217;t need Quartz. Many projects, little time, but we&#8217;ll see&#8230; )</p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/category/art/'>art</a>, <a href='http://sintixerr.wordpress.com/category/code/'>code</a>, <a href='http://sintixerr.wordpress.com/category/art/technique/media/digital/'>digital</a>, <a href='http://sintixerr.wordpress.com/category/music/'>music</a>, <a href='http://sintixerr.wordpress.com/category/osx/'>OSX</a>, <a href='http://sintixerr.wordpress.com/category/programming/'>programming</a>, <a href='http://sintixerr.wordpress.com/category/art/projects/'>Projects</a>, <a href='http://sintixerr.wordpress.com/category/technology/'>technology</a>, <a href='http://sintixerr.wordpress.com/category/visualize/'>visualize</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/tag/art/'>art</a>, <a href='http://sintixerr.wordpress.com/tag/audio/'>audio</a>, <a href='http://sintixerr.wordpress.com/tag/compositions/'>compositions</a>, <a href='http://sintixerr.wordpress.com/tag/download/'>download</a>, <a href='http://sintixerr.wordpress.com/tag/examples/'>examples</a>, <a href='http://sintixerr.wordpress.com/tag/free/'>free</a>, <a href='http://sintixerr.wordpress.com/tag/quartz-compositions/'>quartz compositions</a>, <a href='http://sintixerr.wordpress.com/tag/tool/'>tool</a>, <a href='http://sintixerr.wordpress.com/tag/video/'>video</a>, <a href='http://sintixerr.wordpress.com/tag/visualization/'>visualization</a>, <a href='http://sintixerr.wordpress.com/tag/visualizer/'>visualizer</a>, <a href='http://sintixerr.wordpress.com/tag/vj/'>VJ</a>, <a href='http://sintixerr.wordpress.com/tag/webcam/'>webcam</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/625/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/625/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/625/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/625/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/625/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/625/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/625/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=625&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/02/07/new-webcam-audio-visualizing-compositions-available-for-download/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Spinning Video Treats at HackDC After Shmoocon Friday</title>
		<link>http://sintixerr.wordpress.com/2010/02/03/spinning-video-treats-at-hackdc-after-shmoocon-friday/</link>
		<comments>http://sintixerr.wordpress.com/2010/02/03/spinning-video-treats-at-hackdc-after-shmoocon-friday/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 04:29:17 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA["Quartz Composer"]]></category>
		<category><![CDATA[art]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[District of Columbia]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[interactive]]></category>
		<category><![CDATA[Local]]></category>
		<category><![CDATA[music]]></category>
		<category><![CDATA[Washington DC]]></category>
		<category><![CDATA[Booze]]></category>
		<category><![CDATA[Daniel Packer]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[Friday]]></category>
		<category><![CDATA[HacDC]]></category>
		<category><![CDATA[Hacker's Lounge]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[party]]></category>
		<category><![CDATA[Shmoocon]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=605</guid>
		<description><![CDATA[EDIT: THIS HAS BEEN CANCELED DUE TO SNOW. Not sure what to do after shmoocon Friday night? Not going to the con but need something to do? Come over to the HacDC Hacker&#8217;s Lounge event for a little while (runs 8pm-2am). I&#8217;ve been putting some fun NEW interactive Quartz video projections together for the event [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=605&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>EDIT: THIS HAS BEEN CANCELED DUE TO SNOW.</strong> Not sure what to do after <a href="http://shmoocon.org/" target="_blank">shmoocon</a> Friday night? Not going to the con but need something to do? Come over to the <a href="http://hacdc.org" target="_blank">HacDC</a> Hacker&#8217;s Lounge event for a little while (runs 8pm-2am). I&#8217;ve been putting some fun <strong>NEW</strong> interactive <a href="http://vimeo.com/2792245" target="_blank">Quartz video</a> projections together for the event (link goes to early older work &#8211; need to show up to see newer stuff) and <a href="http://wiki.hacdc.org/index.php/User:Obscurite" target="_blank">Daniel Packer</a> will be doing some audio with supercollider. Oh yeah, and I hear there will be booze.</p>
<p>I can&#8217;t tell you if there will be 10 people or 100 there, but if you take a chance and show up, that&#8217;s 1 closer to 100 :)</p>
<br />Filed under: <a href='http://sintixerr.wordpress.com/category/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/category/art/'>art</a>, <a href='http://sintixerr.wordpress.com/category/art/technique/media/digital/'>digital</a>, <a href='http://sintixerr.wordpress.com/category/local/district-of-columbia/'>District of Columbia</a>, <a href='http://sintixerr.wordpress.com/category/art/events/'>Events</a>, <a href='http://sintixerr.wordpress.com/category/hacking/'>hacking</a>, <a href='http://sintixerr.wordpress.com/category/art/technique/style/interactive/'>interactive</a>, <a href='http://sintixerr.wordpress.com/category/local/'>Local</a>, <a href='http://sintixerr.wordpress.com/category/music/'>music</a>, <a href='http://sintixerr.wordpress.com/category/local/washington-dc/'>Washington DC</a> Tagged: <a href='http://sintixerr.wordpress.com/tag/quartz-composer/'>&quot;Quartz Composer&quot;</a>, <a href='http://sintixerr.wordpress.com/tag/art/'>art</a>, <a href='http://sintixerr.wordpress.com/tag/booze/'>Booze</a>, <a href='http://sintixerr.wordpress.com/tag/daniel-packer/'>Daniel Packer</a>, <a href='http://sintixerr.wordpress.com/tag/event/'>event</a>, <a href='http://sintixerr.wordpress.com/tag/friday/'>Friday</a>, <a href='http://sintixerr.wordpress.com/tag/hacdc/'>HacDC</a>, <a href='http://sintixerr.wordpress.com/tag/hackers-lounge/'>Hacker's Lounge</a>, <a href='http://sintixerr.wordpress.com/tag/hackers/'>hackers</a>, <a href='http://sintixerr.wordpress.com/tag/music/'>music</a>, <a href='http://sintixerr.wordpress.com/tag/party/'>party</a>, <a href='http://sintixerr.wordpress.com/tag/shmoocon/'>Shmoocon</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/605/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/605/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/605/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=605&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/02/03/spinning-video-treats-at-hackdc-after-shmoocon-friday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Google Attacks, China, and Where We All Are</title>
		<link>http://sintixerr.wordpress.com/2010/01/12/google-attacks-china-and-where-we-all-are/</link>
		<comments>http://sintixerr.wordpress.com/2010/01/12/google-attacks-china-and-where-we-all-are/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 00:46:20 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[business architecture]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Enterprise Security Architecture]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[censorship]]></category>
		<category><![CDATA[current events]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[ghostnet]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security architecture]]></category>
		<category><![CDATA[strategy]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=594</guid>
		<description><![CDATA[By the time you read this tomorrow, you&#8217;ll probably already be aware that Google, because of broad, sophisticated, targeted attacks, will stop censoring its searches in China and will consider pulling out of the country altogether. http://googleblog.blogspot.com/2010/01/new-approach-to-china.html I dont know any more than anyone else about this, but it highlights something very important that I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=594&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>By the time you read this tomorrow, you&#8217;ll probably already be aware that <a href="http://google.com" target="_blank">Google</a>, because of broad, sophisticated, targeted attacks, will stop censoring its searches in China and will consider pulling out of the country altogether. <a title="google attacked by china no more censorship" href="http://googleblog.blogspot.com/2010/01/new-approach-to-china.html" target="_blank">http://googleblog.blogspot.com/2010/01/new-approach-to-china.html</a></p>
<p>I dont know any more than anyone else about this, but it highlights something very important that I think gets lost in a lot of our security discussions:</p>
<p><strong>We&#8217;re all at risk, there are active threat actors, and state of the art doesn&#8217;t work.</strong> While I&#8217;m sure Google isnt perfect in the internal security arena, I can&#8217;t help but think it makes an above average attempt at security and uses some very bright people. For them to be attacked in such a way that it makes them reevaluate their business strategy in a market as large as China&#8217;s, it had to have been some pretty nasty stuff.</p>
<p>It makes you wonder &#8211; or it should. <strong>How does that bode for the rest of us arguing about putting in half-assed security controls and using 10 year old security architectures and paying lip service to security because we don&#8217;t really believe in the threats?</strong></p>
<p>And, by the way, executives, this is your issue, not ours.  How -could- your business be negatively impacted by compromises? Reductions in service? Lost data? Have you thought about that? Have you made those operational requirements? Have you looked beyond compliance to &#8220;security&#8221;? Maybe you should. Then tell us how you want to play it, and we&#8217;ll build it for you.</p>
<p>(Hey, while youre here &#8211; Im getting a ton of hits on this &#8211; check out the t-shirts for sale, yeh? Theyre pretty cool ;) <a href="http://zazzle.com/sintixerr" target="_blank">http://zazzle.com/sintixerr</a> )</p>
<br />Posted in business architecture, China, Cyber Security, Enterprise Security Architecture, government, hacking, Information Security, risk management Tagged: attacks, Business, censorship, China, current events, Cyber Security, data security, event, ghostnet, google, hacks, news, security architecture, strategy <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/594/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/594/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/594/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=594&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2010/01/12/google-attacks-china-and-where-we-all-are/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Data Visualization Art Prints Available for Purchase</title>
		<link>http://sintixerr.wordpress.com/2009/12/20/data-visualization-art-prints-available-for-purchase/</link>
		<comments>http://sintixerr.wordpress.com/2009/12/20/data-visualization-art-prints-available-for-purchase/#comments</comments>
		<pubDate>Sun, 20 Dec 2009 17:53:03 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[art]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[data visualization]]></category>
		<category><![CDATA[Graphing]]></category>
		<category><![CDATA[information visualization]]></category>
		<category><![CDATA[Projects]]></category>
		<category><![CDATA[Source Material]]></category>
		<category><![CDATA[store]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[abstract]]></category>
		<category><![CDATA[aesthetics]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[artistic]]></category>
		<category><![CDATA[artwork]]></category>
		<category><![CDATA[data visualization art]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[form]]></category>
		<category><![CDATA[function]]></category>
		<category><![CDATA[prints]]></category>
		<category><![CDATA[purchase]]></category>
		<category><![CDATA[sale]]></category>
		<category><![CDATA[scatterplot]]></category>
		<category><![CDATA[security visualization]]></category>
		<category><![CDATA[viz]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=589</guid>
		<description><![CDATA[I guess once I get going, I keep going for awhile. Recently, I put up some T-shirts for sale which use my art for designs. However, after a few years of showing them, I also wanted to get some of my data and security visualization art available as well and, yesterday, I finally did it.  [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=589&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I guess once I get going, I keep going for awhile. Recently, I put up some <a href="http://zazzle.com/sintixerr" target="_blank">T-shirts for sale</a> which use my art for designs. However, after a few years of showing them, I also wanted to get some of <a href="http://sintixerr.wordpress.com/art-versions-of-data-visualizations/" target="_blank">my data and security visualization art</a> available as well and, yesterday, I finally did it.  You can click here to go to the store:</p>
<p><a title="Data Visualization Art for Sale" href="http://www.zazzle.com/sintixerr/gifts?cg=196575264651641158" target="_blank">Data Visualization Art Prints</a></p>
<p>Some of these don&#8217;t look quite as surreal or &#8220;clean&#8221; as other data visualization art, but that&#8217;s because I&#8217;m very interested in the specific cross-section of usability and &#8220;prettiness&#8221; in the aesthetics of images: The place where what makes them useful is also what makes them attractive. Finding that line, in my mind, is what makes them &#8220;art&#8221;.  One could make some really cool looking images out of most semi-structured data, but it would cease to be useful. The ones here retain their function to security and data analysts while, at the same time, being attractive pieces.</p>
<p>If you&#8217;re interested in other security visualization information, try <a href="http://secviz.org" target="_blank">secviz.org</a></p>
<br />Posted in art, Business, cyberspace, data visualization, Graphing, information visualization, Projects, Source Material, store, technology Tagged: abstract, aesthetics, analysis, art, artistic, artwork, data visualization art, digital, form, function, Graphing, prints, purchase, sale, scatterplot, security visualization, store, viz <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/589/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/589/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/589/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/589/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/589/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/589/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/589/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/589/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/589/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/589/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/589/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/589/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/589/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/589/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=589&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2009/12/20/data-visualization-art-prints-available-for-purchase/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>I&#8217;ll be going to FloCon this year &#8211; are you?</title>
		<link>http://sintixerr.wordpress.com/2009/11/30/ill-be-going-to-flocon-this-year-are-you/</link>
		<comments>http://sintixerr.wordpress.com/2009/11/30/ill-be-going-to-flocon-this-year-are-you/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 19:06:36 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[Correlation]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[IDS Monitoring]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[SEM]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[con]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[data analysis]]></category>
		<category><![CDATA[flocon]]></category>
		<category><![CDATA[flow]]></category>
		<category><![CDATA[ics-cert]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[intrusion]]></category>
		<category><![CDATA[net]]></category>
		<category><![CDATA[net flow]]></category>
		<category><![CDATA[new orleans]]></category>
		<category><![CDATA[packet visualization]]></category>
		<category><![CDATA[pkviz]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[silk]]></category>
		<category><![CDATA[state-of-the-art]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=569</guid>
		<description><![CDATA[In a bit of fun and interesting timing it turns out I&#8217;ll be going to flocon in New Orleans this January. Since I&#8217;ve spent the past 2-3 years doing business risk and security architecture, national sector level strategy, policy, etc&#8230;.but now find myself getting into the technical details of building a CERT (ICS-CERT, specifically)&#8230;it&#8217;s suddenly [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=569&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In a bit of fun and interesting timing it turns out I&#8217;ll be going to <a href="http://www.cert.org/flocon/" target="_blank">flocon</a> in New Orleans this January.</p>
<p>Since I&#8217;ve spent the past 2-3 years doing business risk and security architecture, national sector level strategy, policy, etc&#8230;.but now find myself getting into the technical details of building a CERT (<a href="http://www.us-cert.gov/control_systems/pdf/ICS-CERT_Fact_Sheet_02c.pdf" target="_blank">ICS-CERT</a>, specifically)&#8230;it&#8217;s suddenly time to get more up to speed on flows and how people are using them these days (Especially since I&#8217;d previously spent most of my time with firewalls and IDS data and not netflow / <a href="http://tools.netsa.cert.org/silk/index.html" target="_blank">SiLK</a> stuff).</p>
<p>My work on and release of <a href="../pkviz-packet-visualizer-and-animator/" target="_blank">pkviz</a> this past weekend has helped a bit to get me re-focused on data analysis and playing with correlation tools and methodologies, but I&#8217;m still finding it odd going back to my earlier technology-centric security role  &#8211; which I&#8217;d thought I&#8217;d given up.  My head space has to be completely different than it was and I have to work around what some have called my fatalistic belief that technical security measures and analysis are doomed to fail in the face of our complete lack of interest in doing business risk architectures.</p>
<p>What scares me a little, though, is when I&#8217;ve been talking to people and doing research lately, <strong>it seems the state of the art of IDS, Flows, SEMS, SIEMS, network data analysis, etc. hasn&#8217;t changed all that much in the past few years.</strong> More vendors have sold more products, but they still do the same (questionable) things it seems. What gives? Am I off base?</p>
<p>Still, I&#8217;m pretty excited to get back into this type of thing and about the con. Who&#8217;s going to be there?</p>
<br />Posted in Correlation, Cyber Security, Events, IDS Monitoring, Information Security, Network Security, Professional, risk, SEM, SIEM Tagged: con, conference, data analysis, flocon, flow, ics-cert, IDS, intrusion, net, net flow, new orleans, packet visualization, pkviz, security, silk, state-of-the-art <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/569/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=569&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2009/11/30/ill-be-going-to-flocon-this-year-are-you/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Packet Visualizer/Animator DONE! (ish) and Tool Posted for Download</title>
		<link>http://sintixerr.wordpress.com/2009/11/28/packet-visualizeranimator-done-ish-and-posted/</link>
		<comments>http://sintixerr.wordpress.com/2009/11/28/packet-visualizeranimator-done-ish-and-posted/#comments</comments>
		<pubDate>Sat, 28 Nov 2009 19:06:53 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[art]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[Correlation]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[data visualization]]></category>
		<category><![CDATA[Graphing]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[information visualization]]></category>
		<category><![CDATA[objective-c]]></category>
		<category><![CDATA[OSX]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[Projects]]></category>
		<category><![CDATA[Source Material]]></category>
		<category><![CDATA[visualize]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[animation]]></category>
		<category><![CDATA[animator]]></category>
		<category><![CDATA[application]]></category>
		<category><![CDATA[cycle]]></category>
		<category><![CDATA[display]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[graph]]></category>
		<category><![CDATA[grapher]]></category>
		<category><![CDATA[gui]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[packet]]></category>
		<category><![CDATA[pkviz]]></category>
		<category><![CDATA[plotter]]></category>
		<category><![CDATA[structure]]></category>
		<category><![CDATA[tcpdump]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[traffic]]></category>
		<category><![CDATA[visualization]]></category>
		<category><![CDATA[visualizer]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=557</guid>
		<description><![CDATA[Whew. I can relax. For the past 2-3 months, I&#8217;ve been working on my first real Objective-C project (my iphone app is still going, it just took a back seat to this): An application that will read tcpdump output and animate the packets over time using their inherent byte / packet structure And now&#8230;it&#8217;s up [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=557&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Whew. I can relax.</p>
<p>For the past 2-3 months, I&#8217;ve been working on my first real <a href="http://en.wikipedia.org/wiki/Objective-C" target="_blank">Objective-C</a> project (my iphone app is still going, it just took a back seat to this): An application that will read <a href="http://en.wikipedia.org/wiki/Tcpdump" target="_blank">tcpdump</a> output and animate the packets over time using their inherent <a href="http://www.comsci.us/datacom/ippacket.html" target="_blank">byte / packet structure</a></p>
<p>And now&#8230;it&#8217;s up and in beta-ish quality. (Meaning it works, though some error checking and minor features arent quite where I want them.)</p>
<p><strong>You can download it here for free: <a href="http://sintixerr.wordpress.com/pkviz-packet-visualizer-and-animator/" target="_blank">http://sintixerr.wordpress.com/pkviz-packet-visualizer-and-animator/</a></strong></p>
<p>See it in motion here:</p>
<span style="text-align:center; display: block;"><a href="http://sintixerr.wordpress.com/2009/11/28/packet-visualizeranimator-done-ish-and-posted/"><img src="http://img.youtube.com/vi/WmP_Hi6yY04/2.jpg" alt="" /></a></span>
<p>This project was important to me and has been a long time coming. I&#8217;ve wanted to write a packet visualizer since I first started working with data viz 5 or so years ago at <a href="http://www.linkedin.com/companies/netsec" target="_blank">NetSec</a> and was using <a href="http://www.advizorsolutions.com/" target="_blank">Advizor</a>. That tool cost thousands of dollars per seat, didnt really animate (at least the way I needed), and only parsed CSV or databases. The free tools &#8211; like <a href="http://www.gnuplot.info/" target="_blank">GnuPlot</a>, just weren&#8217;t up to the task at all.</p>
<p>I also wanted something that could plot out data in interesting, pretty ways for some art projects I have in mind.</p>
<p>So, I originally started this time around on a quest to write a short python parser for tcpdump ascii hex output to put into &lt;some generic viz tool&gt; just to get started&#8230;but somehow I ended up writing a full-fledged visualizer (my first GUI project ever, I might add!). The learning process was a blast &#8211; I feel like I&#8217;m a much better coder for it &#8211; and I&#8217;ll be able to extend/expand on this to use for other art and security projects that are on my plate or are coming up.</p>
<p>I&#8217;m pretty excited about it. To see this finished through after years of whining to myself about it, procrastinating, and genuinely not having enough time, is pretty awesome. I&#8217;ve even already created a couple of cool shots that I&#8217;m happy to call &#8220;art&#8221; (granted, there is some photoshop processing here, but they&#8217;re both true to their originals!):</p>
<p><a href="http://farm3.static.flickr.com/2639/3986055652_cd263f6f7d_o.jpg" target="_blank"><img class="alignnone" src="http://farm3.static.flickr.com/2639/3986055652_cd263f6f7d_o.jpg" alt="" width="114" height="190" /></a> <a href="http://farm3.static.flickr.com/2728/4128320540_3fc0882aca_o.jpg" target="_blank"><img class="alignnone" src="http://farm3.static.flickr.com/2728/4128320540_3fc0882aca_o.jpg" alt="" width="114" height="190" /></a></p>
<p>Anyway, Mac Users, check out the tool and let me know what you think!</p>
<br />Posted in art, code, Correlation, cyberspace, data visualization, Graphing, Information Security, information visualization, objective-c, OSX, programming, Projects, Source Material, visualize Tagged: analysis, animation, animator, application, code, cycle, display, download, free, graph, grapher, gui, mac, network, objective-c, os x, packet, pkviz, plotter, structure, tcpdump, tool, traffic, visualization, visualize, visualizer <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/557/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/557/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/557/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/557/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/557/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/557/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/557/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/557/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/557/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/557/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/557/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/557/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/557/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/557/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=557&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2009/11/28/packet-visualizeranimator-done-ish-and-posted/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>

		<media:content url="http://farm3.static.flickr.com/2639/3986055652_cd263f6f7d_o.jpg" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2728/4128320540_3fc0882aca_o.jpg" medium="image" />
	</item>
		<item>
		<title>Ruling Out Best Practices</title>
		<link>http://sintixerr.wordpress.com/2009/11/05/ruling-out-best-practices/</link>
		<comments>http://sintixerr.wordpress.com/2009/11/05/ruling-out-best-practices/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 15:19:08 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[business architecture]]></category>
		<category><![CDATA[CIP]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[academic]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[failure of consensus]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[ICSJWG]]></category>
		<category><![CDATA[national]]></category>
		<category><![CDATA[not a panacea]]></category>
		<category><![CDATA[revelation]]></category>
		<category><![CDATA[solution exclusion]]></category>
		<category><![CDATA[solutions]]></category>
		<category><![CDATA[systems design]]></category>
		<category><![CDATA[talk]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=540</guid>
		<description><![CDATA[So I was sitting in a critical infrastructure cyber security talk earlier this week and had a small revelation.  The talk itself wasn&#8217;t all that interesting &#8211; it was another attempt to collect and identify consensus best practices for critical infrastructure security from a governance point of view &#8211; but it still led me down [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=540&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So I was sitting in a critical infrastructure cyber security talk earlier this week and had a small revelation.  The talk itself wasn&#8217;t all that interesting &#8211; it was another attempt to collect and identify consensus best practices for critical infrastructure security from a governance point of view &#8211; but it still led me down a path that surprised me.</p>
<p>The authors of the paper being presented had done interviews and other research and derived a number of principles required for critical infrastructure cyber security governance based on what they commonly heard over and over. At the talk, we had break-out sessions where they were pinging us for our thoughts on their findings.  During the session, I realized that I&#8217;d heard it all before (obviously, right? It&#8217;s a consensus paper) and was wondering why we couldn&#8217;t get past the stale &#8220;wisdom&#8221; repeated ad nauseam without effect&#8230;when it hit me: the use of their paper might be directly opposite of what they might think it is, but it&#8217;s still useful!</p>
<p>The thought process is as follows:</p>
<ol>
<li>Assumption: We all &#8220;agree&#8221; that cybersecurity for critical infrastructure is insufficient and we&#8217;re missing something.</li>
<li>Assumption: The paper represented the community opinion, to date, on what needs to happen for good cyber security</li>
<li>People are trying to improve security, but despite sporadic improvements, we haven&#8217;t made nearly as much progress as we think we should. Something is missing.</li>
</ol>
<p><strong>Conclusion:</strong> Whatever it is we need to do &#8230;..isn&#8217;t in that paper.  If we collect a series of best practices and community consensus on a topic where we generally consider ourselves to have failed, collecting that consensus should be used &#8211; instead of as a driver of activity &#8211; a hint at what won&#8217;t, by itself, get us where we need to be. The lists should be considered things to exclude as solutions to our unidentified sticking points, but the solutions themselves.</p>
<br />Posted in business architecture, CIP, Critical Infrastructure, Cyber Security, government, Information Security, Professional, risk, risk management, technology Tagged: academic, Critical Infrastructure, Cyber Security, cybersecurity, failure of consensus, governance, ICSJWG, national, not a panacea, revelation, risk, solution exclusion, solutions, systems design, talk <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/540/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=540&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2009/11/05/ruling-out-best-practices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>OWASP Podcast Roundtable with myself, Doug Wilson, Matt Fisher, and Dan Phillpot</title>
		<link>http://sintixerr.wordpress.com/2009/10/01/owasp-podcast-roundtable-with-myself-doug-wilson-matt-fisher-and-dan-phillpot/</link>
		<comments>http://sintixerr.wordpress.com/2009/10/01/owasp-podcast-roundtable-with-myself-doug-wilson-matt-fisher-and-dan-phillpot/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 21:41:28 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Enterprise Security Architecture]]></category>
		<category><![CDATA[ESM]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=537</guid>
		<description><![CDATA[You can find it here: http://www.owasp.org/download/jmanico/owasp_podcast_42.mp3 The topic was &#8220;FISMA&#8221; in the context of OWASP and, while I don&#8217;t really do web app security, I&#8217;m still a &#8220;managed assurance&#8221; guy for risk, and I think that fit in well with everyone else&#8217;s perspective.  That said, I hate listening to myself talk, so tell me what [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=537&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>You can find it here: <a href="http://www.owasp.org/download/jmanico/owasp_podcast_42.mp3" target="_blank">http://www.owasp.org/download/jmanico/owasp_podcast_42.mp3</a></p>
<p>The topic was &#8220;FISMA&#8221; in the context of OWASP and, while I don&#8217;t really do web app security, I&#8217;m still a &#8220;managed assurance&#8221; guy for risk, and I think that fit in well with everyone else&#8217;s perspective.  That said, I hate listening to myself talk, so tell me what you think of how it came out &#8211; I haven&#8217;t listened to it yet!</p>
<p>Also, it&#8217;s <a href="http://www.dhs.gov/files/programs/gc_1158611596104.shtm" target="_blank">&#8220;National Cyber Security Awareness&#8221;</a> month. What does that mean? Are we making everyone aware that we&#8217;re all 0wnz0red?  I like the idea &#8211; and socializing security was one of the recommendations that came out of the Estonia Ddos mess &#8211; but I have concerns about how the good intentions here aregoing to pave a specific road to a specific place.  The concern has to do with security productization.</p>
<p>You see, I have a suspicion that we&#8217;re not going to educate people about the nature of security. Or really that we&#8217;re going to get across how &#8220;security&#8221; is really this thing that everyone does all the name and we should stop treating it like this extra set of things we need to do -in addition- to actual requirements.</p>
<p>Instead, I think it&#8217;s going to come out as (from DHS&#8217;s website):</p>
<ul>
<li>Make sure that you have anti-virus software and firewalls installed, properly configured, and up-to-date. New threats are discovered every day, and keeping your software updated is one of the easier ways to protect yourself from an attack. Set your computer to automatically update for you.</li>
<li>Update your operating system and critical program software. Software updates offer the latest protection against malicious activities. Turn on automatic updating if that feature is available.</li>
<li>Back up key files. If you have important files stored on your computer, copy them onto a removable disc and store it in a safe place.</li>
</ul>
<p>This is all admirable stuff, but it&#8217;s dogmatic. Dogma in security leads to blind trust in marketing and products.  Blind trust in marketing and products will never lead to secure systems or computers.</p>
<p>Yes, it&#8217;ll get us baby steps forward, but then we&#8217;ll be left with ye olde &#8220;I did what you asked me, isn&#8217;t that enough?&#8221; faith-based security and we&#8217;ll be in a pickle when we realize that, architecturally, we have some serious work to do to get where we want to be and no one is interested in doing more.</p>
<br />Posted in Cyber Security, Enterprise Security Architecture, ESM, government, Information Security, Network Security, Professional, risk management, technology  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/537/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=537&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2009/10/01/owasp-podcast-roundtable-with-myself-doug-wilson-matt-fisher-and-dan-phillpot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.owasp.org/download/jmanico/owasp_podcast_42.mp3" length="89260067" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>OWASP AppSec DC 2009 Coming Up &#8211; Remember to Register!</title>
		<link>http://sintixerr.wordpress.com/2009/09/12/owasp-appsec-dc-2009-coming-up-remember-to-register/</link>
		<comments>http://sintixerr.wordpress.com/2009/09/12/owasp-appsec-dc-2009-coming-up-remember-to-register/#comments</comments>
		<pubDate>Sat, 12 Sep 2009 12:35:09 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[District of Columbia]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Local]]></category>
		<category><![CDATA[Open-source]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[Washington DC]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[application developer]]></category>
		<category><![CDATA[AppSec]]></category>
		<category><![CDATA[Capital]]></category>
		<category><![CDATA[Capitol]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[DC]]></category>
		<category><![CDATA[developers]]></category>
		<category><![CDATA[IT professionals]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[project management]]></category>
		<category><![CDATA[quality assurance]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security governance]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[testers]]></category>
		<category><![CDATA[Washington]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[website]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=525</guid>
		<description><![CDATA[I just wanted to make sure everyone remembers to register for this great conference in DC this year.  From their website: Press Release August 20th 2009 &#8212; Speaker Agenda Released and Registration Open! We are pleased to announce that the OWASP DC chapter will host the OWASP AppSec 2009 conference in Washington, DC. The AppSec [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=525&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I just wanted to make sure everyone remembers to register for this great conference in DC this year.  From their <a title="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009" href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009" target="_blank">website</a>:</p>
<blockquote><p><span style="color:#000000;"><strong>Press Release August 20th 2009 &#8212; <a title="http://www.owasp.org/images/4/4d/Press_Release_AppSec_DC_August_20th_2009.pdf" rel="nofollow" href="http://www.owasp.org/images/4/4d/Press_Release_AppSec_DC_August_20th_2009.pdf" target="_blank">Speaker Agenda Released and Registration Open!</a></strong></span></p>
<p><span style="color:#000000;">We are pleased to announce that the <a title="http://www.owasp.org/index.php/Washington_DC" rel="nofollow" href="http://www.owasp.org/index.php/Washington_DC" target="_blank">OWASP DC chapter</a> will host the OWASP AppSec 2009 conference in Washington, DC. The AppSec DC OWASP Conference will be a premier gathering of Information Security leaders. Executives from Fortune 500 firms along with technical thought leaders such as security architects and lead developers will be traveling to hear the cutting-edge ideas presented by Information Security’s top talent. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 600-700 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.</span></p>
<p><span style="color:#000000;">AppSec DC 2009 will be held at the <a title="http://www.dcconvention.com/" rel="nofollow" href="http://www.dcconvention.com/" target="_blank">Walter E. Washington Convention Center</a> (801 Mount Vernon Place NW Washington, DC 20001) on November 10th through 13th 2009.</span></p>
<p><span style="color:#000000;"><strong>Who Should Attend AppSec DC 2009:</strong></span></p>
<ul>
<li><span style="color:#000000;">Application Developers</span></li>
<li><span style="color:#000000;">Application Testers and Quality Assurance</span></li>
<li><span style="color:#000000;">Application Project Management and Staff</span></li>
<li><span style="color:#000000;">Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff</span></li>
<li><span style="color:#000000;">Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance</span></li>
<li><span style="color:#000000;">Security Managers and Staff</span></li>
<li><span style="color:#000000;">Executives, Managers, and Staff Responsible for IT Security Governance</span></li>
<li><span style="color:#000000;">IT Professionals Interesting in Improving IT Security</span></li>
</ul>
</blockquote>
<br />Posted in Critical Infrastructure, Cyber Security, District of Columbia, hacking, Information Security, Local, Open-source, Professional, programming, technology, Washington DC Tagged: 2009, application developer, AppSec, Capital, Capitol, CFO, CIO, conference, CTO, DC, developers, IT professionals, OWASP, project management, quality assurance, security, security governance, security management, testers, Washington, web, Web Application Security, website <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/525/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/525/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/525/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/525/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/525/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/525/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/525/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/525/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/525/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/525/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/525/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/525/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/525/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/525/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=525&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2009/09/12/owasp-appsec-dc-2009-coming-up-remember-to-register/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Follow-up: &#8220;Mission Oriented&#8221; cyber security</title>
		<link>http://sintixerr.wordpress.com/2009/09/01/follow-up-mission-oriented-cyber-security/</link>
		<comments>http://sintixerr.wordpress.com/2009/09/01/follow-up-mission-oriented-cyber-security/#comments</comments>
		<pubDate>Wed, 02 Sep 2009 02:06:44 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[business architecture]]></category>
		<category><![CDATA[CIP]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Enterprise Architecture]]></category>
		<category><![CDATA[Enterprise Security Architecture]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[TSA]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=520</guid>
		<description><![CDATA[Al McDougall from Evolutionary Security Management made the following point in response to my last post, and I thought it was useful to repeat it here: &#8220;End result, the system view is lost because everybody works within their part of the behemoth but forgets about the mission.&#8221; He&#8217;s right, of course. Furthermore: &#8220;Mission oriented&#8221; sounds [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=520&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Al McDougall from <a href="http://www.evolutionarysecurity.ca/" target="_blank">Evolutionary Security Management</a> made the following point in response to my <a href="http://sintixerr.wordpress.com/2009/09/01/labels-of-cyber-confusion-and-a-new-job/" target="_blank">last post</a>, and I thought it was useful to repeat it here:</p>
<blockquote><p><span style="color:#000000;">&#8220;End result, the system view is lost because everybody works within their part of the behemoth but forgets about the mission.&#8221;</span></p></blockquote>
<p>He&#8217;s right, of course. Furthermore: &#8220;Mission oriented&#8221; sounds &#8220;fuzzy&#8221; and people tend to blow it off, but it&#8217;s is not &#8211; it&#8217;s quite important.  In western culture, we seem to need to rush to go solve problems, without really ever trying to understand the nature of what we&#8217;re solving. This leads to all sorts of mayhem and things going wrong. We look back and can&#8217;t figure out why our solutions arent working or why they&#8217;re causing all these weird other problems.</p>
<p>What we need to do, instead, is spend our time groking the problems we&#8217;re wrestling with until we understand their deeper natures.  If we learn to ask sufficiently detailed questions, correct elegant answers will present themselves.  This, in many respects, is the essence of <a href="http://www.sabsa-institute.org/" target="_blank">SABSA</a> and Enterprise Architecture (although, especially in the case of the latter, an essence that is often missed).</p>
<p>In the case of cyber security, we absolutely blow past figuring out and AGREEING ON the nature of the problem and rush straight to the &#8220;solving&#8221; phase with perfectly predictable results.</p>
<p>My compatriots at <a href="http://www.tsa.gov/" target="_blank">TSA</a> are asking me to, before I depart for <a href="http://inl.gov" target="_blank">INL</a>,  transition my approach to the role of the <a href="http://www.dhs.gov/files/programs/gc_1179866197607.shtm" target="_blank">SSA</a> in the <a href="http://www.dhs.gov/files/programs/editorial_0827.shtm" target="_blank">NIPP</a> framework, but it really isn&#8217;t detailed or special. Fundamentally it is this: Figure out ahead of time what you&#8217;re asking and why. What is the mission being supported by cyber systems? What do you need to know to make sure those cyber systems continue to enable that mission? Start from the mission and work down. You&#8217;ll get there.</p>
<p>Hmm. Start somewhere and finish? That sounds like &#8220;Alice and Wonderland&#8221; &#8211; <span style="color:#c0c0c0;"><em>&#8220;start at the beginning and, when you get to the end, stop&#8221;</em></span> &#8211; but it also sounds like a &#8220;process&#8221;. A &#8220;process&#8221; is what the NIPP lacks, yes? More to come&#8230;</p>
<br />Posted in business architecture, CIP, Critical Infrastructure, Cyber Security, Enterprise Architecture, Enterprise Security Architecture, government, Information Security, Professional, risk management, TSA  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/520/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=520&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2009/09/01/follow-up-mission-oriented-cyber-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
		<item>
		<title>Labels of Cyber Confusion and a New Job</title>
		<link>http://sintixerr.wordpress.com/2009/09/01/labels-of-cyber-confusion-and-a-new-job/</link>
		<comments>http://sintixerr.wordpress.com/2009/09/01/labels-of-cyber-confusion-and-a-new-job/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 15:46:25 +0000</pubDate>
		<dc:creator>Jack Whitsitt</dc:creator>
				<category><![CDATA[business architecture]]></category>
		<category><![CDATA[CIP]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Enterprise Architecture]]></category>
		<category><![CDATA[Enterprise Security Architecture]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[politics]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[TSA]]></category>
		<category><![CDATA[Critical Infrastructure Protection]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[dhs]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Idaho National Laboratory]]></category>
		<category><![CDATA[INL]]></category>
		<category><![CDATA[job]]></category>
		<category><![CDATA[national strategy]]></category>
		<category><![CDATA[strategy]]></category>
		<category><![CDATA[work]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=513</guid>
		<description><![CDATA[Starting September 14th, I will no longer be contracting to TSA (via KCG, who have been wonderful). Instead, I will be working for Idaho National Labs (INL) onsite at DHS as a liaison between the smart people exploring the vulnerabilities of our nation&#8217;s critical infrastructure and the smart people at DHS CSSP doing the many [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=513&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Starting September 14th, I will no longer be contracting to TSA (via <a href="http://knowledgecg.com" target="_blank">KCG,</a> who have been wonderful). Instead, I will be working for <a href="http://inl.gov" target="_blank">Idaho National Labs (INL)</a> onsite at DHS as a liaison between the smart people exploring the vulnerabilities of our nation&#8217;s critical infrastructure and the smart people at <a href="http://www.us-cert.gov/control_systems/" target="_blank">DHS CSSP</a> doing the many things that they do.</p>
<p>Before I head out, though, I&#8217;d like to comment a little bit on an issue I&#8217;ve dealt with at TSA that I think also extrapolates to national cyber security efforts and is in no way unique to a single agency, or even the government. The issue is the label &#8220;cyber security&#8221;.  At TSA, as at DHS, as within the media, as within popular culture, there is confusion as to what &#8220;cyber security&#8221; means &#8211; even at a very high level. The term gets bandied about so loosely that it means everything and nothing. Still, people are making policy based on it without any definition.  The amorphous nature of the conversation is going to kick us in the pants sooner rather than later. Can we please nail it down more specifically when we discuss &#8220;cyber security&#8221;?</p>
<p>Below, find some areas of confusion that I&#8217;ve personally run into:</p>
<blockquote><p><span style="color:#000000;"><strong>1. The internet, government networks, SCADA/ICS:</strong> This one is simple. When we talk about cyber security, we really need to preface our statements with which of these areas we&#8217;re discussing. They&#8217;re NOT THE SAME and the strategies, ownership, and etc to deal with them are NOT THE SAME either. Over and over again a lack of explicit distinction here burns us.</span></p>
<p><span style="color:#000000;"><strong>2. &#8220;IT Security&#8221; and Technology vs Strategy: </strong>Often, in my role, we were lumped in with what IT Security does: &#8220;Isn&#8217;t that the same thing, only with more computers?&#8221; was a popular sentiment.  There is the concept that these efforts are technical in nature and that they look a lot like FISMA shops: Assess, Remediate, Certify, etc.  against some standard or set of standards.  Nothing could be further from the truth.  &#8220;Cyber security&#8221; issues are of a strategic business and programmatic nature. We know how to fix computers, we don&#8217;t know how to define what security means to our businesses, how computers affect our operations, and we don&#8217;t know our risk appetites. <strong>In other words, &#8220;cyber security&#8221; in an executive (CEO, CFO, COO, CTO, CIO) issue, not one for technologists.</strong></span></p>
<p><span style="color:#000000;"><strong>3. Computers vs Infrastructure vs Business Assets:</strong> We don&#8217;t care in most sectors if our computers work. Really, we don&#8217;t. What we care about is that our energy grid keeps pumping out power, our chemicals get mixed right, our cars are manufactured correctly, our financial transactions are accurate, our goods get delivered on time, etc.  These are the &#8220;assets&#8221; we are protecting. We are not protecting the internet, we are not protecting government computer systems. We are protecting the national operational interests of the United States.</span></p>
<p><span style="color:#000000;"><strong>4. Think globally, act locally</strong>: We&#8217;re so used to thinking about single companies and single systems within those companies that we forget that everything we do cooperates to larger goals. Our enterprise systems work together to achieve business goals which must be protected. Our business goals within critical infrastructure sectors, in aggregate, also work together to support national goals. For instance, the thousands of independent companies in &#8220;the transportation sectors&#8221; all combine to &#8220;move people and goods throughout the US and the world on time, to the correct destination, in acceptable condition&#8221;.   Many decision makers believe that it&#8217;s ok to ignore this larger context and focus on single system security or, at best, enterprise security. This is dangerous. Since these systems are interdependent whether we acknowledge it or not, they can be be used to exploit each other and damage our soft assets (goals) if we don&#8217;t regular take a look at and secure the larger picture.</span></p></blockquote>
<br />Posted in business architecture, CIP, Critical Infrastructure, Enterprise Architecture, Enterprise Security Architecture, government, Information Security, politics, Professional, risk, risk management, TSA Tagged: CIP, Critical Infrastructure, Critical Infrastructure Protection, Cyber Security, dhs, FISMA, Idaho National Laboratory, INL, job, national strategy, strategy, TSA, work <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sintixerr.wordpress.com/513/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sintixerr.wordpress.com/513/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sintixerr.wordpress.com/513/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sintixerr.wordpress.com/513/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sintixerr.wordpress.com/513/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sintixerr.wordpress.com/513/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sintixerr.wordpress.com/513/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sintixerr.wordpress.com/513/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sintixerr.wordpress.com/513/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sintixerr.wordpress.com/513/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sintixerr.wordpress.com/513/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sintixerr.wordpress.com/513/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sintixerr.wordpress.com/513/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sintixerr.wordpress.com/513/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sintixerr.wordpress.com&amp;blog=508319&amp;post=513&amp;subd=sintixerr&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sintixerr.wordpress.com/2009/09/01/labels-of-cyber-confusion-and-a-new-job/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e7b1e66fef13afbf7f55d434a3d848e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Jack Whitsitt</media:title>
		</media:content>
	</item>
	</channel>
</rss>
