<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Dead Horse Lives</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=611" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=611</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Stuart Berman</title>
		<link>http://spiresecurity.com/?p=611&#038;cpage=1#comment-878</link>
		<dc:creator>Stuart Berman</dc:creator>
		<pubDate>Sun, 03 Apr 2005 02:52:39 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=611#comment-878</guid>
		<description><![CDATA[Beautifully put.

There is a lot of noise out there including that from those with a vested interest. And so much of it seems ridiculous... another RPC vulnerability in my public web server? I guess that is why we block all ports but the essentials ones, but we still patch like crazy and hope the patches do less damage than the threats.

We need to spend more time and thinking on issues like application logging and affordable analysis to see what might really be happening in our environments. Sarbanes may be seriously contributing to solutions now that more logs are being stored. I have advocated the use of data mining tools against those logs to find &#039;interesting&#039; associations - the proverbial needle in a haystack.
]]></description>
		<content:encoded><![CDATA[<p>Beautifully put.</p>
<p>There is a lot of noise out there including that from those with a vested interest. And so much of it seems ridiculous&#8230; another RPC vulnerability in my public web server? I guess that is why we block all ports but the essentials ones, but we still patch like crazy and hope the patches do less damage than the threats.</p>
<p>We need to spend more time and thinking on issues like application logging and affordable analysis to see what might really be happening in our environments. Sarbanes may be seriously contributing to solutions now that more logs are being stored. I have advocated the use of data mining tools against those logs to find &#8216;interesting&#8217; associations &#8211; the proverbial needle in a haystack.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
