I gave a presentation at the conference this year on using ArcSight ESM to catch malware that was not caught by anti-virus software. My slide deck will be available on this site soon. Thank you to everyone that attended the session. It was a packed room. I hope it was worth your time. Any feedback is appreciated!
Sunday, September 18, 2011
I gave a presentation at the conference this year on using ArcSight ESM to catch malware that was not caught by anti-virus software. My slide deck will be available on this site soon. Thank you to everyone that attended the session. It was a packed room. I hope it was worth your time. Any feedback is appreciated!
Monday, May 9, 2011
P2P .... what P2P?
- Security: You have P2P software installed. This is the third time we told you.
- User: I don't know what you're talking about. I didn't do it, nobody saw me do it. Can't prove a thing.
- Security: How about all these movies you have been downloading. Here is the file listing including time stamps.
- User: Oh, those. Oh, right. It was not P2P the movies came from email. Sorry about that. Never happen again.
The trouble is two-fold:
- Bad guys use the same protocols to get data about your company.
- Set up one of these P2P clients wrong and your HR person just shared employee data out to the Internet.
Saturday, September 4, 2010
Fun with a mirror

- Posted using BlogPress from my iPad
Location:Carolina Beach
Sunday, January 11, 2009
Here is a slide show of our trip highlights!
Friday, November 14, 2008
A new chapter at work
Out of all the things I could say, I'd like to highly endorse the Manager Tools website and podcasts. These guys not only know what they are doing, but really convey that knowledge in a way that you can put to use immediately.
Friday, September 26, 2008
ArcSight Logger in front or behind ESM?
This is something I pondered on for quite a while. The mystery was not solved, but revealed quite clearly at the recent user conference. There was a breakout session with architects of the various pieces (ESM, Logger, SmartConnectors, etc) and they discussed the variations.
To me it simply boiled down to this: If you want high performance above all else, put Logger in front of ESM. If you being able have all your correlated events properly connected with EventIDs, then put Logger behind ESM.
For most companies, having Logger in front of ESM may well be what the doctor ordered. This will make sure you have the highest performance and best assurance of not losing events if the database or ESM can not keep up.
If anyone else has other thoughts or I got this confused, let me know in the comments!
Tuesday, September 23, 2008
2008 ArcSight User Conference
The keynote was from the MCI/WorldCom whistleblower, Cynthia Cooper. She tells a great story and really gives you something to think about. It really is amazing to hear about some of the decisions people have to make everyday. I have been lucky not having to deal with anything that heavy, but hope I would make the right decisions if that time ever comes.