<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Less Is More</title>
	<atom:link href="http://newschoolsecurity.com/2009/11/less-is-more/feed/" rel="self" type="application/rss+xml" />
	<link>http://newschoolsecurity.com/2009/11/less-is-more/</link>
	<description>The Blog Inspired By The Book</description>
	<lastBuildDate>Tue, 07 Feb 2012 02:09:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Christopher Porter</title>
		<link>http://newschoolsecurity.com/2009/11/less-is-more/#comment-552</link>
		<dc:creator>Christopher Porter</dc:creator>
		<pubDate>Wed, 25 Nov 2009 19:33:51 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1058#comment-552</guid>
		<description>I suppose this is another way of saying &quot;know your business&quot; or &quot;know your network&quot;.  

In our DBIR, this would fall into this bucket:  &quot;Define “suspicious” and “anomalous” (then look for whatever “it” is):&quot;</description>
		<content:encoded><![CDATA[<p>I suppose this is another way of saying &#8220;know your business&#8221; or &#8220;know your network&#8221;.  </p>
<p>In our DBIR, this would fall into this bucket:  &#8220;Define “suspicious” and “anomalous” (then look for whatever “it” is):&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy Steingruebl</title>
		<link>http://newschoolsecurity.com/2009/11/less-is-more/#comment-550</link>
		<dc:creator>Andy Steingruebl</dc:creator>
		<pubDate>Wed, 25 Nov 2009 16:54:04 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1058#comment-550</guid>
		<description>The best IDS configuration I ever ran was the SHADOW package that Northcutt&#039;s team put together way back when.  All it was was a bunch of tcpdump filters that you could define for profile of normal traffic, and it would alert you to anything not matching the pattern.

Web server making outbound connections of any sort.
Connects to hosts on ports you weren&#039;t expecting
etc.

The only useful IDS package I ever used.</description>
		<content:encoded><![CDATA[<p>The best IDS configuration I ever ran was the SHADOW package that Northcutt&#8217;s team put together way back when.  All it was was a bunch of tcpdump filters that you could define for profile of normal traffic, and it would alert you to anything not matching the pattern.</p>
<p>Web server making outbound connections of any sort.<br />
Connects to hosts on ports you weren&#8217;t expecting<br />
etc.</p>
<p>The only useful IDS package I ever used.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

