<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.1.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>New York Snort Users Group</title>
	<link>http://www.nycsnort.org</link>
	<description></description>
	<pubDate>Tue, 29 Jun 2010 16:52:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.1.2</generator>
	<language>en</language>
			<item>
		<title>IMPORTANT Rule Download Change</title>
		<link>http://www.nycsnort.org/?p=68</link>
		<comments>http://www.nycsnort.org/?p=68#comments</comments>
		<pubDate>Tue, 29 Jun 2010 16:52:39 +0000</pubDate>
		<dc:creator>jonbaer</dc:creator>
		
		<category><![CDATA[VRT]]></category>

		<guid isPermaLink="false">http://www.nycsnort.org/?p=68</guid>
		<description><![CDATA[According to VRT blog &#8230;
Today the Snort Web Team made a change to the way that Snort rules are downloaded from snort.org. Hopefully this will result in faster downloads for most people. The main thing to note though is that the actual file download links have changed.
First, there is no longer any need to add [...]]]></description>
			<content:encoded><![CDATA[<p>According to <a href="http://vrt-sourcefire.blogspot.com/2010/06/important-rule-download-change.html">VRT blog</a> &#8230;</p>
<p>Today the Snort Web Team made a change to the way that Snort rules are downloaded from snort.org. Hopefully this will result in faster downloads for most people. The main thing to note though is that the actual file download links have changed.</p>
<p>First, there is no longer any need to add an &#8220;_s&#8221; to the rule file in order to get the subscriber pack. Second, the link to the file itself has changed:</p>
<p>Old Link:</p>
<p>http://dl.snort.org/reg-rules/snortrules-snapshot-2860.tar.gz?oink_code=<OINKCODE>﻿</p>
<p>New Link:</p>
<p>http://www.snort.org/reg-rules/snortrules-snapshot-2860.tar.gz/<OINKCODE>﻿</p>
<p>You should update your PulledPork and Oinkmaster installations to reflect these changes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nycsnort.org/?feed=rss2&amp;p=68</wfw:commentRss>
		</item>
		<item>
		<title>Solera Networks partner with Sourcefire</title>
		<link>http://www.nycsnort.org/?p=67</link>
		<comments>http://www.nycsnort.org/?p=67#comments</comments>
		<pubDate>Tue, 22 Jun 2010 13:21:03 +0000</pubDate>
		<dc:creator>jonbaer</dc:creator>
		
		<category><![CDATA[Sourcefire]]></category>

		<guid isPermaLink="false">http://www.nycsnort.org/?p=67</guid>
		<description><![CDATA[Solera Networks, a leading network forensics products and services company today announced its partnership with Sourcefire, Inc. (Nasdaq:FIRE), the creators of SNORT® and a leader in intelligent Cybersecurity solutions. Solera Networks can now integrate its award-winning network forensics technology directly into Sourcefire’s event analysis. The integration enhances Sourcefire’s packet analysis functionality to include full session [...]]]></description>
			<content:encoded><![CDATA[<p>Solera Networks, a leading network forensics products and services company today announced its partnership with Sourcefire, Inc. (Nasdaq:FIRE), the creators of SNORT® and a leader in intelligent Cybersecurity solutions. Solera Networks can now integrate its award-winning network forensics technology directly into Sourcefire’s event analysis. The integration enhances Sourcefire’s packet analysis functionality to include full session capture, which provides detailed forensics for any security event. The partnership enables swift incident response to any security event and provides full detail in the interest of understanding &#8220;what happened before and after a security event?&#8221;</p>
<p><a href="http://www.soleranetworks.com/news/solera-networks-and-sourcefire-announce-partnership/">http://www.soleranetworks.com/news/solera-networks-and-sourcefire-announce-partnership/<br />
</a></p>
<p><a href="http://taosecurity.blogspot.com/2010/06/all-aboard-nsm-train.html">http://taosecurity.blogspot.com/2010/06/all-aboard-nsm-train.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nycsnort.org/?feed=rss2&amp;p=67</wfw:commentRss>
		</item>
		<item>
		<title>National Cyber-Security Emergency and Phenomenal Cosmic Power</title>
		<link>http://www.nycsnort.org/?p=66</link>
		<comments>http://www.nycsnort.org/?p=66#comments</comments>
		<pubDate>Tue, 15 Jun 2010 15:22:03 +0000</pubDate>
		<dc:creator>jonbaer</dc:creator>
		
		<category><![CDATA[Notes]]></category>

		<category><![CDATA[Articles]]></category>

		<guid isPermaLink="false">http://www.nycsnort.org/?p=66</guid>
		<description><![CDATA[Matt Olney (of Sourcefire VRT) has read through and analyzed the “Protecting  Cyberspace as a National Asset Act of 2010” (pdf), a 199 page  piece of legislation introduced by Senator Lieberman (I-CT) along with  Senator Susan Collins (R-ME) and Senator Thomas Carper (D-DE).  It is an excellent review of the bill.
Click here [...]]]></description>
			<content:encoded><![CDATA[<p>Matt Olney (of <a href="http://www.snort.org/vrt" title="VRT" target="_blank">Sourcefire VRT</a>) has read through and analyzed the “<em><a href="http://hsgac.senate.gov/public/index.cfm?FuseAction=Files.View&amp;FileStore_id=4ee63497-ca5b-4a4b-9bba-04b7f4cb0123">Protecting  Cyberspace as a National Asset Act of 2010</a></em>” (pdf), a 199 page  piece of legislation introduced by Senator Lieberman (I-CT) along with  Senator Susan Collins (R-ME) and Senator Thomas Carper (D-DE).  It is an excellent review of the bill.</p>
<p><a href="http://vrt-sourcefire.blogspot.com/2010/06/national-cyber-security-emergency-and.html" target="_blank">Click here to read his entire post </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nycsnort.org/?feed=rss2&amp;p=66</wfw:commentRss>
		</item>
		<item>
		<title>Snorby VMware Appliance (Cryptolife)</title>
		<link>http://www.nycsnort.org/?p=64</link>
		<comments>http://www.nycsnort.org/?p=64#comments</comments>
		<pubDate>Mon, 14 Jun 2010 17:35:31 +0000</pubDate>
		<dc:creator>jonbaer</dc:creator>
		
		<category><![CDATA[Tools]]></category>

		<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.nycsnort.org/?p=64</guid>
		<description><![CDATA[The Snorby virtual appliance provides a  preconfigured out of the box Snorby  front-end  for snort, the popular  intrusion detection system . The Snorby  interface is  developed by Dustin  Webber. This appliance is indicated for security professionals with  a depth knowledge of intrusion detection and security  monitoring.   Nevertheless beginners can [...]]]></description>
			<content:encoded><![CDATA[<p>The Snorby virtual appliance provides a  preconfigured out of the box <a href="http://snorby.org/" class="external text" title="http://snorby.org/" rel="nofollow">Snorby</a>  front-end  for <a href="http://www.snort.org/" class="external text" title="http://www.snort.org/" rel="nofollow">snort</a>, the popular  intrusion detection system . The <a href="http://snorby.org/" class="external text" title="http://snorby.org/" rel="nofollow">Snorby</a>  interface is  developed by<a href="http://www.packetport.net/" class="external text" title="http://www.packetport.net/" rel="nofollow"> Dustin  Webber</a>. This appliance is indicated for security professionals with  a depth knowledge of intrusion detection and security  monitoring.   Nevertheless beginners can use the appliance to to understand and learn  about intrusion detection and network security.</p>
<p><a href="http://www.cryptolife.org/index.php/Snorby_virtual_appliance" title="Snorby" target="_blank">Click here for notes and download </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nycsnort.org/?feed=rss2&amp;p=64</wfw:commentRss>
		</item>
		<item>
		<title>Project Razorback™ (formerly known as Near Real-Time Detection)</title>
		<link>http://www.nycsnort.org/?p=63</link>
		<comments>http://www.nycsnort.org/?p=63#comments</comments>
		<pubDate>Mon, 14 Jun 2010 17:30:31 +0000</pubDate>
		<dc:creator>jonbaer</dc:creator>
		
		<category><![CDATA[Articles]]></category>

		<category><![CDATA[Sourcefire]]></category>

		<category><![CDATA[Tools]]></category>

		<category><![CDATA[White papers]]></category>

		<guid isPermaLink="false">http://www.nycsnort.org/?p=63</guid>
		<description><![CDATA[Near Real-Time Detection (Razorback) is the result of extensive research into detection of attacks hidden inside numerous layers of compression, obfuscation, and evasion techniques across multiple file formats. Razorback in its current form is a plugin to the Snort  detection engine. Razorback addresses the issues with file format parsing by separating selected file types [...]]]></description>
			<content:encoded><![CDATA[<p class="indent1">Near Real-Time Detection (Razorback) is the result of extensive research into detection of attacks hidden inside numerous layers of compression, obfuscation, and evasion techniques across multiple file formats. Razorback in its current form is a plugin to the Snort  detection engine. Razorback addresses the issues with file format parsing by separating selected file types from transmitted data, which are then passed to additional detection engines either on local or distributed remote system(s). The intention is for the system to be extensible and not necessarily be a plugin for Snort.</p>
<p class="indent1"><img src="http://www.nycsnort.org/wp-content/uploads/2010/06/screen-shot-2010-06-15-at-110538-am.png" alt="screen-shot-2010-06-15-at-110538-am.png" width="500" /></p>
<p>Future development plans include providing Snort with automatic detection rule updates that an IPS deployment of Snort can use to protect the private network along with further enhancements aimed at data leak prevention. The system will also use templates to describe file types and a simple rule language to detect attacks.</p>
<p class="indent1"> <a href="http://labs.snort.org/razorback/" title="Razorback" target="_blank">Click here for code and presentation</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nycsnort.org/?feed=rss2&amp;p=63</wfw:commentRss>
		</item>
		<item>
		<title>Snort Performance Tuning Webcast - Nov 9th @ 10AM EST</title>
		<link>http://www.nycsnort.org/?p=62</link>
		<comments>http://www.nycsnort.org/?p=62#comments</comments>
		<pubDate>Tue, 03 Nov 2009 01:44:50 +0000</pubDate>
		<dc:creator>jonbaer</dc:creator>
		
		<category><![CDATA[Presentations]]></category>

		<category><![CDATA[Sourcefire]]></category>

		<category><![CDATA[Webinars]]></category>

		<guid isPermaLink="false">http://www.nycsnort.org/?p=62</guid>
		<description><![CDATA[Hi Snort® User,
On behalf of the Snort Team at Sourcefire, I’d like to invite you to attend the next session of the Snort Users Webinar Series.
In this webinar Steve Sturges Snort development team manager will discuss Snort Performance Tuning – Rules and Preprocessors
This discussion will focus on guidelines for tuning Snort based on performance statistics [...]]]></description>
			<content:encoded><![CDATA[<p>Hi Snort® User,</p>
<p>On behalf of the Snort Team at Sourcefire, I’d like to invite you to attend the next session of the Snort Users Webinar Series.</p>
<p>In this webinar Steve Sturges Snort development team manager will discuss Snort Performance Tuning – Rules and Preprocessors</p>
<p>This discussion will focus on guidelines for tuning Snort based on performance statistics from rule and preprocessor profiling and the perfmon preprocessor. It is intended to help Snort administrators when tuning and troubleshooting performance issues. The discussion may also be useful to Snort rule writers for measuring the potential performance impact of their rules</p>
<p>Webinar details:</p>
<p>Date: November 9, 2009<br />
Time: 10:00 AM US Eastern Standard Time (GMT -5:00))</p>
<p>To register for this webinar visit: <a href="https://sourcefire.webex.com/sourcefire/onstage/g.php?t=a&amp;d=792341054">https://sourcefire.webex.com/sourcefire/onstage/g.php?t=a&amp;d=792341054</a></p>
<p>As always this session will be recorded and posted on Snort.org for future use.</p>
<p>I hope you can join us.</p>
<p>Regards,<br />
Mike</p>
<p>Mike Guiterman<br />
Snort Community Manager<br />
Sourcefire, Inc.<br />
mguiterman@sourcefire.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nycsnort.org/?feed=rss2&amp;p=62</wfw:commentRss>
		</item>
		<item>
		<title>NYC Snort User Group Meeting</title>
		<link>http://www.nycsnort.org/?p=61</link>
		<comments>http://www.nycsnort.org/?p=61#comments</comments>
		<pubDate>Mon, 19 Oct 2009 13:14:01 +0000</pubDate>
		<dc:creator>mo</dc:creator>
		
		<category><![CDATA[Meetings]]></category>

		<guid isPermaLink="false">http://www.nycsnort.org/?p=61</guid>
		<description><![CDATA[I&#8217;ve had some calls about holding another Snort User Group meeting soon.  If you are interested shoot me an email at mo@ciphertechs.com
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve had some calls about holding another Snort User Group meeting soon.  If you are interested shoot me an email at mo@ciphertechs.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nycsnort.org/?feed=rss2&amp;p=61</wfw:commentRss>
		</item>
		<item>
		<title>Vulnerability Report August 2009</title>
		<link>http://www.nycsnort.org/?p=60</link>
		<comments>http://www.nycsnort.org/?p=60#comments</comments>
		<pubDate>Tue, 18 Aug 2009 03:52:38 +0000</pubDate>
		<dc:creator>jonbaer</dc:creator>
		
		<category><![CDATA[Presentations]]></category>

		<category><![CDATA[Sourcefire]]></category>

		<category><![CDATA[Webcasts]]></category>

		<guid isPermaLink="false">http://www.nycsnort.org/?p=60</guid>
		<description><![CDATA[




]]></description>
			<content:encoded><![CDATA[<object width="425" height="344">
<param name="movie" value="http://www.youtube.com/v/_L2kkm922LU&#038;rel=0&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en&#038;feature=player_embedded&#038;fs=1"></param>
<param name="allowFullScreen" value="true"></param>
<param name="allowScriptAccess" value="always"></param>
<p><embed src="http://www.youtube.com/v/_L2kkm922LU&#038;rel=0&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en&#038;feature=player_embedded&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="425" height="344"></embed></object>
]]></content:encoded>
			<wfw:commentRss>http://www.nycsnort.org/?feed=rss2&amp;p=60</wfw:commentRss>
		</item>
		<item>
		<title>Rule Performance Part I : Content Matches</title>
		<link>http://www.nycsnort.org/?p=59</link>
		<comments>http://www.nycsnort.org/?p=59#comments</comments>
		<pubDate>Sun, 12 Jul 2009 02:56:50 +0000</pubDate>
		<dc:creator>jonbaer</dc:creator>
		
		<category><![CDATA[Articles]]></category>

		<guid isPermaLink="false">http://www.nycsnort.org/?p=59</guid>
		<description><![CDATA[One of the many things that occupy the time of the VRT is reviewing rule performance data, whether that data is internally generated from one of our test environments or received from customer reports. In the “Rule Performance? series of blog posts, we’ll look at the set of issues that encompass the problematic rule constructs [...]]]></description>
			<content:encoded><![CDATA[<p>One of the many things that occupy the time of the VRT is reviewing rule performance data, whether that data is internally generated from one of our test environments or received from customer reports. In the “Rule Performance? series of blog posts, we’ll look at the set of issues that encompass the problematic rule constructs that we’ve found most significantly impact the performance of Snort sensors. Hopefully you can use this information to add additional detection capability customized to your environment without adding undue processing load.</p>
<p>Read more @ <a href="/2009/07/rule-performance-part-one-content.html ">http://vrt-sourcefire.blogspot.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nycsnort.org/?feed=rss2&amp;p=59</wfw:commentRss>
		</item>
		<item>
		<title>Intro to ClamAV (Screencast)</title>
		<link>http://www.nycsnort.org/?p=58</link>
		<comments>http://www.nycsnort.org/?p=58#comments</comments>
		<pubDate>Thu, 11 Jun 2009 02:40:09 +0000</pubDate>
		<dc:creator>jonbaer</dc:creator>
		
		<category><![CDATA[Presentations]]></category>

		<category><![CDATA[Sourcefire]]></category>

		<category><![CDATA[Webcasts]]></category>

		<guid isPermaLink="false">http://www.nycsnort.org/?p=58</guid>
		<description><![CDATA[Clam AntiVirus (ClamAV) is a free, cross-platform antivirus software tool-kit capable of detecting many types of malicious software, including viruses. One of its main uses is on mail servers as a server-side email virus scanner. The application was developed for Unix and has third party versions available for AIX, BSD, HP-UX, Linux, Mac OS X, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Clam AntiVirus</strong> (<strong>ClamAV</strong>) is a <a href="http://en.wikipedia.org/wiki/Free_software" title="Free software">free</a>, <a href="http://en.wikipedia.org/wiki/Cross-platform" title="Cross-platform">cross-platform</a> <a href="http://en.wikipedia.org/wiki/Antivirus_software" title="Antivirus software">antivirus software</a> tool-kit capable of detecting many types of malicious software, including <a href="http://en.wikipedia.org/wiki/Computer_virus" title="Computer virus">viruses</a>. One of its main uses is on <a href="http://en.wikipedia.org/wiki/Mail_transfer_agent" title="Mail transfer agent">mail servers</a> as a server-side <a href="http://en.wikipedia.org/wiki/Email_virus" title="Email virus" class="mw-redirect">email virus</a> scanner. The application was developed for <a href="http://en.wikipedia.org/wiki/Unix" title="Unix">Unix</a> and has third party versions available for <a href="http://en.wikipedia.org/wiki/IBM_AIX_%28operating_system%29" title="IBM AIX (operating system)" class="mw-redirect">AIX</a>, <a href="http://en.wikipedia.org/wiki/Berkeley_Software_Distribution" title="Berkeley Software Distribution">BSD</a>, <a href="http://en.wikipedia.org/wiki/HP-UX" title="HP-UX">HP-UX</a>, <a href="http://en.wikipedia.org/wiki/Linux" title="Linux">Linux</a>, <a href="http://en.wikipedia.org/wiki/Mac_OS_X" title="Mac OS X">Mac OS X</a>, <a href="http://en.wikipedia.org/wiki/OpenVMS" title="OpenVMS">OpenVMS</a>, <a href="http://en.wikipedia.org/wiki/Tru64_UNIX" title="Tru64 UNIX">OSF</a> and <a href="http://en.wikipedia.org/wiki/Solaris_%28operating_system%29" title="Solaris (operating system)">Solaris</a>. At one time it had a native version available for <a href="http://en.wikipedia.org/wiki/Microsoft_Windows" title="Microsoft Windows">Windows</a>, but that project has been ended.<sup id="cite_ref-ClamAbout_1-0" class="reference"><a href="http://en.wikipedia.org/wiki/Clamav#cite_note-ClamAbout-1"><span></span><span></span></a></sup><sup id="cite_ref-Ports_2-0" class="reference"><a href="http://en.wikipedia.org/wiki/Clamav#cite_note-Ports-2"><span></span><span></span></a></sup><sup id="cite_ref-Windows_3-0" class="reference"><a href="http://en.wikipedia.org/wiki/Clamav#cite_note-Windows-3"><span></span><span></span></a></sup></p>
<p>Both ClamAV and its updates are made available free of charge.</p>
<p><a href="http://en.wikipedia.org/wiki/Sourcefire" title="Sourcefire">Sourcefire</a>, a maker of <a href="http://en.wikipedia.org/wiki/Intrusion_detection" title="Intrusion detection">intrusion detection</a> products and the owner of <a href="http://en.wikipedia.org/wiki/Snort_%28software%29" title="Snort (software)">Snort</a>, announced on 17 August 2007 that it had acquired the <a href="http://en.wikipedia.org/wiki/Trademarks" title="Trademarks" class="mw-redirect">trademarks</a> and <a href="http://en.wikipedia.org/wiki/Copyrights" title="Copyrights" class="mw-redirect">copyrights</a> to ClamAV from five key developers.</p>
<p>Below are 6 screencasts by <span>by Tomasz Kojm discussing: an overview of ClamAV, architecture, deployment and installation, detection mechanism, and troubleshooting. </span></p>
<p>Part I - <a href="http://www.youtube.com/watch?v=hqitIW_XgGI">http://www.youtube.com/watch?v=hqitIW_XgGI</a></p>
<p>Part II - <a href="http://www.youtube.com/watch?v=YWowwh_32cA">http://www.youtube.com/watch?v=YWowwh_32cA</a></p>
<p>Part III - <a href="http://www.youtube.com/watch?v=jElBFo07y5I">http://www.youtube.com/watch?v=jElBFo07y5I</a></p>
<p>Part IV - <a href="http://www.youtube.com/watch?v=wMjMoMcu_4c">http://www.youtube.com/watch?v=wMjMoMcu_4c</a></p>
<p>Part V - <a href="http://www.youtube.com/watch?v=tJvn9AquL6g">http://www.youtube.com/watch?v=tJvn9AquL6g</a></p>
<p>Part VI - <a href="http://www.youtube.com/watch?v=WX2Xdh3KghU">http://www.youtube.com/watch?v=WX2Xdh3KghU</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nycsnort.org/?feed=rss2&amp;p=58</wfw:commentRss>
		</item>
	</channel>
</rss>
