<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Passionate about Information Security &#187; Intrusion Detection Systems</title>
	<atom:link href="http://blog.ismaelvalenzuela.com/category/intrusion-detection-systems/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ismaelvalenzuela.com</link>
	<description>on ismaelvalenzuela.com</description>
	<lastBuildDate>Tue, 26 Jan 2010 17:58:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Teaching Community SANS Security 503: Intrusion Detection In-Depth</title>
		<link>http://blog.ismaelvalenzuela.com/2010/01/26/teaching-community-sans-security-503-intrusion-detection-in-depth/</link>
		<comments>http://blog.ismaelvalenzuela.com/2010/01/26/teaching-community-sans-security-503-intrusion-detection-in-depth/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 17:55:59 +0000</pubDate>
		<dc:creator>Ismael Valenzuela</dc:creator>
				<category><![CDATA[Intrusion Detection Systems]]></category>
		<category><![CDATA[Network Security Monitoring]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[Training]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Mike Poor]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=119</guid>
		<description><![CDATA[I'm glad to announce that I will be teaching Community SANS Security 503: Intrusion Detection In-Depth at Banbury, Oxfordshire (UK). This 6-day course will run from Monday, February 15, 2010 through Saturday, February 20, 2010.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m glad to announce that I will be teaching Community SANS <a title="Security 503: Intrusion Detection In-Depth" href="http://www.sans.org/security-training/intrusion-detection-in-depth-43-mid" target="_blank">Security 503: Intrusion Detection In-Depth</a> at Banbury, Oxfordshire (UK). This 6-day course will run from Monday, February 15, 2010 through Saturday, February 20, 2010.</p>
<p>If you haven&#8217;t heard of <a title="Community SANS" href="http://www.sans.org/community_sans/" target="_blank">Community SANS</a> courses before, I encourage you to have a look at this new format (new outside the US, where it&#8217;s been running for years). This is a great way of bringing the popular <a title="SANS Courses" href="http://www.sans.org/security-training/courses.php" target="_blank">SANS courses</a> to your local security community at a reasonable cost, especially for those that can&#8217;t attend the major events.  It&#8217;s worth mentioning that unlike the <a title="SANS Mentor" href="http://www.sans.org/mentor/about.php" target="_blank">SANS Mentor</a>  sessions, these are delivered over a six-day period, just like it is at a larger SANS event, including the full set of books and access to audio files. They are just delivered in your own community, in a small classroom setting and at a discounted cost for tuition and travel expenses.</p>
<p>I&#8217;ve already <a title="SANS 'Itinerary'" href="http://blog.ismaelvalenzuela.com/2009/03/27/from-brussels-to-amsterdam-calling-at-london-and-sydney/" target="_blank">described my experience with SANS</a>, both as student and facilitator, so I won&#8217;t go over that again. Also, you can find a further detailed description of the Security 503 track on <a title="Security 503" href="http://www.sans.org/security-training/intrusion-detection-in-depth-510-tid" target="_blank">SANS website</a>, an outstanding course that I&#8217;ve already described as the &#8220;most valuable course I&#8217;ve ever taken&#8221;. However, I want you to listen to <a title="Mike Poor at Inguardians" href="http://www.inguardians.com/info/#Poor" target="_blank">Mike Poor</a>, instructor at the SANS Institute and co-author of this course (along with Judy Novak and Guy Bruneau), describing it on YouTube. Mike Poor is both an amazing professional and a great guy that I had the opportunity to meet at <a title="SANS Sydney 2008" href="http://www.sans.org/sydney08/" target="_blank">SANS Sydney in 2008</a>, when I took his <a title="Security 560: Network Penetration Testing and Ethical Hacking" href="http://www.sans.org/sydney08/description.php?tid=1717" target="_blank">Penetration Testing</a> class. As Mike would say, this IDS course is simply &#8220;awesome&#8221;!</p>
<p style="text-align: center;"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/RoB0mLerbG0&amp;hl=es_ES&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/RoB0mLerbG0&amp;hl=es_ES&amp;fs=1&amp;" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ismaelvalenzuela.com/2010/01/26/teaching-community-sans-security-503-intrusion-detection-in-depth/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security Onion LiveCD is now available</title>
		<link>http://blog.ismaelvalenzuela.com/2009/06/16/security-onion-livecd-is-now-available/</link>
		<comments>http://blog.ismaelvalenzuela.com/2009/06/16/security-onion-livecd-is-now-available/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 19:48:01 +0000</pubDate>
		<dc:creator>Ismael Valenzuela</dc:creator>
				<category><![CDATA[Intrusion Detection Systems]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Bro]]></category>
		<category><![CDATA[Doug Burks]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[LiveCD]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Nmap]]></category>
		<category><![CDATA[NSMnow]]></category>
		<category><![CDATA[Security Onion]]></category>
		<category><![CDATA[Sguil]]></category>

		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=93</guid>
		<description><![CDATA[I read in Doug Burks' tweet that his Security Onion LiveCD is now available for download. Being a serious Sguil fan, I can't do anything but recommend you have a look at this new live distro.]]></description>
			<content:encoded><![CDATA[<p><img class="size-medium wp-image-91 alignright" style="border: 0pt none; margin: 2px; vertical-align: top; float: right;" title="yellow-onion1-thumb.jpg" src="http://blog.ismaelvalenzuela.com/wp-content/uploads/2009/06/yellow-onion1-thumb.jpg" alt="Security Onion ??" width="181" height="197" />I read in <a href="https://twitter.com/dougburks" target="_blank">Doug Burks&#8217; tweet</a> that his Security Onion LiveCD is now available for download. Being a serious <a href="http://sguil.sourceforge.net/" target="_blank">Sguil</a> fan, I can&#8217;t do anything but recommend you have a look at this new live distro.</p>
<p>You can download it from the following location:<br />
<a title="Security Onion LiveCD" href="http://distro.ibiblio.org/pub/linux/distributions/security-onion/" target="_blank">http://distro.ibiblio.org/pub/linux/distributions/security-onion/</a></p>
<p>The following information is extracted from Doug&#8217;s <a href="http://securityonion.blogspot.com/" target="_blank">Security Onion blog</a>:<strong></strong></p>
<blockquote><p><strong>What is it?</strong></p>
<p>The Security Onion LiveCD is a bootable CD that contains software used for installing, configuring, and testing Intrusion Detection Systems.<span id="more-93"></span></p>
<p><strong>What software does it contain? </strong></p></blockquote>
<blockquote style="clear: both"><p>The Security Onion LiveCD is based on Xubuntu 9.04 and contains Snort 2.8.4.1, Snort 3.0.0b3 (Beta), sguil, idswakeup, nmap, metasploit, scapy, hping, fragroute, fragrouter, netcat, paketto, tcpreplay, and many other security tools.</p>
<p><strong>What can it be used for?</strong></p>
<p>-The Security Onion LiveCD can be used for Intrusion Detection. Simply boot the CD and double-click either the Snort-Sguil or SnortSP-Sguil desktop shortcuts. The Snort and Sguil daemons will then start, listening on eth0 for any suspicious traffic and creating alerts in the Sguil console.</p>
<p>-The Security Onion LiveCD can be used to test an Intrusion Detection System. Simply boot the CD and use the included tools (such as nmap, metasploit, idswakeup, scapy, hping, and others) to test your existing IDS or to test the included Snort 2.8.4.1 and Snort 3.0 Beta 3.</p>
<p>-The Security Onion LiveCD can be used to install an Intrusion Detection System. Simply boot the CD and double-click the Install desktop shortcut. For more information about installation, please see the README desktop shortcut.</p></blockquote>
<p style="clear: both">I haven&#8217;t had a chance to download it yet, but I will definitely give it a try over the next few days. I&#8217;m very interested in trying out the IDS installation feature and see how it compares to other <a href="http://sguil.sourceforge.net/" target="_blank">Sguil</a> installation scripts like <a href="http://www.securixlive.com/nsmnow/" target="_blank">NSMnow</a>. I&#8217;m currently working on the deployment of a good number of <a href="http://sguil.sourceforge.net/" target="_blank">Sguil</a> servers/sensors and <a href="http://www.securixlive.com/nsmnow/" target="_blank">NSMnow</a> has reduced significantly the time needed to get them up and running. Hence, any new development on this topic is more than welcome.</p>
<p style="clear: both">I will keep posting my findings on this new exciting tool!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ismaelvalenzuela.com/2009/06/16/security-onion-livecd-is-now-available/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
