<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; Uncategorized</title>
	<atom:link href="http://raffy.ch/blog/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://raffy.ch/blog</link>
	<description>Log visualization and log management as seen by Raffael Marty</description>
	<lastBuildDate>Wed, 28 Jul 2010 02:04:42 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>All the Data That&#8217;s Fit to Visualize</title>
		<link>http://raffy.ch/blog/2010/06/28/all-the-data-thats-fit-to-visualize/</link>
		<comments>http://raffy.ch/blog/2010/06/28/all-the-data-thats-fit-to-visualize/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 18:29:36 +0000</pubDate>
		<dc:creator>Raffael Marty</dc:creator>
				<category><![CDATA[Log Analysis]]></category>
		<category><![CDATA[Security Information Management]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Visualization]]></category>

		<guid isPermaLink="false">http://raffy.ch/blog/?p=392</guid>
		<description><![CDATA[Last week I posted the introductionary video for a talk that I gave at Source Boston in 2008. I just found the entire video of that talk. Enjoy:

Talk by Raffael Marty:
With the ever-growing amount of data collected in IT environments, we need new methods and tools to deal with them. Event and Log Analysis is [...]]]></description>
			<content:encoded><![CDATA[<p>Last week I posted the introductionary video for a talk that I gave at Source Boston in 2008. I just found the entire video of that talk. Enjoy:</p>
<p><embed src="http://blip.tv/play/Aa_lQgA" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="270" width="320"></embed></p>
<p>Talk by <a href="http://raffy.ch/blog">Raffael Marty</a>:</p>
<p>With the ever-growing amount of data collected in IT environments, we need new methods and tools to deal with them. Event and Log Analysis is becoming one of the main tools for analysts to investigate and comprehend the state of their networks, hosts, applications, and business processes. Recent developments, such as regulatory compliance and an increased focus on insider threat have increased the demand for analytical tools to help in the process. Visualization is offering a new, more effective, and simpler approach to data analysis. To date, security visualization, has mostly failed to deliver effective tools and methods. This presentation will show what the New York Times has to teach us about effective visualizations. Visualization for the masses and not visualization for the experts. Insider Threat, Governance, Risk, and Compliance (GRC), and Perimeter Threat all require effective visualization methods and they are right in front of us – in the newspaper.</p>
]]></content:encoded>
			<wfw:commentRss>http://raffy.ch/blog/2010/06/28/all-the-data-thats-fit-to-visualize/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Applied Security Visualization Book seen in Singapore</title>
		<link>http://raffy.ch/blog/2009/12/01/applied-security-visualization-book-seen-in-singapore/</link>
		<comments>http://raffy.ch/blog/2009/12/01/applied-security-visualization-book-seen-in-singapore/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 01:50:48 +0000</pubDate>
		<dc:creator>Raffael Marty</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://raffy.ch/blog/?p=323</guid>
		<description><![CDATA[A friend just sent me couple of pictures he took in a bookstore in Singapore.


Have you seen the book Applied Security Visualization on the shelf at your local book store? If so, send me a picture and I will post it…
]]></description>
			<content:encoded><![CDATA[<p>A friend just sent me couple of pictures he took in a bookstore in Singapore.</p>
<p><img src="http://raffy.ch/blog/wp-content/uploads/2009/12/sinagpore_1.jpg" alt="singapore_1" title="singapore_1" width="200" class="alignleft" /></p>
<p><img src="http://raffy.ch/blog/wp-content/uploads/2009/12/singapore_2.jpg" alt="singapore_2" title="singapore_2" width="200"  class="alignleft" /></p>
<p>Have you seen the book <a href="http://secviz.org/content/applied-security-visualization">Applied Security Visualization</a> on the shelf at your local book store? If so, send me a picture and I will post it…</p>
]]></content:encoded>
			<wfw:commentRss>http://raffy.ch/blog/2009/12/01/applied-security-visualization-book-seen-in-singapore/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security Visualization and Log Analysis Workshop &#8211; Sign up now!</title>
		<link>http://raffy.ch/blog/2009/02/17/security-visualization-and-log-analysis-workshop-sign-up-now/</link>
		<comments>http://raffy.ch/blog/2009/02/17/security-visualization-and-log-analysis-workshop-sign-up-now/#comments</comments>
		<pubDate>Wed, 18 Feb 2009 06:32:51 +0000</pubDate>
		<dc:creator>Raffael Marty</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://raffy.ch/blog/?p=292</guid>
		<description><![CDATA[&#8220;Log Analysis and Security Visualization&#8221; is a two-day training class held on March 9th and 10th 2009 in Boston during the SOURCE Boston conference that addresses the data management and analysis challenges of today&#8217;s IT environments.
Students will leave this class with the knowledge to visualize and manage their own IT data. They will learn the [...]]]></description>
			<content:encoded><![CDATA[<p><img style="padding: 5px 5px 0pt 0pt; float:left" src="http://secviz.org/files/03fig_table14.png" border="0" alt="" width="140" />&#8220;<a href="http://www.sourceconference.com/index.php/source-boston-2009/boston-2009-training">Log Analysis and Security Visualization</a>&#8221; is a two-day training class held on <strong>March 9th and 10th 2009</strong> in Boston during the <a href="http://www.sourceconference.com/index.php/source-boston-2009">SOURCE Boston</a> conference that addresses the data management and analysis challenges of today&#8217;s IT environments.<br />
<a href="http://click.linksynergy.com/fs-bin/click?id=UiO/LB8bvCc&amp;offerid=145238.10000081&amp;type=3&amp;subid=0"><img style="float:right" src="http://secviz.org/files/cover2.jpg" border="0" alt="Applied Security Visualization" width="100" /></a>Students will leave this class with the knowledge to <a href="http://secviz.org">visualize</a> and manage their own IT data. They will learn the basics of log analysis, learn about common data sources, get an overview of visualization techniques, and learn how to generate visual representations of IT data for a number of different use-cases from DoS and worm detection to compliance reporting. The training is filled with hands-on exercises utilizing <a href="http://davix.secviz.org">DAVIX</a>, the open-source data analysis and visualization platform.</p>
<p><strong><em><a href="http://www.regonline.com/Checkin.asp?EventId=629189">Register</a></em> today to secure your spot.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://raffy.ch/blog/2009/02/17/security-visualization-and-log-analysis-workshop-sign-up-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>links for 2009-01-02</title>
		<link>http://raffy.ch/blog/2009/01/02/links-for-2009-01-02/</link>
		<comments>http://raffy.ch/blog/2009/01/02/links-for-2009-01-02/#comments</comments>
		<pubDate>Sat, 03 Jan 2009 02:03:26 +0000</pubDate>
		<dc:creator>Raffael Marty</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://raffy.ch/blog/2009/01/02/links-for-2009-01-02/</guid>
		<description><![CDATA[

Index of /CCC/25C3/video_h264_720&#215;576/
(tags: hacking video ccc conference 25c3)


Weka 3 &#8211; Data Mining with Open Source Machine Learning Software in Java
(tags: tool statistics visualization data mining)


honeyblog
(tags: honeypot blog security research)


Visualization Blog
(tags: visualization blog visualzeit)


niklas elmqvist &#124; scatterdice
(tags: scatter visualization)


niklas elmqvist &#124; scatterdice
(tags: scatter visualization)


hakin9.org &#8211; About the mag
(tags: hakin9 hack magazine security)


homepage
(tags: visualization layout papers research)


email [...]]]></description>
			<content:encoded><![CDATA[<ul class="delicious">
<li>
<p class="delicious-link"><a href="http://dewy.fem.tu-ilmenau.de/CCC/25C3/video_h264_720x576/">Index of /CCC/25C3/video_h264_720&#215;576/</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/hacking">hacking</a> <a href="http://delicious.com/zrlram/video">video</a> <a href="http://delicious.com/zrlram/ccc">ccc</a> <a href="http://delicious.com/zrlram/conference">conference</a> <a href="http://delicious.com/zrlram/25c3">25c3</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://www.cs.waikato.ac.nz/ml/weka/">Weka 3 &#8211; Data Mining with Open Source Machine Learning Software in Java</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/tool">tool</a> <a href="http://delicious.com/zrlram/statistics">statistics</a> <a href="http://delicious.com/zrlram/visualization">visualization</a> <a href="http://delicious.com/zrlram/data">data</a> <a href="http://delicious.com/zrlram/mining">mining</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://honeyblog.org/">honeyblog</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/honeypot">honeypot</a> <a href="http://delicious.com/zrlram/blog">blog</a> <a href="http://delicious.com/zrlram/security">security</a> <a href="http://delicious.com/zrlram/research">research</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://visualizeit.wordpress.com/">Visualization Blog</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/visualization">visualization</a> <a href="http://delicious.com/zrlram/blog">blog</a> <a href="http://delicious.com/zrlram/visualzeit">visualzeit</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="https://engineering.purdue.edu/~elm/projects/scatterdice.html">niklas elmqvist | scatterdice</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/scatter">scatter</a> <a href="http://delicious.com/zrlram/visualization">visualization</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://www.lri.fr/~elm/projects/scatterdice.html">niklas elmqvist | scatterdice</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/scatter">scatter</a> <a href="http://delicious.com/zrlram/visualization">visualization</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://hakin9.org/">hakin9.org &#8211; About the mag</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/hakin9">hakin9</a> <a href="http://delicious.com/zrlram/hack">hack</a> <a href="http://delicious.com/zrlram/magazine">magazine</a> <a href="http://delicious.com/zrlram/security">security</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://www.cse.ust.hk/~weiwei/index.php">homepage</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/visualization">visualization</a> <a href="http://delicious.com/zrlram/layout">layout</a> <a href="http://delicious.com/zrlram/papers">papers</a> <a href="http://delicious.com/zrlram/research">research</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://infosthetics.com/archives/2006/06/email_thread_visualization.html">email thread visualization &#8211; information aesthetics</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/visualization">visualization</a> <a href="http://delicious.com/zrlram/email">email</a> <a href="http://delicious.com/zrlram/thread">thread</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://www.mytty.org/kisgearth/">KisGearth &#8211; Porting your Wardrives to GoogleEarth . . .</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/kismet">kismet</a> <a href="http://delicious.com/zrlram/geo">geo</a> <a href="http://delicious.com/zrlram/visualization">visualization</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://geotree.geonames.org/">GeoTree : Oceania &gt; Cook Islands</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/geo">geo</a> <a href="http://delicious.com/zrlram/visualization">visualization</a> <a href="http://delicious.com/zrlram/gis">gis</a>)</p>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://raffy.ch/blog/2009/01/02/links-for-2009-01-02/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>links for 2008-11-28</title>
		<link>http://raffy.ch/blog/2008/11/28/links-for-2008-11-28/</link>
		<comments>http://raffy.ch/blog/2008/11/28/links-for-2008-11-28/#comments</comments>
		<pubDate>Sat, 29 Nov 2008 02:04:06 +0000</pubDate>
		<dc:creator>Raffael Marty</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://raffy.ch/blog/2008/11/28/links-for-2008-11-28/</guid>
		<description><![CDATA[

IT Unified Compliance Framework: Harmonized Policy Controls for PCI, SOX, HIPAA and More
(tags: compliance control objectives)


KartOO visual meta search engine
(tags: visualization search engine onthology)


traer.physics
(tags: particle system layout visualization physics)


Eye-SysÂ® &#124; Welcome
(tags: visualization 3d product)


IEEE Visualization 2008
(tags: visualization papers archive ieee conference)


spy :: visualizes the conversations on Twitter, Friendfeed, Flickr, Blogs and more.
(tags: aggregator social media [...]]]></description>
			<content:encoded><![CDATA[<ul class="delicious">
<li>
<p class="delicious-link"><a href="http://www.unifiedcompliance.rsvp1.com/">IT Unified Compliance Framework: Harmonized Policy Controls for PCI, SOX, HIPAA and More</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/compliance">compliance</a> <a href="http://delicious.com/zrlram/control">control</a> <a href="http://delicious.com/zrlram/objectives">objectives</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://www.kartoo.com/flash04.php3">KartOO visual meta search engine</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/visualization">visualization</a> <a href="http://delicious.com/zrlram/search">search</a> <a href="http://delicious.com/zrlram/engine">engine</a> <a href="http://delicious.com/zrlram/onthology">onthology</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://www.cs.princeton.edu/~traer/physics/">traer.physics</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/particle">particle</a> <a href="http://delicious.com/zrlram/system">system</a> <a href="http://delicious.com/zrlram/layout">layout</a> <a href="http://delicious.com/zrlram/visualization">visualization</a> <a href="http://delicious.com/zrlram/physics">physics</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://www.eye-sys.com/">Eye-SysÂ® | Welcome</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/visualization">visualization</a> <a href="http://delicious.com/zrlram/3d">3d</a> <a href="http://delicious.com/zrlram/product">product</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://www.cse.ust.hk/~wuyc/Vis08.htm">IEEE Visualization 2008</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/visualization">visualization</a> <a href="http://delicious.com/zrlram/papers">papers</a> <a href="http://delicious.com/zrlram/archive">archive</a> <a href="http://delicious.com/zrlram/ieee">ieee</a> <a href="http://delicious.com/zrlram/conference">conference</a>)</p>
</li>
<li>
<p class="delicious-link"><a href="http://spy.appspot.com/">spy :: visualizes the conversations on Twitter, Friendfeed, Flickr, Blogs and more.</a></p>
<p class="delicious-tags">(tags: <a href="http://delicious.com/zrlram/aggregator">aggregator</a> <a href="http://delicious.com/zrlram/social">social</a> <a href="http://delicious.com/zrlram/media">media</a> <a href="http://delicious.com/zrlram/search">search</a>)</p>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://raffy.ch/blog/2008/11/28/links-for-2008-11-28/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Process of Writing the Applied Security Visualization Book</title>
		<link>http://raffy.ch/blog/2008/09/06/the-process-of-writing-the-applied-security-visualization-book/</link>
		<comments>http://raffy.ch/blog/2008/09/06/the-process-of-writing-the-applied-security-visualization-book/#comments</comments>
		<pubDate>Sat, 06 Sep 2008 20:55:35 +0000</pubDate>
		<dc:creator>Raffael Marty</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://raffy.ch/blog/2008/09/06/the-process-of-writing-the-applied-security-visualization-book/</guid>
		<description><![CDATA[A little bit more than two years ago, I approached Jessica Goldstein from Addison Wesley to write a book about security visualization. We sat down during BlackHat 2006 and discussed my idea. It didn&#8217;t take much to convince her that they should get me on board. I went home after the conference and started putting [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://raffy.ch/blog/wp-content/uploads/2008/09/img_0365.jpg" title="img_0365.jpg"><img src="http://raffy.ch/blog/wp-content/uploads/2008/09/img_0365.thumbnail.jpg" alt="img_0365.jpg" align="left" hspace="10" /></a>A little bit more than two years ago, I approached Jessica Goldstein from Addison Wesley to write a <a href="http://secviz.org/content/applied-security-visualization">book about security visualization</a>. We sat down during BlackHat 2006 and discussed my idea. It didn&#8217;t take much to convince her that they should get me on board. I went home after the conference and started putting together a table of contents. Here is the very first TOC that I submitted:</p>
<ol>
<li>Introduction</li>
<li>Data Sources</li>
<li>Visualization</li>
<li>From Data To Visuals</li>
<li>Visual Security Analysis</li>
<li>Situational Awareness</li>
<li>Perimeter Threat</li>
<li>Compliance</li>
<li>Insider Threat</li>
<li>Data Visualization Tools</li>
</ol>
<p>If you read the book, you will notice that this is pretty much what I ended up with. More or less. An interesting fact is that at the time of submitting the TOC, I had no idea what to exactly write about in the compliance and insider threat chapters. The even more interesting fact is that a lot of people told me that their favorite chapter is the insider threat chapter.</p>
<p><a href="http://raffy.ch/blog/wp-content/uploads/2008/09/img_0336.jpg" title="img_0336.jpg"><img src="http://raffy.ch/blog/wp-content/uploads/2008/09/img_0336.thumbnail.jpg" alt="img_0336.jpg" align="right" /></a>After submitting the TOC to Jessica, she had me fill out some more marketing questions about the book. Things like target audience, competitive books, etc. After handing that in, it went silent for a bit. Jessica was selling the book internally. And then things started to look not so good. Jessica went on maternity leave. Kristin took over and got the proposal review process lined up. I asked some people in the industry to have a look over my proposal and provide feedback to the publisher. Questions like: &#8220;Why is Raffy the right person to write this book?&#8221; &#8220;Is there a market for this book?&#8221;Â  etc. were being asked. I received the six really great reviews (thanks guys!) mid December 2006. On December 19th, I received an email with the contract to write the book. I sent the contract off to a friend of mine who is a lawyer, just because I was a bit worried about intellectual property rights. After a few emails also with Addison, I felt much better. They are not at all interested in any IP. They just want the copyright, which was totally fine with me. Then, finally, on January 17th, I signed and was under contract to write about 300 pages about security visualization.</p>
<p>After a few days, I received an ISBN number for the book and a ton of material about style guides and how to go about writing the book. All very exciting. I decided to not write my book in TeX, unlike my masters thesis. That was definitely a smart decision. It turned out that using Word wasn&#8217;t that bad. The template from Addision made it really easy to format the text correctly. I actually ended up using VI to write the original text without any formatting. Once it was all done, I copied the raw text into Word and started formatting. The reason for doing this is that I am so much quicker in VI than I am in Word. (And hitting the ESC key in Word is not something you want to be doing too much.)</p>
<p><a href="http://raffy.ch/blog/wp-content/uploads/2008/09/cimg2403.jpg" title="cimg2403.jpg"><img src="http://raffy.ch/blog/wp-content/uploads/2008/09/cimg2403.thumbnail.jpg" alt="cimg2403.jpg" align="left" hspace="10" /></a>One of the next steps was to put together a timeline. Well, it was sort of aggressive. The version of the schedule I could find in my archives shows that I was planning on being done mid September 2007. Well, I missed that by only a year <img src='http://raffy.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  I attribute a lot to the fact that I didn&#8217; really know how to write (seriously) and to the chatpers for which I had to do a lot of research.</p>
<p>I definitely enjoyed the process of writing the book. The folks at Addison Wesley were awesome. They kept motivating me along the way and provided great insights into the writing process. What I am still very impressed with is the PR aspects. Early on, they hooked me up to film a <a href="http://www.informit.com/podcasts/episode.aspx?e=6326faad-1b98-46c3-b278-90acf6cea51d">video cast</a> about the book. After publishing the book, I get about an email a week for some <a href="http://http://secviz.org/content/applied-security-visualization">press opportunity</a>. Keep them coming <img src='http://raffy.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Here is a fun fact: In <em>~/Data/projects/vis_addision, </em>where I have all the material for the book, I accumulated <strong>1.1</strong>GB of data. Pretty crazy.</p>
<p><a href="http://raffy.ch/blog/wp-content/uploads/2008/09/img_0260.JPG" title="img_0260.JPG"><img src="http://raffy.ch/blog/wp-content/uploads/2008/09/img_0260.thumbnail.JPG" alt="img_0260.JPG" align="left" hspace="10" /></a><a href="http://raffy.ch/blog/wp-content/uploads/2008/09/cimg2019.jpg" title="cimg2019.jpg"><img src="http://raffy.ch/blog/wp-content/uploads/2008/09/cimg2019.thumbnail.jpg" alt="cimg2019.jpg" align="right" border="0" /></a>Are you thinking about writing a book? Do it, but make sure you have time! I spent a LOT of time in the<a href="http://www.farleyscoffee.com"> local coffee shop</a> (picture on the left). I always had printouts with me to work on corrections. The picture on the right I took at 6.30am in Taipei. Yes, it&#8217;s a full-time job! I learned a lot! I made amazing connections. And I had fun! One piece of advice: make sure you have a good publisher!</p>
<p>I haven&#8217;t seen the book in my local Barnes and Nobles yet. Well, I checked two weeks ago. But a friend (<a href="http://twitter.com/jjx">@jjx</a>) sent me this picture. So, apparently some book stores have it in stock:</p>
<p><a href="http://raffy.ch/blog/wp-content/uploads/2008/09/478019.jpg" title="478019.jpg"><img src="http://raffy.ch/blog/wp-content/uploads/2008/09/478019.thumbnail.jpg" alt="478019.jpg" align="middle" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://raffy.ch/blog/2008/09/06/the-process-of-writing-the-applied-security-visualization-book/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>RSA Security Conference 2008 &#8211; What a Week</title>
		<link>http://raffy.ch/blog/2008/04/12/rsa-security-conference-2008-what-a-week/</link>
		<comments>http://raffy.ch/blog/2008/04/12/rsa-security-conference-2008-what-a-week/#comments</comments>
		<pubDate>Sun, 13 Apr 2008 02:41:32 +0000</pubDate>
		<dc:creator>Raffael Marty</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://raffy.ch/blog/2008/04/12/rsa-security-conference-2008-what-a-week/</guid>
		<description><![CDATA[Last week the RSA security conference was held in San Francisco. It&#8217;s hard to put all the impressions I gathered during the week into words. Let me just highlight some things that I thought were interesting:
RSA is a business development conference. It&#8217;s been that way for years and this year was definitely not different. At [...]]]></description>
			<content:encoded><![CDATA[<p>Last week the <a href="http://www.google.com/url?sa=t&amp;ct=res&amp;cd=1&amp;url=http%3A%2F%2Fwww.rsaconference.com%2F&amp;ei=L3IBSL-IHJqYoQS1jfTQBw&amp;usg=AFQjCNFD_UY9aYc7sq1bCGze9ghLuMYfMA&amp;sig2=1usLEikh3ryncJqY8PyzMw">RSA security conference</a> was held in San Francisco. It&#8217;s hard to put all the impressions I gathered during the week into words. Let me just highlight some things that I thought were interesting:</p>
<p><img src="http://raffy.ch/blog/wp-content/uploads/2008/04/img_0290.thumbnail.jpg" style="margin: 0pt 10px 10px 0pt; float: left" alt="img_0292.jpg" border="0" /><img src="http://raffy.ch/blog/wp-content/uploads/2008/04/img_0292.thumbnail.jpg" style="margin: 0pt 10px 10px 0pt; float: left" alt="img_0292.jpg" border="0" />RSA is a business development conference. It&#8217;s been that way for years and this year was definitely not different. At all! Don&#8217;t believe me? If even I, who is not in business development can collect this many cards, it has to be a biz dev con.</p>
<p><a href="http://raffy.ch/blog/wp-content/uploads/2008/04/cimg2668.jpg" title="cimg2668.jpg"><img src="http://raffy.ch/blog/wp-content/uploads/2008/04/cimg2668.thumbnail.jpg" style="margin: 0pt 10px 10px 0pt; float: left" alt="img_0292.jpg" border="0" /></a>The <a href="http://www.rsaconference.com/Security_Topics/Developing_with_Security/Blog_Security_Bloggers_Meet_up_2008.aspx">Security Blogger meetup</a> was great. Unfortunately I had to bounce very early. Sorry guys! I would have loved to stick around. The caliber of people hanging out in that room was crazy. Everyone that has a name, and more importantly a voice in the security industry, was there. Thanks to Jennifer for organizing it. Love the t-shirt!</p>
<p><font color="white">.</font><br />
<a href="http://raffy.ch/blog/wp-content/uploads/2008/04/img_0288.jpg" title="img_0288.jpg"><img src="http://raffy.ch/blog/wp-content/uploads/2008/04/img_0288.thumbnail.jpg" style="margin: 0pt 10px 10px 0pt; float: left" alt="img_0292.jpg" border="0" /></a>Talking about everybody being at RSA: I met the CISO of the <a href="http://www.vatican.va/">Vatican</a> <img src='http://raffy.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><font color="white">.</font></p>
<p><font color="white">.</font></p>
<p><font color="white">.</font></p>
<p><font color="white">.</font></p>
<p><a href="http://raffy.ch/blog/wp-content/uploads/2008/04/cimg2666.jpg" title="cimg2666.jpg"><img src="http://raffy.ch/blog/wp-content/uploads/2008/04/cimg2666.thumbnail.jpg" style="margin: 0pt 10px 10px 0pt; float: left" alt="cimg2666.jpg" border="0" /></a>We had the first in-person <a href="http://cee.mitre.org">common event expression (CEE</a>) meeting. Some people from <a href="http://openxdas.sourceforge.net/">XDAS</a><br />
showed up and we had some fairly good discussions around what to do with both the standards, how they can be aligned and how we can move forward.</p>
<p><font color="white">.</font></p>
<p><a href="http://raffy.ch/blog/wp-content/uploads/2008/04/cimg2678.jpg" title="cimg2678.jpg"><img src="http://raffy.ch/blog/wp-content/uploads/2008/04/cimg2678.thumbnail.jpg" style="margin: 0pt 10px 10px 0pt; float: left" alt="cimg2678.jpg" border="0" /></a>Walking around on the floor, I found some interesting <a href="http://secviz.org">security visualizations</a>. This one is from <a href="http://www.google.com/url?sa=t&amp;ct=res&amp;cd=1&amp;url=http%3A%2F%2Faris.securityfocus.com%2F&amp;ei=nW4BSLG3G4iYoQTBy5DhBw&amp;usg=AFQjCNHfapKX1vVIhFsFDwxe6PVTDr40NQ&amp;sig2=-41GKsIS7XIEOXXn1cC7Rg">DeepSight</a>.  Very visually appealing. I haven&#8217;t spent much time to understand what&#8217;s on the displays, but it looks interesting.</p>
<p><font color="white">.</font></p>
<p><font color="white">.</font></p>
]]></content:encoded>
			<wfw:commentRss>http://raffy.ch/blog/2008/04/12/rsa-security-conference-2008-what-a-week/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bridging Security and Visualization</title>
		<link>http://raffy.ch/blog/2008/01/24/bridging-security-and-visualization/</link>
		<comments>http://raffy.ch/blog/2008/01/24/bridging-security-and-visualization/#comments</comments>
		<pubDate>Fri, 25 Jan 2008 01:56:15 +0000</pubDate>
		<dc:creator>Raffael Marty</dc:creator>
				<category><![CDATA[Log Analysis]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Visualization]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[videocast]]></category>

		<guid isPermaLink="false">http://raffy.ch/blog/2008/01/24/bridging-security-and-visualization/</guid>
		<description><![CDATA[
OnSecrity just released another video of the conversation we recorded last year during RSA. I am talking about security visualization in light of the book I am working on. This  video cast is the sequel to the first one that I posted a few days ago.
One of the topics I am discussing in the [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://raffy.ch/blog/wp-content/uploads/2008/01/picture-8.thumbnail.png" style="margin: 0pt 10px 10px 0pt; float: left" alt="picture-8.png" border="0" /></p>
<p>OnSecrity just released <a href="http://media.podhoster.com/pearsoned2/33_SEC_Marty_02.mp4">another video</a> of the conversation we recorded last year during RSA. I am talking about security visualization in light of the book I am working on. This  video cast is the sequel to <a href="http://raffy.ch/blog/2008/01/18/applied-security-visualization/">the first one</a> that I posted a few days ago.</p>
<p><img src="http://raffy.ch/blog/wp-content/uploads/2008/01/picture-5.png" alt="picture-5.png" style="margin: 0pt 10px 10px 0pt; float: right" width="200" />One of the topics I am discussing in the video is the &#8220;<em>false dichotomy</em>&#8221; between security and visualization. This is a topic that I talked about during a talk at the MIT Lincoln Labs at the beginning of December. The presentation showed how there are really two disciplines that come together in security visualization: Security and Visualization. The problem with this is that visualization people don&#8217;t know much about security and the other way around. It&#8217;s a very interesting topic to explore and it explains some of the mistakes that are being made with visualization tools and is also reflected in visualization research.</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/visualization" rel="tag">visualization</a>, <a href="http://technorati.com/tag/security" rel="tag"> security</a>, <a href="http://technorati.com/tag/videocast" rel="tag"> videocast</a></p>
]]></content:encoded>
			<wfw:commentRss>http://raffy.ch/blog/2008/01/24/bridging-security-and-visualization/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://media.podhoster.com/pearsoned2/33_SEC_Marty_02.mp4" length="41951187" type="video/mpeg" />
		</item>
		<item>
		<title>500 Linkedin Connections</title>
		<link>http://raffy.ch/blog/2008/01/22/500-linkedin-connections/</link>
		<comments>http://raffy.ch/blog/2008/01/22/500-linkedin-connections/#comments</comments>
		<pubDate>Tue, 22 Jan 2008 22:24:10 +0000</pubDate>
		<dc:creator>Raffael Marty</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://raffy.ch/blog/2008/01/22/500-linkedin-connections/</guid>
		<description><![CDATA[I have been using Linkedin for quite a while now. Today marks the day where I actually have 500 connections. I wonder whether I would be able to go through all of them and remember who each and everyone is. I would probably get a 95% hit rate. I don&#8217;t think I am actually making [...]]]></description>
			<content:encoded><![CDATA[<p><a href="www.linkedin.com/in/raffy"><img src="http://raffy.ch/blog/wp-content/uploads/2008/01/picture-7.png" style="margin: 0pt 10px 10px 0pt; float: left" alt="picture-7.png" border="0" /></a>I have been using Linkedin for quite a while now. Today marks the day where I actually have 500 connections. I wonder whether I would be able to go through all of them and remember who each and everyone is. I would probably get a 95% hit rate. I don&#8217;t think I am actually making complete use of my network on Linkedin network, but one of my New Year&#8217;s resolutions is to get a bit better with my networking.</p>
<p>Connect to me if I know you and you are not in my network yet!</p>
]]></content:encoded>
			<wfw:commentRss>http://raffy.ch/blog/2008/01/22/500-linkedin-connections/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>My Splunk Blog</title>
		<link>http://raffy.ch/blog/2007/12/03/my-splunk-blog/</link>
		<comments>http://raffy.ch/blog/2007/12/03/my-splunk-blog/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 00:02:44 +0000</pubDate>
		<dc:creator>Raffael Marty</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://raffy.ch/blog/2007/12/03/my-splunk-blog/</guid>
		<description><![CDATA[I wanted to mention this a long time ago, I am really behind with blogging &#8230;
I started another blog. I hope this is not going to be too confusing.
Here is what goes where:

I will post things that are relevant to my employment and Splunk on my Splunk blog. I will continue my rant on normalization [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blogs.splunk.com/raffy" title="logo_splunk.gif"><img src="http://raffy.ch/blog/wp-content/uploads/2007/12/logo_splunk.thumbnail.gif" style="margin: 0pt 10px 10px 0pt; float: left" alt="logo_splunk.gif" border="0" /></a>I wanted to mention this a long time ago, I am really behind with blogging &#8230;</p>
<p>I started another <a href="http://blogs.splunk.com/raffy">blog</a>. I hope this is not going to be too confusing.</p>
<p>Here is what goes where:</p>
<ul>
<li>I will post things that are relevant to my employment and <a href="http://www.splunk.com">Splunk</a> on <a href="http://blogs.splunk.com/raffy">my Splunk blog</a>. I will <a href="http://blogs.splunk.com/raffy/2007/12/03/it-search-vs-siem-data-collection/">continue</a> my <a href="http://raffy.ch/blog/2007/08/25/event-processing-normalization/">rant on normalization and SIEM</a> over there.</li>
<li>Things that are non-Splunk related, I will keep on this blog here.</li>
<li>And in case you forgot, purely visualization related topics I still post on <a href="http://secviz.org">secviz.org</a> and you should too!</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://raffy.ch/blog/2007/12/03/my-splunk-blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
