Bears Teach Network Security Monitoring Principles
Every once in a while it's good to be reminded of certain principles. In my first book I outlined three lessons I've learned while monitoring intruders. Sometimes threats in nature provide examples of these lessons.
Sguil developer Bamm Visscher pointed me to these images, which I have cropped and annotated for your network security monitoring enjoyment.
NSM Principle 1: Some intruders are smarter than you are.
![](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vgEE5oA92IuT_kdAuthTLDBdB_GVYUjWmcWXBhyw0Qyg1XVXIa0iUb9S5bDFMWAFsSdNpPd8EpZOL42MFC6VH0b-XoWbuoBo4qcesVRnU=s0-d)
NSM Principle 2: Intruders are unpredictable.
![](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uSCnCtg68isijqP5Xi52kPPQx0AW4FOZ0FcnvhjjAQhyY_CW6u-JOYhai0TqQTn1ze1TTlqyT6GTvcUc0-KEZl858ykiEgqtaFA_XidT8=s0-d)
NSM Principle 3: Prevention eventually fails.
![](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vkQmVjyHrK2X4rkYiiShjoepsL0ZtML_WvU1IkiMt7T-g1rPcNkIcovNLfuOlPx-feR-U5aqm4szp91HIO6NYXwxoypNPQiD4CRuu59A=s0-d)
Hence, the need for monitoring, e.g., these photos!
Thank you to GeekBase for posting these -- I hope you prefer me not linking to the photos directly, thereby saving your bandwidth!
Sguil developer Bamm Visscher pointed me to these images, which I have cropped and annotated for your network security monitoring enjoyment.
NSM Principle 1: Some intruders are smarter than you are.
NSM Principle 2: Intruders are unpredictable.
NSM Principle 3: Prevention eventually fails.
Hence, the need for monitoring, e.g., these photos!
Thank you to GeekBase for posting these -- I hope you prefer me not linking to the photos directly, thereby saving your bandwidth!
Comments
H. Carvey
"Windows Forensics and Incident Recovery"
http://www.windows-ir.com
http://windowsir.blogspot.com