Still Blogging
Sometimes work occupies time I would have previously spent blogging, reading, or writing. That's why you'll often see a flurry of blog posts when I have time on a weekend (or now, before a Company holiday). I've fallen far behind in my reading, and my writing is limited to articles. However, I will be collaborating with Keith Jones and team for Real Digital Forensics Volume 2, which should be cool. I don't have a schedule for other books beyond RDF2 at the moment.
Richard Bejtlich is teaching new classes in Las Vegas in 2009. Late Las Vegas registration ends 22 July.
Comments
http://ws.arin.net/whois/?queryinput=3.0.0.0
OrgName: General Electric
NetRange: 3.0.0.0 - 3.255.255.255
CIDR: 3.0.0.0/8
NetName: GE-INTERNET
"Breach 3 / Impact 8 / Intruder has established command and control channel from asset with ready access to sensitive data"
Or maybe I don't even have 3/8 his security skills :)
I have a very large network 100k+ nodes and no funding for a netflow solution. However the Networking guys are willing to turn on netflow on the main internet firewalls if I can figure out what to do with it.
So could you write an article on how to get started with $0 for software and couple of big servers ready to crunch. With the main objective being to identify unknown or dodgy communications.
That would probably reach a few people on this blog.