<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NovaInfosecPortal.com &#187; cyberwarfare</title>
	<atom:link href="http://www.novainfosecportal.com/tag/cyberwarfare/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.novainfosecportal.com</link>
	<description>News, events, &#38; resources for infosec professionals in NoVA, DC, &#38; MD</description>
	<lastBuildDate>Mon, 06 Feb 2012 18:30:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Top 3 NoVA Infosec Blog Posts of the Week</title>
		<link>http://www.novainfosecportal.com/2009/08/03/top-3-nova-infosec-blog-posts-of-the-week-19/</link>
		<comments>http://www.novainfosecportal.com/2009/08/03/top-3-nova-infosec-blog-posts-of-the-week-19/#comments</comments>
		<pubDate>Mon, 03 Aug 2009 15:30:16 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[net-centric-thinking]]></category>
		<category><![CDATA[NoVA Bloggers]]></category>
		<category><![CDATA[richard-bejtlich]]></category>
		<category><![CDATA[rybolov]]></category>
		<category><![CDATA[sanitizing-web-apps]]></category>
		<category><![CDATA[sybersecurity]]></category>
		<category><![CDATA[web-apps]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1874</guid>
		<description><![CDATA[While things were a little quiet on the local blogging front this past week due to the awesomeness that is BlackHat, Richard Bejtlich, @rybolov and @geminisecurity came to the rescue with three excellent posts that discuss everything from the importance of sanitizing web apps to what we need in a CyberArmy. As everyone slowly recuperates from BlackHat, expect a large influx of must-read posts about the event. If you&#8217;d like to catch most of these posts, be sure to follow us @grecs during the week. #3 &#8211; The Real CyberArmy: In his post &#8220;The CyberArmy You Have&#8230;&#8221; @rybolov opens with the military saying, &#8220;[y]ou go to war with the army you have, not with the army you wish you had.&#8221; This is especially true for the US as it charges ahead with its national Cybersecurity strategy without having having the proper skill set or the proper leadership. While Cyberwar is a top skill to have, @rybolov notes that &#8220;the existing contractor skillset is based on procedural offerings,&#8221; and that, &#8220;[t]o be honest, I see lots of people with cybersecurity offerings, but what they really have is rebranded service offerings because the skills sets of the workforce haven’t changed.&#8221; As much [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week+http%3A%2F%2Fj.mp%2FnzkmvU" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2009/08/03/top-3-nova-infosec-blog-posts-of-the-week-19/&amp;t=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p>While things were a little quiet on the local blogging front this past week due to the awesomeness that is BlackHat, <span>Richard Bejtlich, <a href="http://www.twitter.com/rybolov">@rybolov</a> and <a href="http://www.twitter.com/geminisecurity">@geminisecurity</a> came to the rescue with three excellent posts that discuss everything from the importance of sanitizing web apps to what we need in a CyberArmy. </span></p>
<p><span>As everyone slowly recuperates from BlackHat, expect a large influx of must-read posts about the event. If you&#8217;d like to catch most of these posts, be sure to follow us <a href="http://www.twitter.com/grecs">@grecs</a> during the week. </span></p>
<p><span><strong>#3 &#8211; The Real CyberArmy</strong>: In his post &#8220;The CyberArmy You Have&#8230;&#8221; <a href="http://www.twitter.com/rybolov">@rybolov</a> opens with the military saying, &#8220;[y]ou go to war with the army you have, not with the army you wish you had.&#8221; This is especially true for the US as it charges ahead with its national Cybersecurity strategy without having having the proper skill set or the proper leadership. While Cyberwar is a top skill to have, @rybolov notes that &#8220;the existing contractor skillset is based on procedural offerings,&#8221; and that, &#8220;[t]o be honest, I see lots of people with cybersecurity offerings, but what they really have is rebranded service offerings because the skills sets of the workforce haven’t changed.&#8221; As much as we might think that we have a CyberArmy that can handle anything, @rybolov makes the excellent point that we need to see the CyberArmy that <em>we actually have</em>. To learn more about the CyberArmy we have and what we can do to make it better, read @rybolov&#8217;s full post <a href="http://www.guerilla-ciso.com/archives/1235">here</a>.  <span id="more-1874"></span><br />
</span></p>
<p><strong>#2 &#8211; FUD for Thought</strong>: In his guest post for <a href="http://fudsec.com/">fudsec.com</a> (the fud comes from fear, uncertainty and doubt), security expert <span>Richard Bejtlich talks about threat-centric thinking being on the rise. Bejtlich makes the excellent observation that over the past few years, there has been a shift in perspective when DoS attacks occur. It used to be that when a DoS attack occurred, people would ask &#8220;how did it happen?&#8221; Now, the primary concern when a DoS attack occurs is &#8220;who did it?&#8221; But is the shift from &#8220;how&#8221; to &#8220;who&#8221; good or counterproductive? You&#8217;ll just have to read the <a href="http://fudsec.com/threat-centric-thinking-on-the-rise-richard-b">full post</a> to find out; Bejtlich&#8217;s answer might surprise you.<br />
</span></p>
<p><strong>#1 &#8211; Sanitize Those Apps</strong>: A <a href="http://www.novainfosecportal.com/2009/06/22/top-3-nova-infosec-blog-posts-of-the-week-13/">few weeks ago</a> we featured the <a href="http://www.twitter.com/geminisecurity">@geminisecurity</a> post &#8220;Sanitizing Input in Web Apps (Part 1).&#8221; We ranked it at number one to emphasize the importance of sanitizing input for the web (and anything else, for that matter). That&#8217;s why when @geminisecurity rolled out with part two of their &#8220;Sanitizing Web Apps&#8221; article, we knew that it needed to fill the number one slot again. Sanitizing input for web apps is one of the basic tenants for securing web apps. When we forget to sanitize input, or skip what might seem to be a rather minor step, we&#8217;re doing ourselves and users a huge disservice. It goes back to our motto of <a href="http://www.novainfosecportal.com/2009/04/18/recent-studies-stress-back-to-basics/">doing the basics and doing them well</a>; it saves you, and everyone else, a lot of headache in the end. More than that though, it helps keep everyone safer. And at the end of the day, isn&#8217;t that what we all want? While we step off our soapbox, head over to @geminisecurity to read the <a href="http://securitymusings.com/article/1360/sanitizing-input-in-web-apps-part-2">full post</a>.</p>
<p>Well, that&#8217;s all for this week. Expect some interesting BlackHat posts this upcoming week!</p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week+http%3A%2F%2Fj.mp%2FnzkmvU" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2009/08/03/top-3-nova-infosec-blog-posts-of-the-week-19/&amp;t=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/08/03/top-3-nova-infosec-blog-posts-of-the-week-19/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 3 NoVA Infosec Blog Posts of the Week</title>
		<link>http://www.novainfosecportal.com/2009/06/29/top-3-nova-infosec-blog-posts-of-the-week-14/</link>
		<comments>http://www.novainfosecportal.com/2009/06/29/top-3-nova-infosec-blog-posts-of-the-week-14/#comments</comments>
		<pubDate>Mon, 29 Jun 2009 14:00:35 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[infosec-community]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[iphone-3]]></category>
		<category><![CDATA[iphone-apps]]></category>
		<category><![CDATA[NoVA Bloggers]]></category>
		<category><![CDATA[richard-bejtlich]]></category>
		<category><![CDATA[spanish-civil-war]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1732</guid>
		<description><![CDATA[It&#8217;s time for one of our favorite posts of the week&#8230; the post where we get to spotlight some great bloggers who are involved in the local infosec community. If you, or someone you know should be added to the list of bloggers we consider each week, please contact us or send us a tweet. #3 &#8211; iPhone Apps: We&#8217;re always looking for good apps for the iPhone (especially with the release of 3.0) so luckily for us, @geminisecurity had a post that covered 4 of the best apps for the iPhone. But @geminisecurity didn&#8217;t just cover regular iPhone apps; no, they covered security apps for the iPhone, which is definitely needed if all the recent rumors swirling around Apple&#8217;s security are true. You can check out the full post for more information. #2 &#8211; Security for a Million: Writer and speaker Richard Bejtlich posed an interesting question this week, asking what a black hat could do with a $1 million budget. But instead of just leaving it as a question, Bejtlich actually wrote out a tentative breakdown of what a black hat organization could do with a $1 million budget.  I&#8217;m not sure what was scarier; the fact that [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week+http%3A%2F%2Fj.mp%2FnCZZg5" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2009/06/29/top-3-nova-infosec-blog-posts-of-the-week-14/&amp;t=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p>It&#8217;s time for one of our favorite posts of the week&#8230; the post where we get to spotlight some great bloggers who are involved in the local infosec community.</p>
<p>If you, or someone you know should be added to the list of bloggers we consider each week, please <a href="http://www.novainfosecportal.com/contact-us/">contact us</a> or <a href="http://www.twitter.com/grecs">send us a tweet</a>.</p>
<p><strong>#3 &#8211; iPhone Apps</strong>: We&#8217;re always looking for good apps for the iPhone (especially with the release of 3.0) so luckily for us, <a href="http://www.twitter.com/geminisecurity">@geminisecurity</a> had a post that covered 4 of the best apps for the iPhone. But @geminisecurity didn&#8217;t just cover regular iPhone apps; no, they covered <em>security apps</em> for the iPhone, which is definitely needed if all the recent rumors swirling around Apple&#8217;s security are true. You can check out the <a href="http://securitymusings.com/article/1245/4-good-security-applications-for-the-iphone">full post</a> for more information.<span id="more-1732"></span></p>
<p><strong>#2 &#8211; Security for a Million</strong>: Writer and speaker Richard Bejtlich posed an interesting question this week, asking what a black hat could do with a $1 million budget. But instead of just leaving it as a question, Bejtlich actually <em>wrote out</em> a tentative breakdown of what a black hat organization could do with a $1 million budget.  I&#8217;m not sure what was scarier; the fact that he created a potential financial plan for a black hat organization to follow, or that $1 million could go a lot further in a black hat organization than it could in most of the organizations we work for. Really makes you question how much money is wasted on unimportant things. Definitely <a href="http://taosecurity.blogspot.com/2009/06/black-hat-budgeting.html">read the post</a> for yourself and let me know what you think.</p>
<p><strong>#1 &#8211; Cyberwarfare and the Spanish Civil War</strong>: According to guest poster ian99 of the The Guerilla CISO, &#8220;Perhaps the most interesting model of development and Cyberwarfare activity today would be based on the pre-WW II example of the Spanish Civil War.&#8221; Tracing the historical origins of cyberwarfare, ian99&#8242;s post is like attending a ShmooCon talk and a history lesson all in one. Check out the full post <a href="http://www.guerilla-ciso.com/archives/1139">here</a>.</p>
<p>Well, that’s all for this week. Be sure to follow me <a href="http://www.twitter.com/grecs">@grecs</a> during the week for more great posts from local bloggers.</p>
<p style="text-align: center;">o o o o o</p>
<p style="text-align: center;"><em>Speaking of great local bloggers… we’re looking for some great guest bloggers to feature on NovaInfosecPortal. If you’re interested, feel free to <a href="../2009/06/22/contact-us/">contact us</a> or <a href="http://www.twitter.com/grecs">send us a tweet</a>. </em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week+http%3A%2F%2Fj.mp%2FnCZZg5" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2009/06/29/top-3-nova-infosec-blog-posts-of-the-week-14/&amp;t=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/06/29/top-3-nova-infosec-blog-posts-of-the-week-14/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

