<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Not only alert data Part III</title>
	<atom:link href="http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html</link>
	<description>What&#039;s with the blog?</description>
	<lastBuildDate>Tue, 06 Dec 2011 17:11:44 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: ayoi</title>
		<link>http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html/comment-page-1#comment-2152</link>
		<dc:creator>ayoi</dc:creator>
		<pubDate>Wed, 21 Mar 2007 12:50:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html#comment-2152</guid>
		<description>Kewl, hopefully we can share the method as well. Especially on db data mining :D</description>
		<content:encoded><![CDATA[<p>Kewl, hopefully we can share the method as well. Especially on db data mining <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hanashi</title>
		<link>http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html/comment-page-1#comment-2151</link>
		<dc:creator>Hanashi</dc:creator>
		<pubDate>Wed, 21 Mar 2007 12:16:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html#comment-2151</guid>
		<description>Great example!  This is exactly how Sguil was designed to be used.  Personally, I find myself using transcripts to answer probably 80% or 90% of all my questions when I&#039;m processing alerts, and that saves me tons of time.

As for the session data, I&#039;ve also had very good results in using it to identify additional events using some basic traffic analysis.  With a little SQL-foo, it&#039;s pretty easy to spot scanners, for example.  I also correlate session data with PHP injection attack attempts as a rudimentary way to see if any where successful.  Datamining the SQL db is big interest of mine, and most of that hinges on the session data.</description>
		<content:encoded><![CDATA[<p>Great example!  This is exactly how Sguil was designed to be used.  Personally, I find myself using transcripts to answer probably 80% or 90% of all my questions when I&#8217;m processing alerts, and that saves me tons of time.</p>
<p>As for the session data, I&#8217;ve also had very good results in using it to identify additional events using some basic traffic analysis.  With a little SQL-foo, it&#8217;s pretty easy to spot scanners, for example.  I also correlate session data with PHP injection attack attempts as a rudimentary way to see if any where successful.  Datamining the SQL db is big interest of mine, and most of that hinges on the session data.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.957 seconds -->

