<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Not only alert data Part III</title>
	<atom:link href="http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html</link>
	<description>I dunno why on earth I have this blog.</description>
	<pubDate>Fri, 21 Nov 2008 03:09:14 +0000</pubDate>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>By: ayoi</title>
		<link>http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html#comment-2152</link>
		<dc:creator>ayoi</dc:creator>
		<pubDate>Wed, 21 Mar 2007 12:50:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html#comment-2152</guid>
		<description>Kewl, hopefully we can share the method as well. Especially on db data mining :D</description>
		<content:encoded><![CDATA[<p>Kewl, hopefully we can share the method as well. Especially on db data mining <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hanashi</title>
		<link>http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html#comment-2151</link>
		<dc:creator>Hanashi</dc:creator>
		<pubDate>Wed, 21 Mar 2007 12:16:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/185/not-only-alert-data-part-iii.html#comment-2151</guid>
		<description>Great example!  This is exactly how Sguil was designed to be used.  Personally, I find myself using transcripts to answer probably 80% or 90% of all my questions when I'm processing alerts, and that saves me tons of time.

As for the session data, I've also had very good results in using it to identify additional events using some basic traffic analysis.  With a little SQL-foo, it's pretty easy to spot scanners, for example.  I also correlate session data with PHP injection attack attempts as a rudimentary way to see if any where successful.  Datamining the SQL db is big interest of mine, and most of that hinges on the session data.</description>
		<content:encoded><![CDATA[<p>Great example!  This is exactly how Sguil was designed to be used.  Personally, I find myself using transcripts to answer probably 80% or 90% of all my questions when I&#8217;m processing alerts, and that saves me tons of time.</p>
<p>As for the session data, I&#8217;ve also had very good results in using it to identify additional events using some basic traffic analysis.  With a little SQL-foo, it&#8217;s pretty easy to spot scanners, for example.  I also correlate session data with PHP injection attack attempts as a rudimentary way to see if any where successful.  Datamining the SQL db is big interest of mine, and most of that hinges on the session data.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 1.347 seconds -->
