Network Monitoring SIG News http://www.first.org/newsroom/news/nm-sig.html Networking Monitoring Special Interest Group news and related information FIRST.org, Inc. © 1995-2008 by FIRST.org, Inc. Thu, 31 Jul 2008 17:06:00 -0500 Wed, 16 May 2012 23:54:37 -0500 Tecnodesign (http://tecnodz.com) en-us 20 Network Monitoring SIG Newshttp://www.first.org/newsroom/news/nm-sig.html/_images/first-news.png 5th NM-SIG meeting 'Monitoring and Detection of Fast-Flux Service Networks' http://www.first.org/meetings/nm-sig/20080624.html firstnews:40345 Around 60 attendees joined the 5th NM-SIG meeting 'Monitoring and Detection of Fast-Flux Service Networks'. The NM-SIG had invited 3 speakers to talk about this topic, namely David Watson(The Honeynet Project), Jose Nazario(Arbor Networks) and Christian Gorecki(University of Mannheim). David gave an introduction on Fast-Flux Service Networks. Jose talked about Fast-Flux detection via Arbor's project ATLAS. And Christian presented an approach to automate detection of Fast-Flux with certain metrics. The last part of the meeting was called 'Bring your demo'. Three people gave a short demo of network monitoring tools. Florian Weimer explained the approach of passive DNS replication, which also can be used to track Fast-Flux domains. Tillmann Werner gave a demo of 'Nebula', an intrusion signature generator. And Piotr Kijewski showed HoneySpider Network, a client honeypot solution. The feedback of this meeting was very positive and we hope to plan more of these meetings in the near future. Thu, 31 Jul 2008 17:06:00 +0100 NM-SIG meeting 20th Annual FIRST Conference Vancouver: looking for speakers http://www.first.org/global/sigs/monitoring/ firstnews:38543 During the 20th annual FIRST conference in Vancouver (June 22-27, 2008), the Network Monitoring Special Interest Group (NM-SIG) is planning a meeting. During this meeting we would like to focus on the theme: "Monitoring and Detection of Fast-Flux Service Networks" We are looking for speakers who are interested to give a presentation about their tools and experiences regarding monitoring and detection of Fast-Flux Service Networks. If you are interested to give a presentation or if you know anyone who might be interesting to invite, you can the NM-SIG Chair Carol Overes (carol.overes@govcert.nl). Wed, 19 Mar 2008 15:22:00 +0100 4th NM-SIG meeting great success! http://www.first.org/newsroom/releases/20071031.html firstnews:100 The very interactive 4th NM-SIG meeting was held on Wednesday 17th October in Noordwijk (NL), before the GOVCERT.NL-symposium. Around 14 people attended the meeting. With hindsight... Wed, 31 Oct 2007 16:47:00 +0100 nfdump-1.5.6 released http://sourceforge.net/projects/nfdump/ firstnews:99 SWITCH-CERT has released nfdump-1.5.6. It includes: * Fix odd CISCO behaviour for ICMP type/code in src port. * Add fast LZO1X-1 compression option (-z) for output file. * Add lists for port in syntax -> port in [ 135 137 445] * Add lists for AS syntax -> as in [ 1024 1025 ] * Bug fix in filter for syntax 'src as and dst as' Wed, 31 Oct 2007 16:33:00 +0100 Third NM-SIG meeting at FIRST conference Seville http://www.first.org/global/sigs/monitoring/ firstnews:88 The third meeting of the NM-SIG has been held on Thursday 21 June 2007, during the FIRST conference in Seville. Around 35 attendees joined discussions on various topics. The minutes of the meeting will be available for NM-SIG members soon. Fri, 29 Jun 2007 18:00:00 +0100 New Arakis early warning system web interface http://www.arakis.pl firstnews:72 CERT Polska updated the public interface of Arakis early warning system. Statistics from honeynets, darknets, firewalls and antivirus systems are now available, along with information about new packet payload seen on honeypots -- all in English. Thu, 14 Jun 2007 14:15:00 +0100