Perimeter
9/14/2010
11:50 PM
Tim Wilson
Tim Wilson
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Dark Reading Launches Tech Center On Security Monitoring

Today Dark Reading launches a new feature: the Security Monitoring Tech Center, a subsite of Dark Reading devoted to bringing you news, insight, and in-depth reporting on the topic of security data monitoring and analysis.

Today Dark Reading launches a new feature: the Security Monitoring Tech Center, a subsite of Dark Reading devoted to bringing you news, insight, and in-depth reporting on the topic of security data monitoring and analysis.This is the seventh of our Dark Reading Tech Centers, which are designed to provide you with a more focused view of specific issues, threats, and technologies in the world of IT security. The Tech Centers offer in-depth reports and studies, breaking news, and links to additional articles and information not found on the main Dark Reading site. Just as a traditional newspaper offers in-depth sections or supplements on sports, entertainment, or politics, the Dark Reading Tech Centers provide an additional range of news and information for readers who have an interest in specific aspects of IT security.

While Dark Reading does a good deal of coverage of security monitoring, management, and administration, we have not previously offered a single location for news and information on such critical topics as security information and event management (SIEM), network security monitoring, log file analysis, and end user/employee monitoring. The goal of the Security Monitoring Tech Center is to provide breaking news on these important technologies and the threats, challenges, and opportunities that surround them.

With this charter in mind, you can expect the Security Monitoring Tech Center to take a slightly different perspective than the rest of the Dark Reading site -- our coverage will be focused not only on threats that could turn up on your security monitoring screen, but also best practices for instrumenting your security management systems and tips for analyzing security event data. You'll get a deeper look at the monitoring methods and technologies that really work -- and insight on why others really don't.

The goal of the Security Monitoring Tech Center is to help you make informed decisions about what tools, technologies, services, and practices your organization can use to quickly identify potential threats to your organization -- and how to respond to them. In some cases, we'll discuss practices you can implement yourself; in other cases, we'll offer a look at technologies or services you can purchase from vendors, service providers, or consultants. And we'll keep you abreast of the latest threats to look for in your security analysis, and some tips on how to analyze and remediate them quickly.

Of course, the creation of the Security Monitoring Tech Center doesn't mean that our coverage of security management and administration issues on the main Dark Reading site will decrease. You'll continue to see stories about new developments in security monitoring on our home page, and the subject will remain a topic of discussion for our bloggers and on our message boards. But when you click on those stories or blogs, you'll be brought here, to the Tech Center, so you can see the full range of news and information that we offer on the topic, and gain additional context to support what you're reading. We think the Security Monitoring Tech Center will help you understand the security challenges that your organization might face, and make good decisions about the tools and practices that might work best. But in the end, this is your site. Please let us know what you think of the Tech Center, our coverage of security monitoring issues, and what you'd like to see us cover in more depth. We can't guarantee we'll answer every query with a story or in-depth report, but we'll do our best to meet your needs for additional information and analysis.

If it has to do with tools, technologies, or best practices in security monitoring, then you'll find it here. And if you don't, let us know -- our goal is to be the most comprehensive source of security monitoring news and information on the Web.

Tim Wilson Editor, Dark Reading Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6117
Published: 2014-07-11
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

CVE-2014-0174
Published: 2014-07-11
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVE-2014-3485
Published: 2014-07-11
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.

CVE-2014-3499
Published: 2014-07-11
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

CVE-2014-3503
Published: 2014-07-11
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.