Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
The Threat Of Security Analytics Complexity
Newest First  |  Oldest First  |  Threaded View
Dr.T
Dr.T,
User Rank: Ninja
3/27/2016 | 6:10:21 PM
Secure Software
 

Obviously best defense is to build a secure software. Analytics is still basically a catch-up, we just need to re-think our software development practices and embed security while code is being written.
Dr.T
Dr.T,
User Rank: Ninja
3/27/2016 | 6:05:08 PM
Security Analytics
It is mandatory today. This is not a new topic, building knowledge to prevent from future attacks is what we do by default we just need to go beyond that and predicts attacks when there is no any predictability of it.
Dr.T
Dr.T,
User Rank: Ninja
3/27/2016 | 6:04:20 PM
Re: Nice post!
Big data and analytics certainly has big impacts. We just need to use right tools for the right vulnerabilities.

 
Dr.T
Dr.T,
User Rank: Ninja
3/27/2016 | 6:01:13 PM
Re: analytics
I have not used GoStats, is this like Google Analytics or anything more than that?
Dr.T
Dr.T,
User Rank: Ninja
3/27/2016 | 5:57:31 PM
Machine learning in security
A great idea but should be implemented very carefully. As we just experience with Microsoft bot machine could be thought in an unexpected way and results into unintended consequences.
randyorton
randyorton,
User Rank: Apprentice
3/26/2016 | 3:34:23 AM
Re: analytics
good one
kbannan100
kbannan100,
User Rank: Moderator
3/24/2016 | 1:05:05 PM
Nice post!
Excellent article and a true example of how analytics are changing everything -- from security to busines to innovation.


--KB


Karen Bannan, commenting for IDG and Informatica
AllWebAnalytics
AllWebAnalytics,
User Rank: Apprentice
3/24/2016 | 6:10:43 AM
analytics
Great article on security and analytics ... be it sites or data analytics play important tool and GA and Gostats are the ones we look for solutions.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Black Hat USA 2022 Attendee Report
Black Hat attendees are not sleeping well. Between concerns about attacks against cloud services, ransomware, and the growing risks to the global supply chain, these security pros have a lot to be worried about. Read our 2022 report to hear what they're concerned about now.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-36030
PUBLISHED: 2022-08-20
Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes available.
CVE-2022-2789
PUBLISHED: 2022-08-19
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic.
CVE-2022-2790
PUBLISHED: 2022-08-19
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (BLD/BLK files).
CVE-2022-2792
PUBLISHED: 2022-08-19
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.
CVE-2022-2793
PUBLISHED: 2022-08-19
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.