<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Juxt Art &#187; Correlation</title>
	<atom:link href="http://jackwhitsitt.com/category/correlation/feed/" rel="self" type="application/rss+xml" />
	<link>http://jackwhitsitt.com</link>
	<description>Art of Jack Whitsitt, a Washington, DC Based Artist and Information Security Architect</description>
	<lastBuildDate>Fri, 18 Jun 2010 16:31:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Art and Security: A Norton Today (Symantec) Interview with Jack Whitsitt</title>
		<link>http://jackwhitsitt.com/2008/10/art-and-security-a-norton-today-symantec-interview-with-me/</link>
		<comments>http://jackwhitsitt.com/2008/10/art-and-security-a-norton-today-symantec-interview-with-me/#comments</comments>
		<pubDate>Mon, 06 Oct 2008 18:10:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ArcSight]]></category>
		<category><![CDATA[Art]]></category>
		<category><![CDATA[Correlation]]></category>
		<category><![CDATA[District of Columbia]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[Projects]]></category>
		<category><![CDATA[Source Material]]></category>
		<category><![CDATA[Technique]]></category>
		<category><![CDATA[Washington DC]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[abstract]]></category>
		<category><![CDATA[Color]]></category>
		<category><![CDATA[Concept Representation in Art]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Gallery]]></category>
		<category><![CDATA[Graphing]]></category>
		<category><![CDATA[Graphs]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Interactive Discovery]]></category>
		<category><![CDATA[Interview]]></category>
		<category><![CDATA[Jack Whitsitt]]></category>
		<category><![CDATA[magazine]]></category>
		<category><![CDATA[media experimentation]]></category>
		<category><![CDATA[my space on 7th]]></category>
		<category><![CDATA[NetSec]]></category>
		<category><![CDATA[Norton]]></category>
		<category><![CDATA[Norton Today]]></category>
		<category><![CDATA[online]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Event Analysis]]></category>
		<category><![CDATA[show]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[utilitarian]]></category>
		<category><![CDATA[visualization]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=272</guid>
		<description><![CDATA[I&#8217;ve spammed this particular link everwhere else I can think of, but still neglected to post it here on my blog. Basically, I was approached a few months ago by a senior editor of Symantec&#8217;s online magazine &#8220;Norton Today&#8221; because they were interested in doing a piece on Art and Security. I was approached because [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve spammed this particular link everwhere else I can think of, but still neglected to post it here on my blog.</p>
<p>Basically, I was approached a few months ago by a senior editor of Symantec&#8217;s online magazine &#8220;Norton Today&#8221; because they were interested in doing a piece on Art and Security. I was approached because of my old work in security data visualization and the fact that&#8217;d I&#8217;d started to rework and hang the pieces in art shows like Artomatic and <a href="http://sintixerr.wordpress.com/2008/07/07/art-and-security-data-visualization-in-dc-art-show/" target="_blank">My Space on 7th</a>.</p>
<p>Anyway, the interview went really well (in addition to being a lot of fun) and it&#8217;s now online at:</p>
<p><a href="http://nortontoday.symantec.com/features/articles/art_of_security.php" target="_blank">http://nortontoday.symantec.com/features/articles/art_of_security.php</a></p>
<p>(Edit: This link now appears down after a few months. Symantec has republished the article here: <a href="http://www.thegeekweekly.com/feature/turning_computer_vis_into_art/index.html" target="_blank"><strong>http://www.thegeekweekly.com/feature/turning_computer_vis_into_art/index.html</strong></a> )</p>
<p>They used a few <a href="http://flickr.com/photos/sintixerr/sets/72157594550497033/" target="_blank">older images </a>in their Flash slideshow (My fault &#8211; I didnt get them newer images in time).  These were the originals we used at NetSec to do analysis and which have been in a number of presentations (and were in the batch I sent to ArcSight as examples when they were still developing Interactive Discovery, iirc).</p>
<p>You can find the &#8220;art&#8221; versions that I&#8217;ve hung up in galleries at the following link:</p>
<p><a href="http://sintixerr.wordpress.com/art-versions-of-data-visualizations/" target="_blank">http://sintixerr.wordpress.com/art-versions-of-data-visualizations/</a></p>
<p>I&#8217;m still interested in working more of these, but have been moving from graphing &#8211; which was a necessity of the business at the time &#8211; into a broader field of ontological information/concept representation in art.</p>
<p>(This is in addition to my media experimentation with / interest in projection. I think Id like to merge these two tracks together in the future, but havent gotten there yet.)</p>
]]></content:encoded>
			<wfw:commentRss>http://jackwhitsitt.com/2008/10/art-and-security-a-norton-today-symantec-interview-with-me/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Space on 7th: Data Visualization at DC Art Show</title>
		<link>http://jackwhitsitt.com/2008/07/art-and-security-data-visualization-in-dc-art-show/</link>
		<comments>http://jackwhitsitt.com/2008/07/art-and-security-data-visualization-in-dc-art-show/#comments</comments>
		<pubDate>Tue, 08 Jul 2008 04:46:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Art]]></category>
		<category><![CDATA[Correlation]]></category>
		<category><![CDATA[District of Columbia]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Gallery]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[Projects]]></category>
		<category><![CDATA[Salon]]></category>
		<category><![CDATA[Source Material]]></category>
		<category><![CDATA[Washington DC]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[abstract]]></category>
		<category><![CDATA[artist]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[DC]]></category>
		<category><![CDATA[destination ports]]></category>
		<category><![CDATA[Digital Art]]></category>
		<category><![CDATA[digital artist]]></category>
		<category><![CDATA[graph]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[illegitimate]]></category>
		<category><![CDATA[Jack Whitsitt]]></category>
		<category><![CDATA[my space on 7th]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[show]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[touchstone]]></category>
		<category><![CDATA[touchstone gallery]]></category>
		<category><![CDATA[visualization]]></category>
		<category><![CDATA[viz]]></category>
		<category><![CDATA[Washington]]></category>
		<category><![CDATA[web traffic]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/?p=236</guid>
		<description><![CDATA[Hey all! I&#8217;m going to be showing some data visualizations at the My Space on 7th art show in Washington, DC starting Friday, July 11 at the Touchstone Gallery! Everyone should come out. I took a look at the space and there&#8217;s some interesting work hanging already. (And I have to thank Paige, here, who [...]]]></description>
			<content:encoded><![CDATA[<p>Hey all!</p>
<p>I&#8217;m going to be showing some data visualizations at the <a href="http://www.touchstonegallery.com/exhibitions/2008/07-2008.html" target="_blank">My Space on 7th</a> art show in Washington, DC starting Friday, July 11 at the <a href="http://www.touchstonegallery.com/" target="_blank">Touchstone Gallery!</a> Everyone should come out. I took a look at the space and there&#8217;s some interesting work hanging already. <em>(And I have to thank <a href="http://www.flickr.com/photos/paigerella/" target="_blank">Paige</a>, here, who unintentionally helped me decide what to show&#8230;but more on that in a later post.)</em></p>
<p>Oh. And there will be wine tasting opening night. <img src='http://jackwhitsitt.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://sintixerr.files.wordpress.com/2008/07/myspaceon7th-invitation.jpg"><img class="aligncenter size-medium wp-image-237" src="http://sintixerr.files.wordpress.com/2008/07/myspaceon7th-invitation.jpg?w=300" alt="" width="502" height="354" /></a></p>
<p>There will be three old, but reworked images and one new one created just for this show.  Only one has ever been printed before and they all look pretty fantastic.</p>
<p>The new one consists of two superimposed graphs (a paraplot and a scatterplot) of illegitimate traffic going to/from &#8220;jackwhitsitt.com&#8221; (that would be, uh, most of it).</p>
<p><img class="alignnone" src="http://farm4.static.flickr.com/3108/2644426937_c659fac624.jpg" alt="" /></p>
<p>The three older ones are:</p>
<p><em>Destination Port Traffic Volume (global sample)</em></p>
<p><img class="alignnone" src="http://farm4.static.flickr.com/3049/2644425759_a33988d0f4.jpg" alt="" /></p>
<p><em>(Test Data from custom developed SEM correlation  modules)</em></p>
<p><img class="alignnone" src="http://farm4.static.flickr.com/3094/2642524965_24d2dfea56.jpg" alt="" /></p>
<p><em><br />
</em></p>
<p><em>(Pcap data from 10,000 spam emails)</em></p>
<p><img class="alignnone" src="http://farm4.static.flickr.com/3112/2631686392_7025a3d245.jpg" alt="" /></p>
]]></content:encoded>
			<wfw:commentRss>http://jackwhitsitt.com/2008/07/art-and-security-data-visualization-in-dc-art-show/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Twilight Truth Still Truth</title>
		<link>http://jackwhitsitt.com/2007/11/twilight-truth-still-truth-quote-seen-referenced-today/</link>
		<comments>http://jackwhitsitt.com/2007/11/twilight-truth-still-truth-quote-seen-referenced-today/#comments</comments>
		<pubDate>Thu, 01 Nov 2007 16:10:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Correlation]]></category>
		<category><![CDATA[Counter-terrorism]]></category>
		<category><![CDATA[Criticism]]></category>
		<category><![CDATA[Life]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Personal]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/2007/11/01/twilight-truth-still-truth-quote-seen-referenced-today/</guid>
		<description><![CDATA[Someone used this Rod Serling quote today in a post to Bruce Schneier&#8217;s blog. It bears repeating. &#8220;The tools of conquest do not necessarily come with bombs and explosions and fallout. There are weapons that are simply thoughts, attitudes, prejudices, to be found only in the minds of men. For the record: prejudices can kill, [...]]]></description>
			<content:encoded><![CDATA[<p>Someone used this Rod Serling quote today in a post to Bruce Schneier&#8217;s blog. It bears repeating.</p>
<blockquote><p>&#8220;The tools of conquest do not necessarily come with bombs and explosions and fallout. There are weapons that are simply thoughts, attitudes, prejudices, to be found only in the minds of men. For the record: prejudices can kill, and suspicion can destroy, and the thoughtless, frightened search for a scapegoat has a fallout all of its own, for the children and the children yet unborn. And the pity of it is that such things cannot be confined&#8230; to The Twilight Zone.&#8221;</p></blockquote>
<p><a href="http://en.wikipedia.org/wiki/The_Monsters_Are_Due_on_Maple_Street" rel="nofollow"><font color="#0000eb">http://en.wikipedia.org/wiki/The_Monsters_Are_Due_on_Maple_Street</font></a></p>
]]></content:encoded>
			<wfw:commentRss>http://jackwhitsitt.com/2007/11/twilight-truth-still-truth-quote-seen-referenced-today/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Late Night Review: Use &#8220;Ontology&#8221; in a sentence once a day</title>
		<link>http://jackwhitsitt.com/2007/09/late-night-review-use-ontology-in-a-sentence-once-a-day/</link>
		<comments>http://jackwhitsitt.com/2007/09/late-night-review-use-ontology-in-a-sentence-once-a-day/#comments</comments>
		<pubDate>Mon, 17 Sep 2007 03:03:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ArcSight]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Correlation]]></category>
		<category><![CDATA[ESM]]></category>
		<category><![CDATA[Enterprise Architecture]]></category>
		<category><![CDATA[Enterprise Security Architecture]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Ontologies]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[SOA]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/2007/09/16/late-night-review-use-ontology-in-a-sentence-once-a-day/</guid>
		<description><![CDATA[Just comments on a previous coworker&#8217;s paper that he&#8217;s writing on tuning ArcSight. It&#8217;s a bit spewy and unedited (and will go to the other blog as a less stream-of-consciousness bit when I start it shortly), but I thought I&#8217;d pass the time until a write another art entry (photography is fun!) with it anyway: [...]]]></description>
			<content:encoded><![CDATA[<p>Just comments on a previous coworker&#8217;s paper that he&#8217;s writing on tuning ArcSight.  It&#8217;s a bit spewy and unedited (and will go to the other blog as a less stream-of-consciousness bit when I start it shortly), but I thought I&#8217;d pass the time until a write another art entry (photography is fun!) with it anyway:</p>
<blockquote><p>What seems to be missing is commentary on the how and why of acting on the information that goes through the ESM &#8211; beyond just how the tools to perform those actions work.</p>
<p>By way of example, look at these specific quotes:<br />
<span style="font-style:italic;">1. Normalization also includes translating the severity scales used by the different devices into ArcSight&#8217;s &#8220;Agent Severity&#8221; scale. </span></p>
<p><span style="font-style:italic;"><span style="font-style:italic;"> 2. </span>ArcSight connectors also assign each event to a set of categories (that is, it assigns a category tuple) using six fields derived from the fields included in the events collected by the connectors. These categories are designed to group like events from unlike devices, from two different IDSs for example, say, from ISS and Cisco.<br />
</span><br />
Why does ArcSight do this? What does it mean to my correlation rules? Can I, algorithmically ahead of time, <span style="font-weight:bold;">guarantee</span> that the system will &#8220;think&#8221; about every event I want it to? With almost every single correlation methodology Ive seen &#8211; especially including ArcSight&#8217;s default methodology &#8211; the answer is a resounding &#8220;NO&#8221;.  This means that you (formally) have no idea where your bits are at any point, whether they&#8217;ve been aggregated, why or why not, what transformations or decisions ArcSight has made about them, etc.</p>
<p>This methodology failure means that you cannot go back and do formal analysis on an incident that has passed through ArcSight without the original raw events and significant manual labor except by sheer luck (and thats not formal).</p>
<p>Read that statement above again, it&#8217;s important!<br />
<span style="font-style:italic;"><span style="font-style:italic;"></span></span><br />
Basically, tuning the correlation engine (ArcSight) should never be approached from an &#8220;I need to get rid of stuff&#8221; &#8211; pure data reduction &#8211; standpoint. You will, probably, ultimately achieve reduction but thats an effect of the effort, not it&#8217;s actual goal. What you are doing, rather, is defining your environment (in a very literal sense).</p>
<p>These definitions (filters in ArcSight) then allow you to programmatically create an ontology within your system which defines your information classes, what their properties are, and how they relate to each other. That ontology exists as a combination of your basic filters and your core rules.</p>
<p>Once you know what your classes are, you can then write rules to define what kind of transformation (comparison, aggregation, filter, pass to another rule, send to active channel) ArcSight performs on your events.</p>
<p>Once these basic rules are written, you can then write higher level rules to express your intentions logically: &#8220;Show me when any perimeter firewall exceeds its normal state by a factor thats unusual across the enterprise firewalls&#8221;.</p>
<p>In that statement, you have to have &#8220;Firewalls&#8221; defined, what a Perimeter Firewall is, what your enterprise is, what kind of traffic values and ranges firewalls can expect, what your average enterprise data rate is for firewalls, and a host of other things.  Unless you have formally created these things in ArcSight&#8217;s rule/filter system and can reuse you cant hope to create a scalable correlation engine &#8211; youll lose track of what the system is doing and will have to spend time / effort manually retracing how ArcSight got from point A to B and you lose the precision/accuracy of machine correlation in favor of manual correlation under pressure.</p>
<p>Once all of that is in place, you can use create rule classes: Groups of rules that organize and group events, rules that compare them to each other to say something smart about them, and then rules that either present the new events to analysts, send them back for additional correlation, or drop them completely.</p>
<p>I hope Im making some sense here <img src='http://jackwhitsitt.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I would highly suggest checking out this URL: <a href="http://en.wikipedia.org/wiki/Ontology_%28computer_science%29" target="_blank">http://en.wikipedia.org/wiki/Ontology_(computer_science)</a></p>
<p>and:</p>
<p><a href="http://en.wikipedia.org/wiki/Enterprise_service_bus" target="_blank">http://en.wikipedia.org/wiki/Enterprise_service_bus</a></p>
<p>Ontologies are excruciatingly important to understand if youre doing ESM correlation (not that theyre commonly understood, but trust me on this)</p>
<p>Enterprise Service Bus&#8217;s (in Service Oriented Architectures) have a lot of the same requirements and features as ArcSight/ESM&#8217;s and are a good model to look at for what ArcSight&#8217;s role is in the context of security devices.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://jackwhitsitt.com/2007/09/late-night-review-use-ontology-in-a-sentence-once-a-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Closure</title>
		<link>http://jackwhitsitt.com/2007/09/closure/</link>
		<comments>http://jackwhitsitt.com/2007/09/closure/#comments</comments>
		<pubDate>Sun, 02 Sep 2007 19:58:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Art]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Correlation]]></category>
		<category><![CDATA[Counter-terrorism]]></category>
		<category><![CDATA[Enterprise Architecture]]></category>
		<category><![CDATA[Enterprise Security Architecture]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Ontologies]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Professional]]></category>
		<category><![CDATA[SOA]]></category>
		<category><![CDATA[TSA]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[digital]]></category>

		<guid isPermaLink="false">http://sintixerr.wordpress.com/2007/09/02/closure/</guid>
		<description><![CDATA[For various reasons, I&#8217;ve decided to close the SintixErr Gallery in Second Life. Not least of these was the fact that it was costing me $200/month to maintain (including the streaming media accounts). Work has taken on some new angles and that aspect of my life is finally waking from a long slumber and requires [...]]]></description>
			<content:encoded><![CDATA[<p>For various reasons, I&#8217;ve decided to close the SintixErr Gallery in Second Life. Not least of these was the fact that it was costing me $200/month to maintain (including the streaming media accounts).  Work has taken on some new angles and that aspect of my life is finally waking from a long slumber and requires my undivided attantion. Correlation, Ontologies, Semantics, Enterprise Architectures, National Security, Terrorist Watchlists, SOA, Enterprise Service Buses, oh my.</p>
<p>I gave a talk at the DHS Security conference in Baltimore recently about Policy Driven Enterprise Security Architecture and was blown away by how few people understand how much the theory driving EA is going to impact the whole connected human race over the next few decades. They typically regard it as a morass of empty paperwork instead of an attempt to solve the fundamental problems we face as we move from the Data to the actual Information Age.</p>
<p>So, I&#8217;ll be starting a new blog about these topics in the next day or so. Check back for more info on that later.</p>
<p>In the mean time, check out this fantastically on-point book, <a href="http://www.amazon.com/Information-Technologies-Counter-Terrorism-Computational-Intelligence/dp/0471776157" target="_blank">&#8220;Emergent Information Technologies and Enabling Policies for Counter-Terrorism&#8221;</a>  from IEEE Press Series on Computational Intelligence.  It&#8217;s amazing how similar the Security Event Correlation, Enterprise Architecture, and Counter-Terrorism information theory problem domains are.</p>
<p>Also, if you want some dated and dry but still relevant reading straight from the US government, try this (I found it in the above book): <a href="http://www.gao.gov/new.items/d03322.pdf" target="_BLANK">http://www.gao.gov/new.items/d03322.pdf</a></p>
<p>It essentially links EA directly to National Security matters.</p>
]]></content:encoded>
			<wfw:commentRss>http://jackwhitsitt.com/2007/09/closure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
