<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Small Blue-Green World</title>
	<atom:link href="http://smallbluegreenblog.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://smallbluegreenblog.wordpress.com</link>
	<description>publishing for the IT security community</description>
	<lastBuildDate>Mon, 12 Dec 2011 18:03:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='smallbluegreenblog.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/8eddef4d4e447d6b410948d4f5d9e975?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Small Blue-Green World</title>
		<link>http://smallbluegreenblog.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://smallbluegreenblog.wordpress.com/osd.xml" title="Small Blue-Green World" />
	<atom:link rel='hub' href='http://smallbluegreenblog.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Malicious Android: why the Birds are Angry</title>
		<link>http://smallbluegreenblog.wordpress.com/2011/12/12/malicious-android-why-the-birds-are-angry/</link>
		<comments>http://smallbluegreenblog.wordpress.com/2011/12/12/malicious-android-why-the-birds-are-angry/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 17:49:46 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[David Harley]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[mobile malware]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Mac Virus]]></category>
		<category><![CDATA[Blackberry]]></category>
		<category><![CDATA[RIM]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[Chris DiBona]]></category>

		<guid isPermaLink="false">http://smallbluegreenblog.wordpress.com/?p=355</guid>
		<description><![CDATA[It&#8217;s no secret that trojans that misuse premium SMS services are one of the most prevalent problems in the mobile malware arena. However, the flood of &#8220;Lagostrod&#8221; and &#8220;Miriada&#8221; so-called free knock-offs of real games are peppered with code that sends text messages to premium services. Mikko Hypponen retweeted an estimate, based on comments to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=355&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s no secret that trojans that misuse premium SMS services are one of the most prevalent problems in the mobile malware arena. However, the flood of &#8220;Lagostrod&#8221; and &#8220;Miriada&#8221; so-called free knock-offs of <a href="http://www.reddit.com/r/Android/comments/n8o3o/theres_trouble_written_all_over_this" target="_blank">real games</a> are peppered with code that sends text messages to premium services. Mikko Hypponen retweeted <a href="http://twitter.com/#!/nwhusted/statuses/146262794239614976" target="_blank">an estimate</a>, based on <a href="http://www.reddit.com/r/Android/comments/n8o3o/theres_trouble_written_all_over_this" target="_blank">comments to reddit</a>, that the attackers could have made around $12,000,000.</p>
<p><a href="http://smallbluegreenblog.files.wordpress.com/2011/12/12million.png"><img title="12million" src="http://smallbluegreenblog.files.wordpress.com/2011/12/12million.png?w=300&#038;h=148" alt="" width="300" height="148" /></a></p>
<p>According to Sophos&#8217; <a href="http://nakedsecurity.sophos.com/2011/12/12/malicious-cloned-games-attack-google-android-market/" target="_blank">Vanja Svajcer</a>:</p>
<p style="padding-left:30px;">After more than a day on the market, the applications were pulled off by the Android Market security team. Google&#8217;s reaction has been quick, but not quick enough &#8211; at least ten thousand users downloaded one of the malicious apps from the list.</p>
<p>Much more information on the event in Vanja&#8217;s blog and in Sean&#8217;s blog for <a href="http://www.f-secure.com/weblog/archives/00002280.html" target="_blank">F-Secure</a>.</p>
<p>I hope to see an apology from <a href="http://macviruscom.wordpress.com/2011/11/21/memoirs-of-a-charlatan-scammer/" target="_blank">Chris DiBona</a> for suggesting that anyone working for an AV company <a href="https://plus.google.com/u/0/114765095157367281222/posts/ZqPvFwdDLPv#114765095157367281222/posts/ZqPvFwdDLPv" target="_blank">should be ashamed of themselves</a> if they have a product for Android,  Blackberry or iOS, but won&#8217;t be holding my breath.</p>
<p>(Yes, this is the sort of stuff I usually post to Mac Virus, but it&#8217;s not really Apple-related, I guess, so I think I&#8217;ll probably do more of it here.)</p>
<p><strong>David Harley CITP FBCS CISSP</strong><br />
<strong>Small Blue-Green World/AVIEN/Mac Virus</strong><br />
<strong>ESET Senior Research Fellow</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smallbluegreenblog.wordpress.com/355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smallbluegreenblog.wordpress.com/355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/smallbluegreenblog.wordpress.com/355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/smallbluegreenblog.wordpress.com/355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/smallbluegreenblog.wordpress.com/355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/smallbluegreenblog.wordpress.com/355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/smallbluegreenblog.wordpress.com/355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/smallbluegreenblog.wordpress.com/355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/smallbluegreenblog.wordpress.com/355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/smallbluegreenblog.wordpress.com/355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/smallbluegreenblog.wordpress.com/355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/smallbluegreenblog.wordpress.com/355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/smallbluegreenblog.wordpress.com/355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/smallbluegreenblog.wordpress.com/355/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=355&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smallbluegreenblog.wordpress.com/2011/12/12/malicious-android-why-the-birds-are-angry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>

		<media:content url="http://smallbluegreenblog.files.wordpress.com/2011/12/12million.png?w=300" medium="image">
			<media:title type="html">12million</media:title>
		</media:content>
	</item>
		<item>
		<title>Before you get to the blogs further down&#8230;</title>
		<link>http://smallbluegreenblog.wordpress.com/2011/09/16/before-you-get-to-the-blogs/</link>
		<comments>http://smallbluegreenblog.wordpress.com/2011/09/16/before-you-get-to-the-blogs/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 03:15:46 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[anti-malware testing]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Articles]]></category>
		<category><![CDATA[Conference papers]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Testing]]></category>

		<guid isPermaLink="false">http://smallbluegreenblog.wordpress.com/?p=327</guid>
		<description><![CDATA[[Updated on 12th December 2011.] &#8230;welcome! Here&#8217;s a quick overview of the geography of a Small Blue Green World. This is the Small Blue-Green Blog. You could regard it as the gateway to the various blogs and bits and bobs that constitute the SBGW presence on the web. Essentially, this is a consultancy launched by David Harley in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=327&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>[<em>Updated on 12th December 2011.</em>]</p>
<p>&#8230;welcome! Here&#8217;s a quick overview of the geography of a Small Blue Green World. This is the Small Blue-Green Blog. You could regard it as the gateway to the various blogs and bits and bobs that constitute the SBGW presence on the web. Essentially, this is a consultancy launched by <a href="http://en.wikipedia.org/wiki/David_Harley" target="_blank">David Harley</a> in 2006 with one main customer (<a href="http://blog.eset.com/" target="_blank">ESET</a>) so this particular page isn&#8217;t maintained very regularly: it has (currently) no commercial/advertising function, but it includes some papers/resources that may not be available elsewhere. The blogs linked here, however, especially those to which I contribute on ESET&#8217;s behalf, <em>are</em> maintained regularly.</p>
<p><strong>Work for <a href="http://www.eset.com/" target="_blank">ESET</a></strong></p>
<p>The services I provide to ESET are quite wide-ranging, but they include blogging on the <a href="http://blog.eset.com/" target="_blank">ESET blog page</a> and for SC Magazine&#8217;s <a href="http://www.scmagazineus.com/cybercrime-corner/section/1511/" target="_blank">Cybercrime Corner</a>, and other authoring and editing including conference papers, white papers and so on. The <a href="http://www.eset.com/us/documentation/white-papers" target="_blank">ESET white papers page</a> includes papers written specifically for ESET or while representing ESET at conferences and workshop, as well as links to articles written for outside publications and sites, again on ESET&#8217;s behalf.</p>
<p>One of the toughest jobs I do for ESET is to represent the company in the Anti-Malware Testing Standards Organization (<a href="http://www.amtso.org/" target="_blank">AMTSO</a>): not least because I&#8217;m also a member of the AMTSO Board of Directors, which means that I have to prioritise AMTSO&#8217;s interests over ESET&#8217;s on occasion. I don&#8217;t run the main AMTSO site, but I do host the <a href="http://amtso.wordpress.com/" target="_blank">AMTSO blog</a>.</p>
<p>AVIEN (formerly the Anti-Virus Information Exchange Network), which is run as an independent organization by myself and Andrew Lee, is hosted on its own <a href="http://avien.net/" target="_blank">web site</a> and has <a href="http://avien.net/blog" target="_blank">its own blog</a> page hosted there, but will eventually be integrated more closely with these pages. There&#8217;ll be more information on that, however, in due course.</p>
<p>I run several other specialist security blogs completely independently of ESET, and these include a blog focused on <a href="http://chainmailcheck.wordpress.com/" target="_blank">hoaxes, spam, scams and similar nuisances</a> (thanks to <a href="http://www.eset.com/us/" target="_blank">ESET N. America</a> CEO and long-time friend and colleague Andrew Lee, you can also access this as <a href="http://www.virushoax.co.uk)">http://www.virushoax.co.uk</a>, and <a href="http://macviruscom.wordpress.com/" target="_blank">another that focuses (mostly) on Apple malware</a>: essentially, it&#8217;s the current incarnation of the old <a href="http://macvirus.com/" target="_blank">Mac Virus</a> web site originally founded by Susan Lesch, and includes contributions from Old Mac Bloggit, the well-known pseudonym.</p>
<p>I also blog occasionally at other sites, include <a href="http://www.infosecurity-magazine.com/blog/user/david--harley" target="_blank">Infosecurity Magazine</a>,  <a href="http://blog.isc2.org/" target="_blank">(ISC)2</a> and <a href="http://blogs.securiteam.com/" target="_blank">Securiteam</a>. And when I remember, I flag current articles, papers, blogs and media coverage at <a href="http://geekpeninsula.wordpress.com/" target="_blank">The Geek Peninsula</a> (some of this is also tweeted via <a href="http://twitter.com/DavidHarleyBlog/">http://twitter.com/DavidHarleyBlog/</a>)</p>
<p>There are some other blogs associated with this site that aren&#8217;t particularly security-oriented. <a href="http://dharley.wordpress.com/" target="_blank">Words and Music</a> is used for &#8211; well, words and music: songs, verse, miscellaneous extra-curricular prose by David Harley. <a href="http://smallbluegreenfotos.wordpress.com/" target="_blank">Postcards from</a> is a selection from our huge collection of travel photographs, <a href="http://smallbluegreenflowers.wordpress.com/" target="_blank">Flower Portraits</a> is about astronomy (I&#8217;m kidding! It&#8217;s floral photographs!) and <a href="http://smallbluegreenwords.wordpress.com/" target="_blank">Words</a> is other (mostly travel) writing with more photos, all maintained by Jude Harley. Much more to come. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>David Harley CITP FBCS CISSP<br />
Small Blue-Green World</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smallbluegreenblog.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smallbluegreenblog.wordpress.com/327/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/smallbluegreenblog.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/smallbluegreenblog.wordpress.com/327/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/smallbluegreenblog.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/smallbluegreenblog.wordpress.com/327/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/smallbluegreenblog.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/smallbluegreenblog.wordpress.com/327/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/smallbluegreenblog.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/smallbluegreenblog.wordpress.com/327/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/smallbluegreenblog.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/smallbluegreenblog.wordpress.com/327/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/smallbluegreenblog.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/smallbluegreenblog.wordpress.com/327/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=327&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smallbluegreenblog.wordpress.com/2011/09/16/before-you-get-to-the-blogs/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>EICAR 2011 Paper</title>
		<link>http://smallbluegreenblog.wordpress.com/2011/05/15/eicar-2011-paper/</link>
		<comments>http://smallbluegreenblog.wordpress.com/2011/05/15/eicar-2011-paper/#comments</comments>
		<pubDate>Sun, 15 May 2011 10:17:27 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Conference papers]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[EICAR]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[papers]]></category>
		<category><![CDATA[anti-malware]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Black Hat SEO]]></category>
		<category><![CDATA[fake AV]]></category>
		<category><![CDATA[fake security]]></category>
		<category><![CDATA[FUD]]></category>
		<category><![CDATA[Paul Ducklin]]></category>
		<category><![CDATA[rogue anti-malware]]></category>
		<category><![CDATA[rogue marketing]]></category>
		<category><![CDATA[security scams]]></category>
		<category><![CDATA[Virus Bulletin]]></category>

		<guid isPermaLink="false">http://smallbluegreenblog.wordpress.com/?p=314</guid>
		<description><![CDATA[This is a paper presented last week at the EICAR conference in Krems, Austria, on "Security Software &#38; Rogue Economics: New Technology or New Marketing?" <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=314&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>And a big hand, please, for my <a href="http://smallbluegreenblog.files.wordpress.com/2011/05/eicar-2011-paper.pdf">EICAR 2011 paper</a>!</p>
<p>This is a paper I presented last week at the <a href="http:/www.eicar.org/" target="_blank">EICAR</a> conference in Krems, Austria, on &#8220;Security Software &amp; Rogue Economics: New Technology or New Marketing?&#8221; Here&#8217;s the abstract:</p>
<p style="padding-left:30px;">A highlight of the 2009 Virus Bulletin Conference was a panel session on “Free AV vs paid-for AV; Rogue AVs”, chaired by Paul Ducklin. As the title indicates, the discussion was clearly divided into two loosely related topics, but it was perhaps the first indication of a dawning awareness that the security industry has a problem that is only now being acknowledged.</p>
<p style="padding-left:30px;">Why is it so hard for the general public to distinguish between the legitimate AV marketing model and the rogue marketing approach used by rogue (fake) security software? Is it because the purveyors of rogue services are so fiendishly clever? Is it simply because the public is dumb? Is it, as many journalists would claim, the difficulty of discriminating between “legitimate” and criminal flavours of FUD (Fear, Uncertainty, Doubt)? Is the AV marketing model fundamentally flawed? In any case, the security industry needs to do a better job of explaining its business models in a way that clarifies the differences between real and fake anti-malware, and the way in which marketing models follow product architecture.</p>
<p style="padding-left:30px;">This doesn’t just mean declining to mimic rogue AV marketing techniques, bad though they are for the industry and for the consumer: it’s an educational initiative, and it involves educating the business user, the end-user, and the people who market and sell products. A security solution is far more than a scanner: it’s a whole process that ranges from technical research and development, through marketing and sales, to post-sales support. But so is a security threat, and rogue applications involve a wide range of skills: not just the technical range associated with a Stuxnet-like, multi-disciplinary tiger team, but the broad skills ranging from development to search engine optimization, to the psychologies of evaluation and ergonomics, to identity and brand theft, to call centre operations that are hard to tell apart from legitimate support schemes, for the technically unsophisticated customer. A complex problem requires a complex and comprehensive solution, incorporating techniques and technologies that take into account the vulnerabilities inherent in the behaviour of criminals, end-users and even prospective customers, rather than focusing entirely on technologies for the detection of malicious binaries.</p>
<p style="padding-left:30px;">This paper contrasts existing malicious and legitimate technology and marketing, but also looks at ways in which holistic integration of multi-layered security packages might truly reduce the impact of the current wave of fake applications and services.</p>
<p><strong>David Harley CITP FBCS CISSP</strong><br />
<strong>ESET Senior Research Fellow</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smallbluegreenblog.wordpress.com/314/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smallbluegreenblog.wordpress.com/314/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/smallbluegreenblog.wordpress.com/314/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/smallbluegreenblog.wordpress.com/314/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/smallbluegreenblog.wordpress.com/314/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/smallbluegreenblog.wordpress.com/314/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/smallbluegreenblog.wordpress.com/314/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/smallbluegreenblog.wordpress.com/314/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/smallbluegreenblog.wordpress.com/314/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/smallbluegreenblog.wordpress.com/314/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/smallbluegreenblog.wordpress.com/314/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/smallbluegreenblog.wordpress.com/314/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/smallbluegreenblog.wordpress.com/314/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/smallbluegreenblog.wordpress.com/314/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=314&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smallbluegreenblog.wordpress.com/2011/05/15/eicar-2011-paper/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>EICAR Performance Testing Paper</title>
		<link>http://smallbluegreenblog.wordpress.com/2010/05/13/eicar-performance-testing-paper/</link>
		<comments>http://smallbluegreenblog.wordpress.com/2010/05/13/eicar-performance-testing-paper/#comments</comments>
		<pubDate>Thu, 13 May 2010 10:32:57 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[anti-malware testing]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[Ján Vrabec]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[detection testing]]></category>
		<category><![CDATA[EICAR]]></category>
		<category><![CDATA[Paris]]></category>
		<category><![CDATA[performance testing]]></category>

		<guid isPermaLink="false">http://smallbluegreenblog.wordpress.com/?p=259</guid>
		<description><![CDATA[Back to ESET White Papers This is a paper called &#8220;Real Performance?&#8221; written by Ján Vrabec and myself and presented at the 2010 EICAR Conference in Paris in May, available by kind permission of EICAR. Abstract: The methodology and categories used in performance testing of anti-malware products and their impact on the computer remains a contentious area. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=259&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.eset.com/documentation/white-papers" target="_blank">Back to ESET White Papers</a></p>
<p>This is a paper called &#8220;Real Performance?&#8221; written by <span style="font-size:x-small;">Ján Vrabec and myself and presented at the 2010 EICAR Conference in Paris in May, available by kind permission of EICAR.</span></p>
<p><span style="font-size:x-small;">Abstract:</span></p>
<p style="padding-left:30px;"><em>The methodology and categories used in performance testing of anti-malware products and their impact on the computer remains a contentious area. While there’s plenty of information, some of it actually useful, on detection testing, there is very little on performance testing. Yet, while the issues are different, sound performance testing is at least as challenging, in its own way, as detection testing. Performance testing based on assumptions that ‘one size [or methodology] fits all’, or that reflects an incomplete understanding of the technicalities of performance evaluation, can be as misleading as a badly-implemented detection test. There are now several sources of guidelines on how to test detection, but no authoritative information on how to test performance in the context of anti-malware evaluation. Independent bodies are working on these right now but the current absence of such standards often results in the publication of inaccurate comparative test results. This is because they do not accurately reflect the real needs of the end-user and dwell on irrelevant indicators, resulting in potentially skewed product rankings and conclusions. Thus, the “winner” of these tests is not always the best choice for the user. For example a testing scenario created to evaluate performance of a consumer product, should not be used for benchmarking of server products.</em></p>
<p style="padding-left:30px;"><em>There are, of course, examples of questionable results that have been published where the testing body or tester seem to be unduly influenced by the functionality of a particular vendor. However, there is also scope, as with other forms of testing, to introduce inadvertent bias into a product performance test. There are several benchmarking tools that are intended to evaluate performance of hardware but for testing software as complex as antivirus solutions and their impact on the usability of a system, these simply aren’t precise enough. This is especially likely to cause problems when a single benchmark is used in isolation, and looks at aspects of performance that may cause unfair advantage or disadvantage to specific products.</em></p>
<p style="padding-left:30px;"><em>This paper aims to objectively evaluate the most common performance testing models used in anti-malware testing, such as scanning speed, memory consumption and boot speed, and to help highlight the main potential pitfalls of these testing procedures. We present recommendations on how to test objectively and how to spot a potential bias. In addition, we propose some “best-fit” testing scenarios for determining the most suitable anti-malware product according to the specific type of end user and target audience.</em></p>
<p>Download &#8211; <a href="http://smallbluegreenblog.files.wordpress.com/2010/05/eicarrealperformance.pdf">EICAR: Real Performance paper</a></p>
<p><strong>David Harley FBCS CITP CISSP</strong><br />
Security Author/Consultant at Small Blue-Green World<br />
ESET Research Fellow &amp; Director of Malware Intelligence<br />
Chief Operations Officer, AVIEN<br />
Mac Virus Administrator</p>
<p>Also blogging at:<br />
<a href="http://avien.net/blog">http://avien.net/blog</a><br />
<a href="http://www.eset.com/blog">http://www.eset.com/blog</a><br />
<a href="http://smallbluegreenblog.wordpress.com/">http://smallbluegreenblog.wordpress.com/</a><br />
<a href="http://blogs.securiteam.com">http://blogs.securiteam.com</a><br />
<a href="http://blog.isc2.org/">http://blog.isc2.org/</a><br />
<a href="http://dharley.wordpress.com">http://dharley.wordpress.com</a><br />
<a href="http://macvirus.com">http://macvirus.com</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smallbluegreenblog.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smallbluegreenblog.wordpress.com/259/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/smallbluegreenblog.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/smallbluegreenblog.wordpress.com/259/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/smallbluegreenblog.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/smallbluegreenblog.wordpress.com/259/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/smallbluegreenblog.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/smallbluegreenblog.wordpress.com/259/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/smallbluegreenblog.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/smallbluegreenblog.wordpress.com/259/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/smallbluegreenblog.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/smallbluegreenblog.wordpress.com/259/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/smallbluegreenblog.wordpress.com/259/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/smallbluegreenblog.wordpress.com/259/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=259&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smallbluegreenblog.wordpress.com/2010/05/13/eicar-performance-testing-paper/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Re-Floating the Titanic: Social Engineering Paper</title>
		<link>http://smallbluegreenblog.wordpress.com/2010/04/16/re-floating-the-titanic-social-engineering-paper/</link>
		<comments>http://smallbluegreenblog.wordpress.com/2010/04/16/re-floating-the-titanic-social-engineering-paper/#comments</comments>
		<pubDate>Fri, 16 Apr 2010 15:09:11 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Conference papers]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[EICAR]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[AVIEN]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[hoaxes]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[management buy-in]]></category>
		<category><![CDATA[password practice]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[psychological subversion]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Titanic]]></category>

		<guid isPermaLink="false">http://smallbluegreenblog.wordpress.com/?p=252</guid>
		<description><![CDATA[Back to ESET White Papers Re-Floating the Titanic: Dealing with Social Engineering Attacks is a paper I presented at EICAR in 1998. It hasn&#8217;t been available on the web for a while, but as I&#8217;ve had occasion to refer to it several times (for instance, http://www.eset.com/blog/2010/04/16/good-password-practice-not-the-golden-globe-award and http://avien.net/blog/?p=484) in the last few days, I figured it was [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=252&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.eset.com/documentation/white-papers" target="_blank">Back to ESET White Papers</a></p>
<p><a href="http://smallbluegreenblog.files.wordpress.com/2010/04/eicar98.pdf">Re-Floating the Titanic: Dealing with Social Engineering Attacks</a> is a paper I presented at <a title="EICAR Social Engineering Paper" href="http://www.eicar.org/" target="_blank">EICAR </a>in 1998. It hasn&#8217;t been available on the web for a while, but as I&#8217;ve had occasion to refer to it several times (for instance, <a href="http://www.eset.com/blog/2010/04/16/good-password-practice-not-the-golden-globe-award">http://www.eset.com/blog/2010/04/16/good-password-practice-not-the-golden-globe-award</a> and <a href="http://avien.net/blog/?p=484">http://avien.net/blog/?p=484</a>) in the last few days, I figured it was time it went up again. To my surprise, it doesn&#8217;t seem to have dated particularly (less so than the abstract suggests).</p>
<p>Abstract follows: </p>
<p style="padding-left:30px;">&#8220;Social Engineering&#8221; as a concept has moved from the social sciences and into the armouries of cyber-vandals, who have pretty much set the agenda and, arguably, the definitions. Most of the available literature focuses on social engineering in the limited context of password stealing by psychological  subversion. This paper re-examines some common assumptions about what constitutes social engineering, widening the definition of the problem to include other forms of applied psychological manipulation, so as to work towards a holistic solution to a problem that is not generally explicitly recognised as a problem. Classic social engineering techniques and countermeasures are considered, but where previous literature offers piecemeal solutions to a limited range of problems, this paper attempts to extrapolate general principles from particular examples.</p>
<p style="padding-left:30px;">It does this by attempting a comprehensive definition of what constitutes social engineering as a security threat, including taxonomies of social engineering techniques and user vulnerabilities. Having formalized the problem, it then moves on to consider how to work towards an effective solution.  making use of realistic, pragmatic policies, and examines ways of implementing them effectively through education and management buy-in.</p>
<p style="padding-left:30px;">The inclusion of spam, hoaxes (especially hoax virus alerts) and distribution of some real viruses and Trojan Horses in the context of social engineering is somewhat innovative, and derives from the recognition among some security practitioners of an increase in the range of threats based on psychological manipulation. What’s important here is that educational solutions to these problems not only have a bearing on solutions to other social engineering issues, but also equip computer users to make better and more appropriate use of their systems in terms of general security and safety.</p>
<p><strong>David Harley FBCS CITP CISSP</strong><br />
Security Author/Consultant at Small Blue-Green World<br />
Chief Operations Officer, AVIEN<br />
Chief Cook &amp; Bottle Washer, Mac Virus<br />
ESET Research Fellow &amp; Director of Malware Intelligence</p>
<p>Also blogging at:<br />
<a href="http://avien.net/blog">http://avien.net/blog</a><br />
<a href="http://www.eset.com/blog">http://www.eset.com/blog</a><br />
<a href="http://smallbluegreenblog.wordpress.com/">http://smallbluegreenblog.wordpress.com/</a><br />
<a href="http://blogs.securiteam.com">http://blogs.securiteam.com</a><br />
<a href="http://blog.isc2.org/">http://blog.isc2.org/</a><br />
<a href="http://dharley.wordpress.com">http://dharley.wordpress.com</a><br />
<a href="http://macvirus.com">http://macvirus.com</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smallbluegreenblog.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smallbluegreenblog.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/smallbluegreenblog.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/smallbluegreenblog.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/smallbluegreenblog.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/smallbluegreenblog.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/smallbluegreenblog.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/smallbluegreenblog.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/smallbluegreenblog.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/smallbluegreenblog.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/smallbluegreenblog.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/smallbluegreenblog.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/smallbluegreenblog.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/smallbluegreenblog.wordpress.com/252/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=252&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smallbluegreenblog.wordpress.com/2010/04/16/re-floating-the-titanic-social-engineering-paper/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Anti-Phishing Working Group: CeCOS IV</title>
		<link>http://smallbluegreenblog.wordpress.com/2010/03/20/anti-phishing-working-group-cecos-iv/</link>
		<comments>http://smallbluegreenblog.wordpress.com/2010/03/20/anti-phishing-working-group-cecos-iv/#comments</comments>
		<pubDate>Sat, 20 Mar 2010 15:52:37 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Anti-Phishing Working Group]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[Phishing & ID Theft]]></category>
		<category><![CDATA[APWG]]></category>
		<category><![CDATA[Brazil]]></category>
		<category><![CDATA[CeCOS IV]]></category>
		<category><![CDATA[Counter eCrime Operations Summit]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[eCrime]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://smallbluegreenblog.wordpress.com/?p=240</guid>
		<description><![CDATA[The Anti-Phishing Working Group has asked its members to publicize the forthcoming Counter eCrime Operations Summit in Brazil, which I&#8217;m pleased to do. Apologies to those who will have come across this elsewhere, including some of my other blogs. This year the APWG is hosting it&#8217;s fourth annual Counter eCrime Operations Summit (CeCOS IV) on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=240&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.apwg.org/" target="_blank">Anti-Phishing Working Group </a>has asked its members to publicize the forthcoming Counter eCrime Operations Summit in Brazil, which I&#8217;m pleased to do. Apologies to those who will have come across this elsewhere, including some of my other blogs.</p>
<p style="padding-left:30px;">This year the APWG is hosting it&#8217;s fourth annual Counter eCrime Operations Summit (CeCOS IV) on May 11, 12 &amp; 13 in São Paulo, Brazil.  The Discounted Early Bird Registration rate will end on April 9th.  Do not miss this opportunity to join our host CERT.br with APWG Members from around the globe at this one of a kind event. Counter-eCrime professionals will meet for sessions and discussion panels that look into case studies of organizations under attack and deliver narratives of successful trans-national forensic cooperation.</p>
<p style="padding-left:30px;">This is APWG&#8217;s first visit to South America and will help build our network of trusted friends worldwide.  The discounted registration rate of $250 USD covers all three days of content, lunch, breaks and the Wednesday night reception.  (NOTE: APWG Members will receive an additional discount during registration) This &#8220;Early Bird&#8221; rate will end on April 9th, after that through the beginning of the event on 11 May registration is $325 USD.</p>
<p style="padding-left:30px;">A partial agenda is posted at the link below.  Translation services for English, Spanish and Portuguese will be available for all session.</p>
<p style="padding-left:30px;"><a href="http://www.apwg.org/events/2010_opSummit.html#agenda">http://www.apwg.org/events/2010_opSummit.html#agenda</a></p>
<p style="padding-left:30px;">Register Here:</p>
<p style="padding-left:30px;"><a href="http://secure.lenos.com/lenos/antiphishing/cecos2010/">http://secure.lenos.com/lenos/antiphishing/cecos2010/</a></p>
<p>David Harley FBCS CITP CISSP<br />
Security Author/Consultant at Small Blue-Green World<br />
Chief Operations Officer, AVIEN<br />
ESET Research Fellow &amp; Director of Malware Intelligence</p>
<p>Also blogging at:<br />
<a href="http://avien.net/blog">http://avien.net/blog</a><br />
<a href="http://www.eset.com/blog">http://www.eset.com/blog</a><br />
<a href="http://blogs.securiteam.com">http://blogs.securiteam.com</a><br />
<a href="http://blog.isc2.org/">http://blog.isc2.org/</a><br />
<a href="http://dharley.wordpress.com/">http://dharley.wordpress.com</a><br />
<a href="http://macvirus.com/">http://macvirus.com</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smallbluegreenblog.wordpress.com/240/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smallbluegreenblog.wordpress.com/240/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/smallbluegreenblog.wordpress.com/240/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/smallbluegreenblog.wordpress.com/240/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/smallbluegreenblog.wordpress.com/240/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/smallbluegreenblog.wordpress.com/240/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/smallbluegreenblog.wordpress.com/240/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/smallbluegreenblog.wordpress.com/240/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/smallbluegreenblog.wordpress.com/240/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/smallbluegreenblog.wordpress.com/240/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/smallbluegreenblog.wordpress.com/240/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/smallbluegreenblog.wordpress.com/240/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/smallbluegreenblog.wordpress.com/240/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/smallbluegreenblog.wordpress.com/240/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=240&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smallbluegreenblog.wordpress.com/2010/03/20/anti-phishing-working-group-cecos-iv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Lazy 419s &#8211; Another Contender</title>
		<link>http://smallbluegreenblog.wordpress.com/2010/01/30/lazy-419s-another-contender/</link>
		<comments>http://smallbluegreenblog.wordpress.com/2010/01/30/lazy-419s-another-contender/#comments</comments>
		<pubDate>Sat, 30 Jan 2010 14:56:01 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[419]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[email scams]]></category>
		<category><![CDATA[lazy 419s]]></category>

		<guid isPermaLink="false">http://smallbluegreenblog.wordpress.com/?p=231</guid>
		<description><![CDATA[[I think I feel a scam collection coming on: compare a previous blog at http://blogs.securiteam.com/index.php/archives/1331] Thank you very much, Official Notice (also known, apparently, as julie-becker@sbcglobal.net) for letting me know that my email ID has won 1,000,000.00 GBP in the Tobacco Award Promo. As I noticed that you had actually blind copied me, presumably along with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=231&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>[<em>I think I feel a scam collection coming on: compare a previous blog at</em> <a href="http://blogs.securiteam.com/index.php/archives/1331">http://blogs.securiteam.com/index.php/archives/1331</a>]</p>
<p>Thank you very much, Official Notice (also known, apparently, as <a href="mailto:julie-becker@sbcglobal.net">julie-becker@sbcglobal.net</a>) for letting me know that my email ID has won 1,000,000.00 GBP in the Tobacco Award Promo.</p>
<p>As I noticed that you had actually blind copied me, presumably along with hundreds of other lucky winners (I didn&#8217;t realize there was still so much money in nicotine), I thought I&#8217;d respond to your request to send details publicly. That way, if any of those other winners are confused about how to respond, this should make it clear.</p>
<p>&#8220;Name&#8230;Address&#8230;Sex&#8221; </p>
<p>As for your first query, yes, I do have a name, but thank you for asking. I also have an address: several in fact, including the one you mailed me on. Or did you mean my actual terrestrial address? Sure, I have one of those. Would you like me to send it to you, along with my key and my bank details? It&#8217;ll save us both time that way: we can skip the bit where you tell me that I need to pay you some money so that you can release my million pounds, and you can just get on with stealing my identity and the contents of my house and bank account at your convenience.</p>
<p>Sex? Well, from time to time, but not as much as I used to. Why, is that part of the deal? Nothing personal, but I make it a rule never to sleep with scammers.</p>
<p>Thank you for calling. BZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ&#8230;..</p>
<p>David Harley FBCS CITP CISSP<br />
Security Author/Consultant at Small Blue-Green World<br />
Chief Operations Officer, AVIEN<br />
ESET Research Fellow &amp; Director of Malware Intelligence</p>
<p>Also blogging at:<br />
<a href="http://avien.net/blog">http://avien.net/blog</a><br />
<a href="http://www.eset.com/threat-center/blog">http://www.eset.com/threat-center/blog</a><br />
<a href="http://blogs.securiteam.com">http://blogs.securiteam.com</a><br />
<a href="http://blog.isc2.org/">http://blog.isc2.org/</a><br />
<a href="http://dharley.wordpress.com">http://dharley.wordpress.com</a><br />
<a href="http://macvirus.wordpress.com">http://macviruscom.wordpress.com</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smallbluegreenblog.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smallbluegreenblog.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/smallbluegreenblog.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/smallbluegreenblog.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/smallbluegreenblog.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/smallbluegreenblog.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/smallbluegreenblog.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/smallbluegreenblog.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/smallbluegreenblog.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/smallbluegreenblog.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/smallbluegreenblog.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/smallbluegreenblog.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/smallbluegreenblog.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/smallbluegreenblog.wordpress.com/231/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=231&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smallbluegreenblog.wordpress.com/2010/01/30/lazy-419s-another-contender/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Lost in Cyberspace</title>
		<link>http://smallbluegreenblog.wordpress.com/2009/09/19/lost-in-cyberspace/</link>
		<comments>http://smallbluegreenblog.wordpress.com/2009/09/19/lost-in-cyberspace/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 17:39:58 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=127</guid>
		<description><![CDATA[<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=127&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://smallbluegreenblog.files.wordpress.com/2009/09/xkcd1.jpg"><img class="alignleft size-medium wp-image-128" title="xkcd" src="http://smallbluegreenblog.files.wordpress.com/2009/09/xkcd1.jpg?w=300&#038;h=263" alt="xkcd" width="300" height="263" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smallbluegreenblog.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smallbluegreenblog.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/smallbluegreenblog.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/smallbluegreenblog.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/smallbluegreenblog.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/smallbluegreenblog.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/smallbluegreenblog.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/smallbluegreenblog.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/smallbluegreenblog.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/smallbluegreenblog.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/smallbluegreenblog.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/smallbluegreenblog.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/smallbluegreenblog.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/smallbluegreenblog.wordpress.com/127/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=127&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smallbluegreenblog.wordpress.com/2009/09/19/lost-in-cyberspace/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>

		<media:content url="http://smallbluegreenblog.files.wordpress.com/2009/09/xkcd1.jpg?w=300" medium="image">
			<media:title type="html">xkcd</media:title>
		</media:content>
	</item>
		<item>
		<title>Malware Naming, Shape Shifters &amp; Sympathetic Magic</title>
		<link>http://smallbluegreenblog.wordpress.com/2009/09/19/malware-naming-shape-shifters-sympathetic-magic/</link>
		<comments>http://smallbluegreenblog.wordpress.com/2009/09/19/malware-naming-shape-shifters-sympathetic-magic/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 17:28:53 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Conference papers]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Canterbury]]></category>
		<category><![CDATA[CFET 2009]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[Naming of Malware]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=120</guid>
		<description><![CDATA[Back to ESET White Papers This is the paper on malware naming I presented at CFET 2009 in Canterbury: http://www.eset.com/download/whitepapers/cfet2009naming.pdf Abstract Once upon a time, one infection by specific malware looked much like another infection, to an antivirus scanner if not to the naked eye. Even back then, virus naming wasn&#8217;t very consistent between vendors, but [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=120&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.eset.com/documentation/white-papers" target="_blank">Back to ESET White Papers</a></p>
<p>This is the paper on malware naming I presented at CFET 2009 in Canterbury: <a href="http://www.eset.com/download/whitepapers/cfet2009naming.pdf">http://www.eset.com/download/whitepapers/cfet2009naming.pdf</a></p>
<p>Abstract</p>
<p>Once upon a time, one infection by specific malware looked much like another infection, to an antivirus scanner if not to the naked eye. Even back then, virus naming wasn&#8217;t very consistent between vendors, but at least virus encyclopaedias and third-party resources like vgrep made it generally straightforward to map one vendor&#8217;s name for a virus to another vendor&#8217;s name for the same malware.</p>
<p>In 2009, though, the threat landscape looks very different. Viruses and other replicative malware, while far from extinct, pose a comparatively manageable problem compared to other threats with the single common characteristic of malicious intent. Proof-of-Concept code with sophisticated self-replicating mechanisms is of less interest to today&#8217;s malware authors than shape-shifting Trojans that change their appearance frequently to evade detection and are intended to make money for criminals rather than getting adolescent admiration and bragging rights.</p>
<p>Sheer sample glut makes it impossible to categorize and standardize on naming for each and every unique sample out of tens of thousands processed each day.</p>
<p>Detection techniques such as generic signatures, heuristics and sandboxing have also changed the ways in which malware is detected and therefore how it is classified, confounding the old assumptions of a simple one-to-one relationship between a detection label and a malicious program. This presentation will explain how one-to-many, many-to-one, or many-to-many models are at least as likely as the old one-detection-per-variant model, why &#8220;Do you detect Win32/UnpleasantVirus.EG?&#8221; is such a difficult question to answer, and explain why exact indication is not a pre-requisite for detection and remediation of malware, and actually militates against the most effective use of analysis and development time and resources. But what is the information that the end-user or end-site really needs to know about an incoming threat?</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smallbluegreenblog.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smallbluegreenblog.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/smallbluegreenblog.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/smallbluegreenblog.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/smallbluegreenblog.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/smallbluegreenblog.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/smallbluegreenblog.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/smallbluegreenblog.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/smallbluegreenblog.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/smallbluegreenblog.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/smallbluegreenblog.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/smallbluegreenblog.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/smallbluegreenblog.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/smallbluegreenblog.wordpress.com/120/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=120&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smallbluegreenblog.wordpress.com/2009/09/19/malware-naming-shape-shifters-sympathetic-magic/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>A Myth Laid to Rest</title>
		<link>http://smallbluegreenblog.wordpress.com/2009/09/19/a-myth-laid-to-rest/</link>
		<comments>http://smallbluegreenblog.wordpress.com/2009/09/19/a-myth-laid-to-rest/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 16:15:37 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Cartoons]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=113</guid>
		<description><![CDATA[<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=113&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://smallbluegreenblog.files.wordpress.com/2009/09/acme3.jpg"><img class="alignleft size-medium wp-image-112" title="acme3" src="http://smallbluegreenblog.files.wordpress.com/2009/09/acme3.jpg?w=461&#038;h=289" alt="acme3" width="461" height="289" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smallbluegreenblog.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smallbluegreenblog.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/smallbluegreenblog.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/smallbluegreenblog.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/smallbluegreenblog.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/smallbluegreenblog.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/smallbluegreenblog.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/smallbluegreenblog.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/smallbluegreenblog.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/smallbluegreenblog.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/smallbluegreenblog.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/smallbluegreenblog.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/smallbluegreenblog.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/smallbluegreenblog.wordpress.com/113/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smallbluegreenblog.wordpress.com&amp;blog=11168358&amp;post=113&amp;subd=smallbluegreenblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smallbluegreenblog.wordpress.com/2009/09/19/a-myth-laid-to-rest/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>

		<media:content url="http://smallbluegreenblog.files.wordpress.com/2009/09/acme3.jpg?w=300" medium="image">
			<media:title type="html">acme3</media:title>
		</media:content>
	</item>
	</channel>
</rss>
