<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Eng-Tips Whitepaper Library &#187; Security</title>
	<atom:link href="http://eng-tips.nethawk.net/blog/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://eng-tips.nethawk.net/blog</link>
	<description>Whitepaper Library for Engineering Professionals</description>
	<lastBuildDate>Thu, 09 Feb 2012 17:49:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Malvertising on KickAssTorrents (kat.ph), OpenX compromised to serve fake anti-virus &#8220;Security Sphere 2012&#8243;</title>
		<link>http://eng-tips.nethawk.net/blog/malvertising-on-kickasstorrents-kat-ph-openx-compromised-to-serve-fake-anti-virus-security-sphere-2012</link>
		<comments>http://eng-tips.nethawk.net/blog/malvertising-on-kickasstorrents-kat-ph-openx-compromised-to-serve-fake-anti-virus-security-sphere-2012#comments</comments>
		<pubDate>Sun, 16 Oct 2011 21:22:36 +0000</pubDate>
		<dc:creator>Wayne Huang</dc:creator>
				<category><![CDATA[Editorial]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://eng-tips.nethawk.net/blog/?p=2534</guid>
		<description><![CDATA[(Credits: Wayne Huang, Chris Hsiao, NightCola Lin) Yesterday our HackAlert website malware monitoring service told us that KickAssTorrents (kat.ph), ranked 321 globally on Alexa with more than 1.5 million unique visitors per month, is serving malware to all of its visitors via malvertising. Below is a video showing how visitors are infected: Coincidentally, KickAss Torrents [...]


Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/security-in-the-golden-age-of-the-internet' rel='bookmark' title='Permanent Link: Security In the Golden Age Of The Internet'>Security In the Golden Age Of The Internet</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/p2463' rel='bookmark' title='Permanent Link: Is Apple&#8217;s Pre-emptive Censor Anti Customer?'>Is Apple&#8217;s Pre-emptive Censor Anti Customer?</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/what-is-the-deal-with-security-in-smart-grid' rel='bookmark' title='Permanent Link: What is the Deal with Security in Smart Grid?'>What is the Deal with Security in Smart Grid?</a></ol>]]></description>
			<content:encoded><![CDATA[<p>(Credits: Wayne Huang, Chris Hsiao, NightCola Lin)</p>
<p><img class="alignnone size-full wp-image-3425" title="malvertising on kickasstorrents spreading security sphere 2012 fake antivirus via hacked openx 3" src="http://tek-tips.nethawk.net/blog/wp-content/uploads/2011/10/malvertising-on-kickasstorrents-spreading-security-sphere-2012-fake-antivirus-via-hacked-openx-3.png" alt="" width="550" /></p>
<p>Yesterday our <a href="http://armorize.com/?link_id=hackalert">HackAlert website malware monitoring service</a> told us that KickAssTorrents (kat.ph), ranked <a href="http://www.alexa.com/siteinfo/kat.ph">321 globally on Alexa</a> with more than <a href="http://siteanalytics.compete.com/kat.ph/">1.5 million unique visitors per month</a>, is serving malware to all of its visitors via malvertising. Below is a video showing how visitors are infected:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="600" height="335" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/iMKKbwWIcYk?version=3&amp;hl=en_US&amp;rel=0" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="600" height="335" src="http://www.youtube.com/v/iMKKbwWIcYk?version=3&amp;hl=en_US&amp;rel=0" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>Coincidentally, KickAss Torrents published a <a href="http://www.kat.ph/blog/post/1022/">blog post</a> on Oct 10th in response to the website being flagged by antivirus vendor Avast. In it they said:<br />
===================<br />
Our users that are using the Avast anti-virus might have noticed that KAT.ph suddenly became labeled as a dangerous website for users that are not logged in. We want to assure our users that KickassTorrents has no malware or viruses of any kind and it is absolutely safe to use our website. We already contacted Avast and currently we are trying to find and fix the cause of this problem. You will help us if you choose the &#8220;Report the file as a false positive&#8221; option if you get the alert.<br />
===================</p>
<p>In <a href="http://www.kat.ph/community/show/21785/">another thread</a>, KickAss Torrents said:</p>
<p>===================<br />
Now what the hell does this error mean?<br />
First of all, don&#8217;t flip out, don&#8217;t go post on the KAT site, post down here if you experience the same problem.<br />
Secondly, report down here if you experience this error.<br />
Thirdly, add kat.ph to the safe URLs in your AV.<br />
And lastly, please go to this site and report the problem (Avast! users only):<br />
Avast! forum thread<br />
Back on topic. What is this error? Does error roughly means that your anti-virus software has found some bad code in an iFrame. This could be from the site itself, or from advertisements. An iFrame is a piece of code that allows you to do several things. Embedding something to your site is a good example.<br />
I hope this topic helps a little and I certainly hope the error is going to be fixed now.<br />
Q&amp;A:<br />
Q: OMFG IS KAT HACKED?<br />
A: Nope, just some error.<br />
Q: Is it really safe to visit KAT?<br />
A: Yes, it is.<br />
===================</p>
<p>KickAss Torrents also referred to this discussion thread on Avast&#8217;s forum. At the end of the forum it appears that Avast has acknowledged that it was indeed a false positive and have addressed the issue:</p>
<p>===================<br />
Hello,</p>
<p>It should be solved, if not let us know please.</p>
<p>Miroslav Jenšík<br />
AVAST Software a.s.<br />
===================</p>
<p>Well, that time it might have been a false positive from Avast, but this time the website is absolutely infecting its visitors, as seen in our video.</p>
<p>[Summary]</p>
<p>Here we summarize characteristics worth noting:</p>
<p>1. High traffic website compromised.<br />
2. Malvertising via compromising KickAssTorrents&#8217; OpenX platform.<br />
3. Spreading fake antivirus &#8220;Security Sphere 2012&#8243; by conducting a drive-by download process. Simply navigating to the website with an outdated browsing platform will result in infection. No clicks necessary (see video).<br />
4. Same attackers responsible for the recent <a href="http://blog.armorize.com/2011/10/malvertising-lifecycle-case-study-openx.html">speedtest.net incident</a>.<br />
5. Using DynDNS domains for their exploit server.<br />
6. Domain names are auto-calculated using Javascript. The algorithm used generates a (predicable) different dyndns.tv domain name every hour, in the format of roboABCD.tv, where ABCD are characters with a fixed seed and incremented by one character every different UTC hour.<br />
7. The new dyndns domain for the next hour is generated every hour precisely at minutes 2 to 5, so this may be done by an automated mechanism.<br />
8. Initial antivirus detection rates are very low, from 0 to 2 vendors out of 43 on VirusTotal.<br />
9. All generated domains resolve to a single IP: 184.22.224.154 (AS21788, United States Scranton Network Operations Center Inc), located in the US.<br />
10. The domain: obama-president.com resolves to this IP and is serving the same exploit pack. This domain was registered on Aug 4th through an Russian registrar, 1&#8242;ST DOMAIN NAME SERVICE www.1dns.ru. At this time the domain resolved to an Netherlands IP 85.17.93.9. The domain started to resolve to 184.22.224.154 on Aug 23rd. This IP and the president-obama.com domain are both currently still up and working.</p>
<p>[Details]</p>
<p>KickAssTorrents serves its ads via its OpenX installation at ad.kat.ph. This platform has been compromised and made to serve browser exploits. In our video, this URL:</p>
<p>http://ad.kat.ph/delivery/ajs.php?zoneid=4&amp;target=_blank&amp;charset=UTF-8&amp;cb=95920847237&amp;charset=UTF-8&amp;loc=http%3A//www.kat.ph/§ion=1939940</p>
<p>was injected with malicious javascript. In the following code snippet, the highlighted sections are the injected part. Note the code isn&#8217;t just a few lines of &#8220;injection&#8221;&#8211;the code is merged with the original OpenX html code:</p>
<p><img class="alignnone size-full wp-image-3426" title="malvertising on kickasstorrents spreading security sphere 2012 fake antivirus via hacked openx 2" src="http://tek-tips.nethawk.net/blog/wp-content/uploads/2011/10/malvertising-on-kickasstorrents-spreading-security-sphere-2012-fake-antivirus-via-hacked-openx-2.png" alt="" width="600" /></p>
<p>The following is the important parts of the decoded version:</p>
<p><img class="alignnone size-full wp-image-3427" title="malvertising on kickasstorrents spreading security sphere 2012 fake antivirus via hacked openx 4" src="http://tek-tips.nethawk.net/blog/wp-content/uploads/2011/10/malvertising-on-kickasstorrents-spreading-security-sphere-2012-fake-antivirus-via-hacked-openx-4.png" alt="" width="550" /></p>
<p>From line 29-41, we can see that the function spelled() generates four characters based on the current hour in UTC. From line 18 we can see how this function is called: var gyrally = spelled(String(&#8220;robo&#8221;), new String(&#8220;.dynd&#8221; + &#8220;ns.tvmg7j&#8221;.substr(0, 5)));</p>
<p>Antivirus detection of the dropped and installed malicious binary was <a href="2 out of 42 vendors on VirusTotal">2 out of 42 vendors on VirusTotal</a>.</p>
<p><img class="alignnone size-full wp-image-3428" title="malvertising on kickasstorrents spreading security sphere 2012 fake antivirus via hacked openx 5" src="http://tek-tips.nethawk.net/blog/wp-content/uploads/2011/10/malvertising-on-kickasstorrents-spreading-security-sphere-2012-fake-antivirus-via-hacked-openx-5.png" alt="" width="550" /></p>
<p>And finally, here&#8217;s a screenshot of the installed fake antivirus Security Sphere 2012:</p>
<p><img class="alignnone size-full wp-image-3429" title="malvertising on kickasstorrents spreading security sphere 2012 fake antivirus via hacked openx 6" src="http://tek-tips.nethawk.net/blog/wp-content/uploads/2011/10/malvertising-on-kickasstorrents-spreading-security-sphere-2012-fake-antivirus-via-hacked-openx-6.png" alt="" width="550" /></p>


<p>Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/security-in-the-golden-age-of-the-internet' rel='bookmark' title='Permanent Link: Security In the Golden Age Of The Internet'>Security In the Golden Age Of The Internet</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/p2463' rel='bookmark' title='Permanent Link: Is Apple&#8217;s Pre-emptive Censor Anti Customer?'>Is Apple&#8217;s Pre-emptive Censor Anti Customer?</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/what-is-the-deal-with-security-in-smart-grid' rel='bookmark' title='Permanent Link: What is the Deal with Security in Smart Grid?'>What is the Deal with Security in Smart Grid?</a></ol></p>]]></content:encoded>
			<wfw:commentRss>http://eng-tips.nethawk.net/blog/malvertising-on-kickasstorrents-kat-ph-openx-compromised-to-serve-fake-anti-virus-security-sphere-2012/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security In the Golden Age Of The Internet</title>
		<link>http://eng-tips.nethawk.net/blog/security-in-the-golden-age-of-the-internet</link>
		<comments>http://eng-tips.nethawk.net/blog/security-in-the-golden-age-of-the-internet#comments</comments>
		<pubDate>Mon, 15 Aug 2011 21:33:48 +0000</pubDate>
		<dc:creator>Eng-Tips</dc:creator>
				<category><![CDATA[Editorial]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://eng-tips.nethawk.net/blog/?p=2479</guid>
		<description><![CDATA[The political spectrum, we learned in civics lessons in high school, is actually a cyclical format that renders the furthest of the right, most closely to the furthest of the left. In 2011 that may be a bit hard to sustain in an argument, but the principal of belief systems cycling is rather empirical. Today [...]


Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/obama-administration-and-political-internet-decisions' rel='bookmark' title='Permanent Link: Obama Administration And Political Internet Decisions'>Obama Administration And Political Internet Decisions</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/malvertising-on-kickasstorrents-kat-ph-openx-compromised-to-serve-fake-anti-virus-security-sphere-2012' rel='bookmark' title='Permanent Link: Malvertising on KickAssTorrents (kat.ph), OpenX compromised to serve fake anti-virus &#8220;Security Sphere 2012&#8243;'>Malvertising on KickAssTorrents (kat.ph), OpenX compromised to serve fake anti-virus &#8220;Security Sphere 2012&#8243;</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/2011-q1-internet-world-statistics' rel='bookmark' title='Permanent Link: 2011 Q1 Internet World Statistics'>2011 Q1 Internet World Statistics</a></ol>]]></description>
			<content:encoded><![CDATA[<p>The political spectrum, we learned in civics lessons in high school, is actually a cyclical format that renders the furthest of the right, most closely to the furthest of the left. In 2011 that may be a bit hard to sustain in an argument, but the principal of belief systems cycling is rather empirical. Today we see the Rupert Murdoch media kingdom labeled far right and it seems the target of the radical far left, in this case let&#8217;s look at the hacking community. So when reports of the demise of Lulzec, like that of Mark Twain, seemed a bit premature, or at least exaggerated, it appears these anonymous folks are still plugging away at those who hold the power and certainly the wealth. Not exactly coming together considering civics class.</p>
<p><a href="http://nethawk.net/wp-content/uploads/2011/07/lulzecimage2.jpg"><img class="aligncenter size-full wp-image-640" title="lulzecimage2" src="http://nethawk.net/wp-content/uploads/2011/07/lulzecimage2.jpg" alt="" width="259" height="194" /></a></p>
<p>In the midst of the Fox scandal, Lulzec issued a statement saying they &#8220;have 4GB of emails taken from an alleged hack on servers at the Sun, but won&#8217;t make them public for fear of jeopardizing ongoing legal actions.&#8221; Either that, or they are still licking their wounds for messing with the man and don&#8217;t see any percentage in taking on Murdoch who may be worse.</p>
<table>
<tbody>
<tr>
<th rowspan="3" width="35"></th>
<td colspan="2">
<hr /></td>
<td rowspan="3" width="35"></td>
</tr>
<tr>
<td><img src="http://eng-tips.nethawk.net/logos/1252082532_APC_96x46.jpg" alt="" /></td>
<td><strong><a href="http://eng-tips.nethawk.net/registration_dynamic.php?id=63"><span style="font-family: Times New Roman;">Monitoring Physical Threats in the Data Center</span></a></strong></td>
</tr>
<tr>
<td colspan="2">
<hr /></td>
</tr>
</tbody>
</table>
<p>While Murdoch&#8217;s boys are busy scuttling the would be evidence against them by attempting to dismiss email entirely from the court room, the boys and girls of the anonymous hack job are threatening to selectively provide the content of some of these to chosen media outlets. The British government, which stands a lot to lose from the alleged Murdoch thievery, and hack job on prominent cell phones, is trying to sort the mess out.</p>
<p>The most interesting piece of technology video on the topic of Internet security recently comes from a video by <a href="http://mikko.hypponen.com/" target="_blank">Mikko H. Hypponen</a>, Chief Research Officer at F-Secure.  We&#8217;d love to get Mikko to do a video interview on our site so let us know if you like the idea.</p>
<p>http://www.ted.com/talks/mikko_hypponen_fighting_viruses_defending_the_net.html</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="526" height="374" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="wmode" value="transparent" /><param name="bgColor" value="#ffffff" /><param name="flashvars" value="vu=http://video.ted.com/talk/stream/2011G/Blank/MikkoHypponen_2011G-320k.mp4&amp;su=http://images.ted.com/images/ted/tedindex/embed-posters/MikkoHypponen-2011G.embed_thumbnail.jpg&amp;vw=512&amp;vh=288&amp;ap=0&amp;ti=1192&amp;lang=&amp;introDuration=15330&amp;adDuration=4000&amp;postAdDuration=830&amp;adKeys=talk=mikko_hypponen_fighting_viruses_defending_the_net;year=2011;theme=a_taste_of_tedglobal_2011;theme=new_on_ted_com;theme=what_s_next_in_tech;theme=bold_predictions_stern_warnings;event=TEDGlobal+2011;tag=Global+Issues;tag=Technology;tag=computers;tag=crime;tag=internet;tag=virus;&amp;preAdTag=tconf.ted/embed;tile=1;sz=512x288;" /><param name="src" value="http://video.ted.com/assets/player/swf/EmbedPlayer.swf" /><param name="pluginspace" value="http://www.macromedia.com/go/getflashplayer" /><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="bgcolor" value="#ffffff" /><embed type="application/x-shockwave-flash" width="526" height="374" src="http://video.ted.com/assets/player/swf/EmbedPlayer.swf" pluginspace="http://www.macromedia.com/go/getflashplayer" flashvars="vu=http://video.ted.com/talk/stream/2011G/Blank/MikkoHypponen_2011G-320k.mp4&amp;su=http://images.ted.com/images/ted/tedindex/embed-posters/MikkoHypponen-2011G.embed_thumbnail.jpg&amp;vw=512&amp;vh=288&amp;ap=0&amp;ti=1192&amp;lang=&amp;introDuration=15330&amp;adDuration=4000&amp;postAdDuration=830&amp;adKeys=talk=mikko_hypponen_fighting_viruses_defending_the_net;year=2011;theme=a_taste_of_tedglobal_2011;theme=new_on_ted_com;theme=what_s_next_in_tech;theme=bold_predictions_stern_warnings;event=TEDGlobal+2011;tag=Global+Issues;tag=Technology;tag=computers;tag=crime;tag=internet;tag=virus;&amp;preAdTag=tconf.ted/embed;tile=1;sz=512x288;" bgcolor="#ffffff" wmode="transparent" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>


<p>Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/obama-administration-and-political-internet-decisions' rel='bookmark' title='Permanent Link: Obama Administration And Political Internet Decisions'>Obama Administration And Political Internet Decisions</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/malvertising-on-kickasstorrents-kat-ph-openx-compromised-to-serve-fake-anti-virus-security-sphere-2012' rel='bookmark' title='Permanent Link: Malvertising on KickAssTorrents (kat.ph), OpenX compromised to serve fake anti-virus &#8220;Security Sphere 2012&#8243;'>Malvertising on KickAssTorrents (kat.ph), OpenX compromised to serve fake anti-virus &#8220;Security Sphere 2012&#8243;</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/2011-q1-internet-world-statistics' rel='bookmark' title='Permanent Link: 2011 Q1 Internet World Statistics'>2011 Q1 Internet World Statistics</a></ol></p>]]></content:encoded>
			<wfw:commentRss>http://eng-tips.nethawk.net/blog/security-in-the-golden-age-of-the-internet/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Checklist For The Cloud</title>
		<link>http://eng-tips.nethawk.net/blog/checklist-for-the-cloud</link>
		<comments>http://eng-tips.nethawk.net/blog/checklist-for-the-cloud#comments</comments>
		<pubDate>Tue, 14 Jun 2011 23:54:51 +0000</pubDate>
		<dc:creator>Eng-Tips</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Editorial]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://eng-tips.nethawk.net/blog/?p=2462</guid>
		<description><![CDATA[We re-posted the story on the definition of the &#8220;cloud&#8221; so we could take a deeper look at where it has come in the last two years and how it has changed. Our parent company, NetHawk Interactive, Inc., has used the cloud for its CRM files and we park our mail servers at our IT [...]


Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/cloud-contains-a-storm-but-not-a-shower' rel='bookmark' title='Permanent Link: Cloud Contains a Storm but not a Shower'>Cloud Contains a Storm but not a Shower</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/an-indispensable-element-to-cloud-computing' rel='bookmark' title='Permanent Link: An Indispensable Element to Cloud Computing'>An Indispensable Element to Cloud Computing</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/is-cloud-just-another-word-for-proprietary' rel='bookmark' title='Permanent Link: Is &#8220;Cloud&#8221; Just A Euphemism For Proprietary?'>Is &#8220;Cloud&#8221; Just A Euphemism For Proprietary?</a></ol>]]></description>
			<content:encoded><![CDATA[<p>We re-posted the story on <a href="http://tek-blogs.com/a/rt9bx">the definition of the &#8220;cloud&#8221;</a> so we could take a deeper look at where it has come in the last two years and how it has changed.  Our parent company, <a href="http://www.nethawk.net">NetHawk Interactive, Inc.</a>, has used the cloud for its CRM files and we park our mail servers at our IT provider&#8217;s location so they can watch it. If Google had gotten their act together, and provided a suitable Office suite along with a domain nest, we may have dumped our too long relationship with Microsoft.  No joke.  Our reasoning back in the late nineties was that as a marketing company, maintaining an in-house IT staff was essential, if we wanted to build a network that would scale.  In those days, we still weren&#8217;t sure which way the wind would blow and we thought we were buying innovation in the process.  That proved to be nonsense, as our IT staff became entrenched and we were not able to separate the innovations and their expenses from the status quo.  We soon quit trying to build a formidable online automated service and got back to what we know best:  finding sales leads for IT companies.</p>
<p><img class="alignnone size-medium wp-image-3248" title="lenticular-clouds" src="http://tek-tips.nethawk.net/blog/wp-content/uploads/2011/06/lenticular-clouds-300x221.jpg" alt="" width="300" height="221" /></p>
<p>So while the mid-nineties represented a time when owning racks of servers was some sort of status symbol, today all that iron is an albatross around the necks of many small and medium-sized companies.  The cloud as it is now framed  is not new or different.  The only real difference is the security situation and the techniques used to manage the wide area network we call home.  With our team scattered around the world, that demands enough of our bandwidth.</p>
<p>So now the decisions for companies to make are inundated with fear and loathing on the way to the cloud and its accoutrements.  As Dr. Alastair MacWillson, the global managing director of <a href="http://www.securityweek.com/cloud-security-no-time-stay-sidelines ">Accenture’s global security practice, puts it</a>, &#8220;It’s certainly justified for an organization to worry about theft, loss or legal noncompliance.&#8221;</p>
<p>The good doctor lists Five (5) major points for us to address when assessing the situation:</p>
<p>1. Know your appetite for privacy and security risk.</p>
<p>2. Expect to share responsibility.</p>
<p>3. Demand transparency and accountability from cloud providers.</p>
<p>4. Use the cloud to address identity and access management issues.</p>
<p>5. Architect solutions that address the risk.</p>
<p>The first point is dynamic and changing as fast as the markets, and, as MacWillson points out, much faster than legislation on things like privacy and compliance.  For us it was simple, since the IT provider that now manages our data and our iron is the same as we used when we had all our racks on premise.  He also mentions Common Assurance Maturity Model (CAMM) and the introductory video below explains how you might use these services to help ascertain you are covering your data correctly.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="390" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/QzY4fd1j78s?version=3&amp;hl=en_US&amp;rel=0" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="390" src="http://www.youtube.com/v/QzY4fd1j78s?version=3&amp;hl=en_US&amp;rel=0" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>Secondly, he reminds us that we will have to share responsibilities, not really new but a bit different, than managing in premises servers.</p>
<table>
<tbody>
<tr>
<th rowspan="3" width="35"></th>
<td colspan="2">
<hr /></td>
<td rowspan="3" width="35"></td>
</tr>
<tr>
<td><img src="http://eng-tips.nethawk.net/logos/1252082532_APC_96x46.jpg" alt="" /></td>
<td><a href="http://eng-tips.nethawk.net/registration_dynamic.php?id=83"><span style="font-family: Times New Roman;">Allocating data center energy costs and carbon to IT users</span></a></td>
</tr>
<tr>
<td colspan="2">
<hr /></td>
</tr>
</tbody>
</table>
<p>&#8220;It is critical to clarify the roles of the data owner and cloud provider (and systems integrator, if applicable) in delivering legally compliant solutions. While the law doesn’t state any clear division of labor as long as certain things get done, many data owners and cloud providers have misconceptions about their responsibilities.&#8221;</p>
<p>In his third point, he provides a template for how to negotiate your requirements and I strongly urge those considering moving their data to a third party to meticulously follow these points.  Questioning cloud providers requires a variety of checklists and an open framework with which to insure your risks are managed correctly.  If you are not comfortable, there are many consultants versed in these situations and you should consider having someone experienced make sure you are covered.</p>
<p>Number four is about identity issues which you must look carefully at before you make any decisions.  In a recent <a href="http://tek-tips.nethawk.net/blog/%E2%80%9Cadvanced-persistent-threat%E2%80%9D-questions-rsa-securid">post</a>, we discussed the intrusions and options.  Review that post for a more fluid approach to assessing your options.  There are some, like phone id&#8217;s but those have other challenges.  If the secure ID&#8217;s are replaced, this may drive it.  Stay tuned on that one.</p>
<p>Number five is a bit of mystery to this writer because I am really not sure how any of the architected choices are any different.  If Google is as vulnerable to the threats that they seem to be, if Amazon hasn&#8217;t got all of this wired, than I would say smaller vendors, like Lan Logic, which we use, are on an equal par.  Check it out and let us know what you learn, what questions you are not able to find answers to and what advice you would like to share with others going through the same pain staking analysis.</p>


<p>Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/cloud-contains-a-storm-but-not-a-shower' rel='bookmark' title='Permanent Link: Cloud Contains a Storm but not a Shower'>Cloud Contains a Storm but not a Shower</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/an-indispensable-element-to-cloud-computing' rel='bookmark' title='Permanent Link: An Indispensable Element to Cloud Computing'>An Indispensable Element to Cloud Computing</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/is-cloud-just-another-word-for-proprietary' rel='bookmark' title='Permanent Link: Is &#8220;Cloud&#8221; Just A Euphemism For Proprietary?'>Is &#8220;Cloud&#8221; Just A Euphemism For Proprietary?</a></ol></p>]]></content:encoded>
			<wfw:commentRss>http://eng-tips.nethawk.net/blog/checklist-for-the-cloud/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Advanced Persistent Threat&#8221; Questions RSA SecurID</title>
		<link>http://eng-tips.nethawk.net/blog/advanced-persistent-threat-questions-rsa-securid</link>
		<comments>http://eng-tips.nethawk.net/blog/advanced-persistent-threat-questions-rsa-securid#comments</comments>
		<pubDate>Wed, 01 Jun 2011 17:37:39 +0000</pubDate>
		<dc:creator>Eng-Tips</dc:creator>
				<category><![CDATA[Community Manager]]></category>
		<category><![CDATA[Editorial]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://eng-tips.nethawk.net/blog/?p=2456</guid>
		<description><![CDATA[Lockheed Martin, the world&#8217;s largest defense company, first detected an intruder trying to break into its network on May 22. Intruders apparently created duplicates of &#8220;SecurID&#8221; electronic keys, used to log into networks, from EMC&#8217;s RSA security division. &#8220;Our systems remain secure; no customer, program or employee personal data has been compromised,&#8221; Company spokeswoman Jennifer [...]


Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/rsa-media-alert-lifestyle-hackers-the-latest-insider-threat' rel='bookmark' title='Permanent Link: RSA Media Alert: Lifestyle Hackers, the Latest Insider Threat'>RSA Media Alert: Lifestyle Hackers, the Latest Insider Threat</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/rsa-conference-coverage-april-20-24-2009' rel='bookmark' title='Permanent Link: RSA Conference Coverage April 20-24 2009'>RSA Conference Coverage April 20-24 2009</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/rsa-conference-coverage-april-20-24-2009-2' rel='bookmark' title='Permanent Link: RSA Conference Coverage  April 20-24 2009'>RSA Conference Coverage  April 20-24 2009</a></ol>]]></description>
			<content:encoded><![CDATA[<p>Lockheed Martin, the world&#8217;s largest defense company, first detected an intruder trying to break into its network on May 22.  Intruders apparently created duplicates of &#8220;SecurID&#8221; electronic keys, used to log into networks, from EMC&#8217;s RSA security division.</p>
<p><img class="alignnone size-full wp-image-3225" title="RSA_SecurID" src="http://tek-tips.nethawk.net/blog/wp-content/uploads/2011/06/RSA_SecurID.jpg" alt="" width="275" height="130" /></p>
<p>&#8220;Our systems remain secure; no customer, program or employee personal data has been compromised,&#8221; Company spokeswoman Jennifer Whitlow of the Bethesda, MD.-based company<a href="http://www.rsa.com/node.aspx?id=3872"> said</a>. White House spokesman Jay Carney said, &#8220;Based on what I&#8217;ve seen, they feel it’s fairly minimal in terms of the damage.&#8221;</p>
<p>Back in March,  Art Coviello, Executive Chairman of RSA, an EMC Company, said in statement, “the attack is in the category of an Advanced Persistent Threat (APT). Our investigation also revealed that the attack resulted in certain information being extracted from RSA&#8217;s systems. Some of that information is specifically related to RSA&#8217;s SecurID two-factor authentication products.&#8221;  He went on to say, &#8220;While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers, this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack.&#8221;</p>
<table>
<tr>
<th width="35" rowspan="3">&nbsp;</th>
<td colspan="2">- &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - -</td>
<td width="35" rowspan="3">&nbsp;</td>
</tr>
<tr>
<td><img src="http://eng-tips.nethawk.net/logos/1252082532_APC_96x46.jpg"></td>
<td><a href="http://eng-tips.nethawk.net/registration_dynamic.php?id=80"><span style="font-family: Times New Roman;">Classification of Data Center Operations Technology (OT) Management Tools</span></a></td>
</tr>
<tr>
<td colspan="2">- &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - -</td>
</tr>
</table>
<p>Advanced Persistent Threat (APT) is a big deal, usually associated with a nation/state organization level.  If cyber-security threats are on the rise, we want to trace them and the systems being threatened.    EMC is reporting that remediation has been provided in the form of replacing the SecurID tokens.   These memory stick- like units that generate random numbers used in combination with a personal identification number, to gain entry, may have lost the confidence battle:  If intruders get the key, the seed that enables one-time passwords to be generated, then they may have the capability to break into networks that depend on such systems to authenticate users.</p>
<p>In the world of APT&#8217;s, confidence tends to be a bigger threat to product life cycles.  If Lockheed throws out the bay with the bath water, and RSA too, this may lead to a new way to manage identities. For the nation&#8217;s defense contractors, this may already be happening.</p>


<p>Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/rsa-media-alert-lifestyle-hackers-the-latest-insider-threat' rel='bookmark' title='Permanent Link: RSA Media Alert: Lifestyle Hackers, the Latest Insider Threat'>RSA Media Alert: Lifestyle Hackers, the Latest Insider Threat</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/rsa-conference-coverage-april-20-24-2009' rel='bookmark' title='Permanent Link: RSA Conference Coverage April 20-24 2009'>RSA Conference Coverage April 20-24 2009</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/rsa-conference-coverage-april-20-24-2009-2' rel='bookmark' title='Permanent Link: RSA Conference Coverage  April 20-24 2009'>RSA Conference Coverage  April 20-24 2009</a></ol></p>]]></content:encoded>
			<wfw:commentRss>http://eng-tips.nethawk.net/blog/advanced-persistent-threat-questions-rsa-securid/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Power as One of the Criteria for Selecting a Data Center Site</title>
		<link>http://eng-tips.nethawk.net/blog/power-as-one-of-the-criteria-for-selecting-a-data-center-site</link>
		<comments>http://eng-tips.nethawk.net/blog/power-as-one-of-the-criteria-for-selecting-a-data-center-site#comments</comments>
		<pubDate>Wed, 30 Mar 2011 20:55:37 +0000</pubDate>
		<dc:creator>Zen Kishimoto</dc:creator>
				<category><![CDATA[Data Center]]></category>
		<category><![CDATA[Editorial]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://eng-tips.nethawk.net/blog/?p=2421</guid>
		<description><![CDATA[In the recent Critical Facilities Roundtable, Steve Rosa, principal of Unique Infrastructure Group, gave a very interesting presentation on power availability and cost as a criterion for selecting a site for a new data center. There are many criteria for selecting such a site (see here). Probably, available and reasonably priced power is the most [...]


Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/an-example-of-data-center-site-selection-reno-technology-park' rel='bookmark' title='Permanent Link: An Example of Data Center Site Selection: Reno Technology Park'>An Example of Data Center Site Selection: Reno Technology Park</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/direct-current-power-distribution-in-a-data-center' rel='bookmark' title='Permanent Link: Direct Current Power Distribution in a Data Center'>Direct Current Power Distribution in a Data Center</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/sentilla-measuring-power-consumption-at-a-data-center' rel='bookmark' title='Permanent Link: Sentilla: Measuring Power Consumption At A Data Center'>Sentilla: Measuring Power Consumption At A Data Center</a></ol>]]></description>
			<content:encoded><![CDATA[<p>In the recent Critical Facilities Roundtable, Steve Rosa, principal of <a href="http://www.uniqueig.com/" target="_blank">Unique Infrastructure Group</a>, gave a very interesting presentation on power availability and cost as a criterion for selecting a site for a new data center. There are many criteria for selecting such a site (see <a href="http://altaterra.site-ym.com/members/blog_view.asp?id=288668&amp;post=45403" target="_blank">here</a>).</p>
<p>Probably, available and reasonably priced power is the most important factor, and access to the fiber network is the second.</p>
<p><img src="http://altaterra.site-ym.com/resource/resmgr/steve-rosa-0.jpg" alt="" /></p>
<p>Steve Rosa</p>
<p>When I started looking into the power issue, I looked at my power and gas bill for the first time. I was amazed that it included several charges beyond the charge for actual use. A residential bill is not the same as a data center bill. The following slide from Steve shows what is involved in the power bill.</p>
<p><img src="http://altaterra.site-ym.com/resource/resmgr/steve-rosa-1.jpg" alt="" /></p>
<p>Power charge consists of demand charge, power surcharge, service charge, and sales tax.</p>
<p>(courtesy of Unique Infrastructure Group)</p>
<p>Steve continued by discussing what needs to be considered: utility portfolio, rate increases, NERC CIP-compliance, regulatory, future capacity, PUE, and today’s bill. He covered each of these elements:</p>
<p>Utility portfolio: This is the source of power generation and needs to be considered because some sources, such as coal, may be regulated more than others. Some utilities are heavy users of crude oil, while others use little oil for power generation. The price of oil is very volatile and must be considered in your site selection.</p>
<table>
<tr>
<th width="35" rowspan="3">&nbsp;</th>
<td colspan="2">- &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - -</td>
<td width="35" rowspan="3">&nbsp;</td>
</tr>
<tr>
<td><img src="http://eng-tips.nethawk.net/logos/1252082532_APC_96x46.jpg"></td>
<td><a href="http://eng-tips.nethawk.net/registration_dynamic.php?id=81"><span style="font-family: Times New Roman;">Virtualization: Optimized Power and Cooling to Maximize Benefits</span></a></td>
</tr>
<tr>
<td colspan="2">- &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - -</td>
</tr>
</table>
<p>Rate increases: It is likely that the cost of power will increase over time, and that increase may depend on the site you select. The president of Rocky Mountain Power predicted that power cost would double in the next 10 years.</p>
<p>Future capacity: This is important because you need to have reliable delivery of power even when your demand for power increases in the future. For example, you cannot get even 1 kW for your new needs in Manhattan.</p>
<p><img src="http://altaterra.site-ym.com/resource/resmgr/steve-rosa-2.jpg" alt="" /></p>
<p>Factors to consider beyond today&#8217;s bill: utility portfolio, rate increases, NERC CIP-compliance, regulations, future capacity, PUE.</p>
<p>(courtesy of Unique Infrastructure Group)</p>
<p>Steve also talked about the EPA&#8217;s Maximum Achievable Control Technology (MACT) Standards, which is a court-sanctioned mandate that will take effect later this year. MACT is concerned with the emissions from coal-fired power plants. MACT is one type of <a href="http://www.epa.gov/oecaerth/monitoring/programs/caa/neshaps.html" target="_blank">National Emission Standards for Hazardous Air Pollutants (NESHAP</a>). See for<a href="http://www.epa.gov/oecaerth/monitoring/programs/caa/neshaps.html" target="_blank"> NESHAP</a> and for <a href="http://dnr.wi.gov/air/toxics/MACT/index.htm" target="_blank">MACT</a>.</p>
<p><a href="http://www.bernsteinresearch.com/BRWEB/Public/Login.aspx?ReturnUrl=%2fbrweb%2fHome.aspx" target="_blank">Bernstein Research&#8217;s </a>comprehensive analysis of the impact of the new standards on coal-fired power plants concluded that 9% of them will need to be shut down. The following is <a href="http://grist.s3.amazonaws.com/eparegs/Bernstein%20-%20black%20days%20ahead%20for%20coal%20-%2007%2021%2010.pdf" target="_blank">a short summary of Bernstein’s report</a>.</p>
<p>If your utility is a heavy user of coal for power generation and its coal-fired power plants are to be shut down for noncompliance with MACT standards, you will not get enough power for your data centers. Your utility will lose a lot of its power generation capacity, increasing the power cost for sure. One such example Steve mentioned is a utility that might lose 43% of power generation capacity. In general, coal-fired power plants are concentrated in the mid-Atlantic region, where coal is abundant and cheap. Many power plants in that region are small, old, and less efficient. Steve predicts that the owners of such plants will not renew but abandon them.</p>
<p>He also covered security requirements (<a href="http://www.garrettcom.com/nerc_cip_opportunity.htm" target="_blank">NERC CIP-compliance</a>)for utilities’ facilities in view of malware, such as <a href="http://en.wikipedia.org/wiki/Stuxnet">Stuxnet </a>(attacks SCADA systems) and cyber attacks. NERC CIP-compliance is for the security of power generation and the power transmission infrastructure. The auditors are getting serious about enforcing it, and if a utility does not comply, it will be fined $1M a day, which will be passed onto consumers. To date, not a single utility satisfies this requirement. Steve&#8217;s suggestion is to get off the power grid and rely on your own facilities for power. The military is working to get its critical infrastructures off the grid now.</p>
<p>When I talk to people responsible for managing energy for a large corporate campus, they tell me their number one reason not to consider having their own power microgrid is the cost of implementing and maintaining it. But as power cost increases and the supply gets smaller, the move to microgrid may become a reasonable choice. Steve’s talk was geared towards data center operators in their site selection. But those who already have data centers and a campus to manage their energy should also take his warning seriously and consider their future energy demands.</p>


<p>Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/an-example-of-data-center-site-selection-reno-technology-park' rel='bookmark' title='Permanent Link: An Example of Data Center Site Selection: Reno Technology Park'>An Example of Data Center Site Selection: Reno Technology Park</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/direct-current-power-distribution-in-a-data-center' rel='bookmark' title='Permanent Link: Direct Current Power Distribution in a Data Center'>Direct Current Power Distribution in a Data Center</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/sentilla-measuring-power-consumption-at-a-data-center' rel='bookmark' title='Permanent Link: Sentilla: Measuring Power Consumption At A Data Center'>Sentilla: Measuring Power Consumption At A Data Center</a></ol></p>]]></content:encoded>
			<wfw:commentRss>http://eng-tips.nethawk.net/blog/power-as-one-of-the-criteria-for-selecting-a-data-center-site/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cut Time, Not Corners: 5 Steps to Efficiently Manage Defects across Shared Code</title>
		<link>http://eng-tips.nethawk.net/blog/cut-time-not-corners-5-steps-to-efficiently-manage-defects-across-shared-code</link>
		<comments>http://eng-tips.nethawk.net/blog/cut-time-not-corners-5-steps-to-efficiently-manage-defects-across-shared-code#comments</comments>
		<pubDate>Thu, 06 May 2010 16:33:52 +0000</pubDate>
		<dc:creator>Coverity</dc:creator>
				<category><![CDATA[Development Tools]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[White Papers]]></category>
		<category><![CDATA[Coverity]]></category>
		<category><![CDATA[Developer Efficiency]]></category>
		<category><![CDATA[Developer Productivity]]></category>
		<category><![CDATA[Dynamic Analysis]]></category>
		<category><![CDATA[Mission critical software]]></category>
		<category><![CDATA[Software Analysis]]></category>
		<category><![CDATA[Software Defects]]></category>
		<category><![CDATA[Software Efficiency]]></category>
		<category><![CDATA[Software Integrity]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[Static Analysis]]></category>

		<guid isPermaLink="false">http://eng-tips.nethawk.net/blog/?p=2133</guid>
		<description><![CDATA[When working on projects with large codebases that re-use components, it can be hard to identify which projects and products are affected by defects in shared code. How do you understand the impact of defects in your shared components? How do you analyze and prioritize the defects in your shared components so you know what [...]


Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/ipaccess-ensures-quality-of-3rd-party-code' rel='bookmark' title='Permanent Link: ip.access Ensures Quality of 3rd Party Code'>ip.access Ensures Quality of 3rd Party Code</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/how-to-find-fix-and-prevent-top-software-defects-with-static-analysis' rel='bookmark' title='Permanent Link: How to Find, Fix and Prevent Top Software Defects with Static Analysis'>How to Find, Fix and Prevent Top Software Defects with Static Analysis</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/coverity-maintains-software-integrity-of-sun-microsystems-award-winning-storage-products' rel='bookmark' title='Permanent Link: Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products'>Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products</a></ol>]]></description>
			<content:encoded><![CDATA[<p>When working on projects with large codebases that re-use components, it can be hard to identify which projects and products are affected by defects in shared code. How do you understand the impact of defects in your shared components? How do you analyze and prioritize the defects in your shared components so you know what to fix first, or not at all? How do you effectively track defect status and history across shared code?</p>
<p>Attend this webcast and you will learn five steps you can take to make the process of finding and fixing defects across shared code more efficient to increase developer productivity and reduce the risk of a schedule slip.</p>
<p>In this 30 minutes session you will learn:</p>
<p>&bull; How to effectively scan your software to identify hard to spot defects in shared code<br />
&bull; How to identify which projects and products are impacted by defects to prioritize which defects should be fixed first<br />
&bull; What actions and best practices are needed to ensure the necessary fixes are implemented to prevent defects from entering the field</p>
<p><a href="http://eng-tips.nethawk.net/registration_dynamic.php?id=70">View webinar</a></p>


<p>Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/ipaccess-ensures-quality-of-3rd-party-code' rel='bookmark' title='Permanent Link: ip.access Ensures Quality of 3rd Party Code'>ip.access Ensures Quality of 3rd Party Code</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/how-to-find-fix-and-prevent-top-software-defects-with-static-analysis' rel='bookmark' title='Permanent Link: How to Find, Fix and Prevent Top Software Defects with Static Analysis'>How to Find, Fix and Prevent Top Software Defects with Static Analysis</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/coverity-maintains-software-integrity-of-sun-microsystems-award-winning-storage-products' rel='bookmark' title='Permanent Link: Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products'>Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products</a></ol></p>]]></content:encoded>
			<wfw:commentRss>http://eng-tips.nethawk.net/blog/cut-time-not-corners-5-steps-to-efficiently-manage-defects-across-shared-code/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ip.access Ensures Quality of 3rd Party Code</title>
		<link>http://eng-tips.nethawk.net/blog/ipaccess-ensures-quality-of-3rd-party-code</link>
		<comments>http://eng-tips.nethawk.net/blog/ipaccess-ensures-quality-of-3rd-party-code#comments</comments>
		<pubDate>Tue, 04 May 2010 17:18:58 +0000</pubDate>
		<dc:creator>Coverity</dc:creator>
				<category><![CDATA[Development Tools]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[White Papers]]></category>
		<category><![CDATA[Coverity]]></category>
		<category><![CDATA[Coverity Prevent]]></category>
		<category><![CDATA[Developer Efficiency]]></category>
		<category><![CDATA[Developer Productivity]]></category>
		<category><![CDATA[Dynamic Analysis]]></category>
		<category><![CDATA[Mission critical software]]></category>
		<category><![CDATA[Software Analysis]]></category>
		<category><![CDATA[Software Defects]]></category>
		<category><![CDATA[Software Efficiency]]></category>
		<category><![CDATA[Software Integrity]]></category>
		<category><![CDATA[Software Safety]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[Static Analysis]]></category>

		<guid isPermaLink="false">http://eng-tips.nethawk.net/blog/?p=2129</guid>
		<description><![CDATA[ip.access is the leader in developing innovative technology for IP and Mobile connectivity. To meet consumer demand for their products, ip.access developers and external development partners need to collaborate to deliver top notch code under tight timetables. With more than 3.6 million lines of C/C++ and Java code, development leaders at ip.access recognized that unit [...]


Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/cut-time-not-corners-5-steps-to-efficiently-manage-defects-across-shared-code' rel='bookmark' title='Permanent Link: Cut Time, Not Corners: 5 Steps to Efficiently Manage Defects across Shared Code'>Cut Time, Not Corners: 5 Steps to Efficiently Manage Defects across Shared Code</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/schneider-electric-improves-product-quality-while-saving-over-2500-engineering-hours-with-coverity' rel='bookmark' title='Permanent Link: Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity'>Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/coverity-maintains-software-integrity-of-sun-microsystems-award-winning-storage-products' rel='bookmark' title='Permanent Link: Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products'>Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products</a></ol>]]></description>
			<content:encoded><![CDATA[<p>ip.access is the leader in developing innovative technology for IP and Mobile connectivity. To meet consumer demand for their products, ip.access developers and external development partners need to collaborate to deliver top notch code under tight timetables.</p>
<p>With more than 3.6 million lines of C/C++ and Java code, development leaders at ip.access recognized that unit tests and manual peer review were becoming too labor intensive to stay on the company&rsquo;s development timeline. Therefore, the company elected to create a continuous integration development process that would accelerate the ability of both internal and external teams to ensure the quality of their combined code. A key component in this process would be the use of static analysis to evaluate code prior to run-time.</p>
<p>ip.access selected Coverity Prevent as its static analysis solution because Prevent automatically finds a high concentration of critical software defects with the lowest false positive rate in the industry. In fact, ip.access reports false-positive rates at or below 5%. Because these analysis results are so accurate, developers at ip.access and its development partner can now avoid a significant amount of time-consuming manual code reviews and can check in code with greater confidence.</p>
<p>&quot;During our preliminary trial process, Coverity Prevent identified 27 &#8216;must-fix&#8217; defects in our draft code,&quot; said Jason Cooper, Senior Software Engineer at ip.access. &quot;With results like that, selecting Coverity was a quick decision for us.&quot;</p>
<p><a href="http://eng-tips.nethawk.net/registration_dynamic.php?id=69">Download whitepaper</a></p>


<p>Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/cut-time-not-corners-5-steps-to-efficiently-manage-defects-across-shared-code' rel='bookmark' title='Permanent Link: Cut Time, Not Corners: 5 Steps to Efficiently Manage Defects across Shared Code'>Cut Time, Not Corners: 5 Steps to Efficiently Manage Defects across Shared Code</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/schneider-electric-improves-product-quality-while-saving-over-2500-engineering-hours-with-coverity' rel='bookmark' title='Permanent Link: Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity'>Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/coverity-maintains-software-integrity-of-sun-microsystems-award-winning-storage-products' rel='bookmark' title='Permanent Link: Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products'>Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products</a></ol></p>]]></content:encoded>
			<wfw:commentRss>http://eng-tips.nethawk.net/blog/ipaccess-ensures-quality-of-3rd-party-code/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity</title>
		<link>http://eng-tips.nethawk.net/blog/schneider-electric-improves-product-quality-while-saving-over-2500-engineering-hours-with-coverity</link>
		<comments>http://eng-tips.nethawk.net/blog/schneider-electric-improves-product-quality-while-saving-over-2500-engineering-hours-with-coverity#comments</comments>
		<pubDate>Tue, 04 May 2010 17:04:39 +0000</pubDate>
		<dc:creator>Coverity</dc:creator>
				<category><![CDATA[Development Tools]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[White Papers]]></category>
		<category><![CDATA[Coverity]]></category>
		<category><![CDATA[Developer Efficiency]]></category>
		<category><![CDATA[Developer Productivity]]></category>
		<category><![CDATA[Dynamic Analysis]]></category>
		<category><![CDATA[Mission critical software]]></category>
		<category><![CDATA[Software Analysis]]></category>
		<category><![CDATA[Software Defects]]></category>
		<category><![CDATA[Software Efficiency]]></category>
		<category><![CDATA[Software Integrity]]></category>
		<category><![CDATA[Software Safety]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[Static Analysis]]></category>

		<guid isPermaLink="false">http://eng-tips.nethawk.net/blog/?p=2127</guid>
		<description><![CDATA[Schneider Electric (Schneider) is a global leader in energy management, developing solutions to make energy safe, reliable, efficient, and productive from plant to plug. Schneider Electric has adopted Coverity to improve product quality and software integrity while reducing development costs and re-focusing resources on innovation, benefits which have been realized within the development organization, across [...]


Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/ipaccess-ensures-quality-of-3rd-party-code' rel='bookmark' title='Permanent Link: ip.access Ensures Quality of 3rd Party Code'>ip.access Ensures Quality of 3rd Party Code</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/frequentis-standardizes-on-coverity-static-analysis-for-safety-critical-software-integrity' rel='bookmark' title='Permanent Link: Frequentis Standardizes on Coverity Static Analysis for Safety-Critical Software Integrity'>Frequentis Standardizes on Coverity Static Analysis for Safety-Critical Software Integrity</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/coverity-maintains-software-integrity-of-sun-microsystems-award-winning-storage-products' rel='bookmark' title='Permanent Link: Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products'>Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products</a></ol>]]></description>
			<content:encoded><![CDATA[<p>Schneider Electric (Schneider) is a global leader in energy management, developing solutions to make energy safe, reliable, efficient, and productive from plant to plug.</p>
<p>Schneider Electric has adopted Coverity to improve product quality and software integrity while reducing development costs and re-focusing resources on innovation, benefits which have been realized within the development organization, across the company, and supported at the highest level within Schneider Electric management.</p>
<p>&quot;We run the analysis from a centralized team and send out an email one week later announcing the results are available for the developers to review. If there is ever a delay in getting this information out to the developers, they come to us and seek it out. Not a single developer did this in the past. Now we have developers demanding Coverity.&quot;<br />
- Frank Klosek, Qualimetry and Senior Technical Manager</p>
<p><a href="http://eng-tips.nethawk.net/registration_dynamic.php?id=68">Download whitepaper</a></p>


<p>Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/ipaccess-ensures-quality-of-3rd-party-code' rel='bookmark' title='Permanent Link: ip.access Ensures Quality of 3rd Party Code'>ip.access Ensures Quality of 3rd Party Code</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/frequentis-standardizes-on-coverity-static-analysis-for-safety-critical-software-integrity' rel='bookmark' title='Permanent Link: Frequentis Standardizes on Coverity Static Analysis for Safety-Critical Software Integrity'>Frequentis Standardizes on Coverity Static Analysis for Safety-Critical Software Integrity</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/coverity-maintains-software-integrity-of-sun-microsystems-award-winning-storage-products' rel='bookmark' title='Permanent Link: Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products'>Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products</a></ol></p>]]></content:encoded>
			<wfw:commentRss>http://eng-tips.nethawk.net/blog/schneider-electric-improves-product-quality-while-saving-over-2500-engineering-hours-with-coverity/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products</title>
		<link>http://eng-tips.nethawk.net/blog/coverity-maintains-software-integrity-of-sun-microsystems-award-winning-storage-products</link>
		<comments>http://eng-tips.nethawk.net/blog/coverity-maintains-software-integrity-of-sun-microsystems-award-winning-storage-products#comments</comments>
		<pubDate>Tue, 04 May 2010 16:47:43 +0000</pubDate>
		<dc:creator>Coverity</dc:creator>
				<category><![CDATA[Development Tools]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Coverity]]></category>
		<category><![CDATA[Developer Efficiency]]></category>
		<category><![CDATA[Developer Productivity]]></category>
		<category><![CDATA[Dynamic Analysis]]></category>
		<category><![CDATA[Mission critical software]]></category>
		<category><![CDATA[Software Analysis]]></category>
		<category><![CDATA[Software Defects]]></category>
		<category><![CDATA[Software Efficiency]]></category>
		<category><![CDATA[Software Integrity]]></category>
		<category><![CDATA[Software Safety]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[Static Analysis]]></category>

		<guid isPermaLink="false">http://eng-tips.nethawk.net/blog/?p=2124</guid>
		<description><![CDATA[For customers of Sun Microsystems&#8217; long-term storage products, quality is rarely an issue. Sun is a global leader in network computing infrastructure solutions with well-known brands such as Java, Solaris, MySQL, and StorageTek. In a highly competitive market, companies like Sun constantly need to increase quality and reliability, speed delivery, and reduce costs just to [...]


Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/frequentis-standardizes-on-coverity-static-analysis-for-safety-critical-software-integrity' rel='bookmark' title='Permanent Link: Frequentis Standardizes on Coverity Static Analysis for Safety-Critical Software Integrity'>Frequentis Standardizes on Coverity Static Analysis for Safety-Critical Software Integrity</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/ipaccess-ensures-quality-of-3rd-party-code' rel='bookmark' title='Permanent Link: ip.access Ensures Quality of 3rd Party Code'>ip.access Ensures Quality of 3rd Party Code</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/schneider-electric-improves-product-quality-while-saving-over-2500-engineering-hours-with-coverity' rel='bookmark' title='Permanent Link: Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity'>Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity</a></ol>]]></description>
			<content:encoded><![CDATA[<p>For customers of Sun Microsystems&#8217; long-term storage products, quality is rarely an issue. Sun is a global leader in network computing infrastructure solutions with well-known brands such as Java, Solaris, MySQL, and StorageTek.</p>
<p>In a highly competitive market, companies like Sun constantly need to increase quality and reliability, speed delivery, and reduce costs just to stay even with its rivals. Coverity Static Analysis is a great addition to help not only achieve these objectives, but also surpass them. It has proven to be a tool that can find defects earlier, which reduces development costs and accelerates time to market.</p>
<p>Using Coverity Static Analysis also results in higher quality products in the field because there is more complete coverage of exception handling code in testing.  Finally, the real-time feedback improves software developers&rsquo; coding skills resulting in fewer testers needed relative to the number of developers. These benefits help Sun and its already award-winning products to not just stay on par with the competition, but widen the gap between Sun and its challengers.</p>
<p><a href="http://eng-tips.nethawk.net/registration_dynamic.php?id=67">Download whitepaper</a></p>


<p>Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/frequentis-standardizes-on-coverity-static-analysis-for-safety-critical-software-integrity' rel='bookmark' title='Permanent Link: Frequentis Standardizes on Coverity Static Analysis for Safety-Critical Software Integrity'>Frequentis Standardizes on Coverity Static Analysis for Safety-Critical Software Integrity</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/ipaccess-ensures-quality-of-3rd-party-code' rel='bookmark' title='Permanent Link: ip.access Ensures Quality of 3rd Party Code'>ip.access Ensures Quality of 3rd Party Code</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/schneider-electric-improves-product-quality-while-saving-over-2500-engineering-hours-with-coverity' rel='bookmark' title='Permanent Link: Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity'>Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity</a></ol></p>]]></content:encoded>
			<wfw:commentRss>http://eng-tips.nethawk.net/blog/coverity-maintains-software-integrity-of-sun-microsystems-award-winning-storage-products/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Frequentis Standardizes on Coverity Static Analysis for Safety-Critical Software Integrity</title>
		<link>http://eng-tips.nethawk.net/blog/frequentis-standardizes-on-coverity-static-analysis-for-safety-critical-software-integrity</link>
		<comments>http://eng-tips.nethawk.net/blog/frequentis-standardizes-on-coverity-static-analysis-for-safety-critical-software-integrity#comments</comments>
		<pubDate>Tue, 04 May 2010 16:24:59 +0000</pubDate>
		<dc:creator>Coverity</dc:creator>
				<category><![CDATA[Development Tools]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[White Papers]]></category>
		<category><![CDATA[Coverity]]></category>
		<category><![CDATA[Developer Efficiency]]></category>
		<category><![CDATA[Developer Productivity]]></category>
		<category><![CDATA[Dynamic Analysis]]></category>
		<category><![CDATA[Mission critical software]]></category>
		<category><![CDATA[Software Analysis]]></category>
		<category><![CDATA[Software bug detection]]></category>
		<category><![CDATA[Software Defects]]></category>
		<category><![CDATA[Software Efficiency]]></category>
		<category><![CDATA[Software Integrity]]></category>
		<category><![CDATA[Software Safety]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[Static Analysis]]></category>

		<guid isPermaLink="false">http://eng-tips.nethawk.net/blog/?p=2119</guid>
		<description><![CDATA[Frequentis develops highly reliable communication and information systems for safety-critical applications. Its market leading control centre solutions, products and services are used by customers in a variety of mission critical public and private fields such as air traffic control (civil and military); emergency services (police, fire departments, and ambulances); maritime systems; and railways and public [...]


Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/coverity-maintains-software-integrity-of-sun-microsystems-award-winning-storage-products' rel='bookmark' title='Permanent Link: Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products'>Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/schneider-electric-improves-product-quality-while-saving-over-2500-engineering-hours-with-coverity' rel='bookmark' title='Permanent Link: Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity'>Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/ipaccess-ensures-quality-of-3rd-party-code' rel='bookmark' title='Permanent Link: ip.access Ensures Quality of 3rd Party Code'>ip.access Ensures Quality of 3rd Party Code</a></ol>]]></description>
			<content:encoded><![CDATA[<p>Frequentis develops highly reliable communication and information systems for safety-critical applications. Its market leading control centre solutions, products and services are used by customers in a variety of mission critical public and private fields such as air traffic control (civil and military); emergency services (police, fire departments, and ambulances); maritime systems; and railways and public transport. Safety and freedom of failure is the single most important objective for Frequentis.</p>
<p>Frequentis&#8217; mission and commitment to safety is engrained into every part of the company, and the software quality organization is a direct reflection of this commitment. Coverity has helped Frequentis ensure a high level of software integrity to support its product mission of freedom from failure, while continually improving the productivity of its developers.</p>
<p>According to Andreas Gerstinger, Software Quality and Software Safety Engineer, who drove the evaluation and introduction of Coverity Static Analysis into the organization, &quot;We had used other analysis tools in the past but they did not go as deep as Coverity&#8211;they only provided metrics such as complexity measurement&#8211;but did not go as far as finding faults and pinpointing where they reside in the code. Developers didn&rsquo;t want a tool that only showed them abstract metrics, but would instead show them exactly where they made a coding error.&quot;</p>
<p><a href="http://eng-tips.nethawk.net/registration_dynamic.php?id=66">Download whitepaper</a></p>


<p>Related posts:<ol><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/coverity-maintains-software-integrity-of-sun-microsystems-award-winning-storage-products' rel='bookmark' title='Permanent Link: Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products'>Coverity Maintains Software Integrity of Sun Microsystems&#8217; Award-Winning Storage Products</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/schneider-electric-improves-product-quality-while-saving-over-2500-engineering-hours-with-coverity' rel='bookmark' title='Permanent Link: Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity'>Schneider Electric Improves Product Quality While Saving Over 2,500 Engineering Hours with Coverity</a><li><a class='blue_bold_text_normal' href='http://eng-tips.nethawk.net/blog/ipaccess-ensures-quality-of-3rd-party-code' rel='bookmark' title='Permanent Link: ip.access Ensures Quality of 3rd Party Code'>ip.access Ensures Quality of 3rd Party Code</a></ol></p>]]></content:encoded>
			<wfw:commentRss>http://eng-tips.nethawk.net/blog/frequentis-standardizes-on-coverity-static-analysis-for-safety-critical-software-integrity/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

