<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Advancements at the Monastery &#187; Trust Management</title>
	<atom:link href="http://blog.securitymonks.com/category/trust-management/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.securitymonks.com</link>
	<description>Information about developments at the Monastery</description>
	<lastBuildDate>Fri, 03 Sep 2010 05:41:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>TOTEM: Threat Observation, Tracking, and Evaluation Model</title>
		<link>http://blog.securitymonks.com/2009/06/06/totem-threat-observation-tracking-and-evaluation-model/</link>
		<comments>http://blog.securitymonks.com/2009/06/06/totem-threat-observation-tracking-and-evaluation-model/#comments</comments>
		<pubDate>Sun, 07 Jun 2009 01:29:06 +0000</pubDate>
		<dc:creator>John Gerber</dc:creator>
				<category><![CDATA[ANL Federated Model]]></category>
		<category><![CDATA[Bro]]></category>
		<category><![CDATA[CAMNEP]]></category>
		<category><![CDATA[CPP]]></category>
		<category><![CDATA[Defense in Depth]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Reputation]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[SlideCasting]]></category>
		<category><![CDATA[SlideShare]]></category>
		<category><![CDATA[Snort]]></category>
		<category><![CDATA[TVA]]></category>
		<category><![CDATA[Trust Management]]></category>
		<category><![CDATA[Visualization]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://blog.securitymonks.com/?p=1165</guid>
		<description><![CDATA[This week I had the pleasure of presenting two talks at the National Laboratories Information Technology (NLIT) 2009 Summit held in Oak Ridge, TN.  Everyone involved was great and I had a fun time.  Since the presentations have been posted to the NLIT site, I am free to post now.  

The original [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://imagecache2.allposters.com/images/pic/BRGPOD/203201~St-John-Chrystostomos-circa-347-407-Preaching-Before-the-Empress-Eudoxia-circa-404-circa-1880-Posters.jpg"><img src="http://imagecache2.allposters.com/images/pic/BRGPOD/203201~St-John-Chrystostomos-circa-347-407-Preaching-Before-the-Empress-Eudoxia-circa-404-circa-1880-Posters.jpg" alt="" align="left" width=150 /></a>This week I had the pleasure of presenting two talks at the <a href="http://www.fbcinc.com/nlit/default.aspx">National Laboratories Information Technology (NLIT)</a> 2009 Summit held in Oak Ridge, TN.  Everyone involved was great and I had a fun time.  Since the presentations have been <a href="http://info.ornl.gov/events/nlit09/Pages/Home.aspx">posted</a> to the NLIT site, I am free to post now.  </p>
<p>
The original slides made heavy use of the <a href="http://en.wikipedia.org/wiki/PowerPoint_animation">Microsoft PowerPoint animation</a> feature.  Unfortunately, SlideShare does not currently support animation.  You can download the presentation and the animations will work, but I ended up modifying the slides so they are more viewable online.  <a href="http://www.slideboom.com/">SlideBoom</a> will keep the animation, but it does it by creating a video of the presentation.  I decided to stick with SlideShare and spare you the resulting nine minute video.  While I should add audio and make a <a href="http://www.slideshare.net/jboutelle/slidecasting-101">SlideCast</a>, this post might never be completed if I wait until I have time to create a really nice web presentation.
</p>
<p>
<a href="http://www.merriam-webster.com/dictionary/totem">Merriam-Webster</a> defines a <strong>totem</strong> as any supposed entity that watches over or assists a group of people, such as a family, clan, or tribe.  In this presentation I focused on how TOTEM assists in watching over and evaluating the threat an IP represents.  The idea behind TOTEM is simple: compare threat information from sources such as watchlists (DShield, Emerging Threats, SenderBase, etc.) to activities with the organization (IDS/IPS, flow logs, etc.) and other locations (SANS ISC, DOE federated model, etc.).  As new threat information and activity sources are added, a better evaluation can be rendered.
</p>
<p><div style="width:425px;text-align:left" id="__ss_1543517"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/johngerber/totem-threat-observation-tracking-and-evaluation-model-1543517?type=powerpoint" title="TOTEM: Threat Observation, Tracking, and Evaluation Model">TOTEM: Threat Observation, Tracking, and Evaluation Model</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=totem-090606185822-phpapp02&#038;rel=0&#038;stripped_title=totem-threat-observation-tracking-and-evaluation-model-1543517" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=totem-090606185822-phpapp02&#038;rel=0&#038;stripped_title=totem-threat-observation-tracking-and-evaluation-model-1543517" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object>
<div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more presentations by <a style="text-decoration:underline;" href="http://www.slideshare.net/johngerber">John Gerber</a>.</div>
</div>
<p>
The purpose of this presentation has been to share the basic ideas behind TOTEM with the hope that others may provide helpful insight.  So far I have not disappointed.  I wanted to thank everyone for I have received some very intriguing ideas.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.securitymonks.com/2009/06/06/totem-threat-observation-tracking-and-evaluation-model/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

