<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>I-BLOG &#187; Paper Of The Day</title>
	<atom:link href="http://www.rsivanandan.com/category/paper-of-the-day/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rsivanandan.com</link>
	<description>Never go to bed mad. Stay up and fight!</description>
	<lastBuildDate>Sat, 17 Dec 2011 08:20:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>IP Spoofing</title>
		<link>http://www.rsivanandan.com/2008/02/24/ip-spoofing/</link>
		<comments>http://www.rsivanandan.com/2008/02/24/ip-spoofing/#comments</comments>
		<pubDate>Sun, 24 Feb 2008 03:35:15 +0000</pubDate>
		<dc:creator>rsivanandan</dc:creator>
				<category><![CDATA[Paper Of The Day]]></category>

		<guid isPermaLink="false">http://www.rsivanandan.com/?p=224</guid>
		<description><![CDATA[After a while I decided to browse to see if there is any article of interest and ended up in IP Journal (Cisco&#8217;s). In this edition there is a fairly neat and to-the-point explanation of IP Spoofing. For some one who is just coming to security, which is the case of a lot of guys [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.rsivanandan.com/wp-content/uploads/2008/02/ip.jpg"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="101" alt="IP" src="http://www.rsivanandan.com/wp-content/uploads/2008/02/ip-thumb.jpg" width="244" border="0"></a> After a while I decided to browse to see if there is any article of interest and ended up in IP Journal (Cisco&#8217;s). In this edition there is a fairly neat and to-the-point explanation of IP Spoofing. For some one who is just coming to security, which is the case of a lot of guys I know; this would be a good read.</p>
<p>Especially the section as to what are the methods (not very effective), we can take to identify IP Spoofing. In most cases asymmetric routing can happen if we want to put in some methods to identify this by IP trace back which then would falsely identify a legitimate traffic as spoof!</p>
<p>A good read overall [ <a href="http://www.cisco.com/web/about/ac123/ac147/archived_issues/ipj_10-4/104_ip-spoofing.html" target="_blank">Here</a> ]</p>
<div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:96fb21ed-f117-4382-8683-700b1facee34" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/IP%20spoofing" rel="tag">IP spoofing</a>,<a href="http://technorati.com/tags/cisco%20ip%20journal" rel="tag">cisco ip journal</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.rsivanandan.com/2008/02/24/ip-spoofing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Transparent Firewalls</title>
		<link>http://www.rsivanandan.com/2007/06/02/transparent-firewalls/</link>
		<comments>http://www.rsivanandan.com/2007/06/02/transparent-firewalls/#comments</comments>
		<pubDate>Sat, 02 Jun 2007 08:19:20 +0000</pubDate>
		<dc:creator>rsivanandan</dc:creator>
				<category><![CDATA[Juniper]]></category>
		<category><![CDATA[Paper Of The Day]]></category>
		<category><![CDATA[Tech in general]]></category>

		<guid isPermaLink="false">http://www.rsivanandan.com/?p=161</guid>
		<description><![CDATA[Transparent firewalls are definitely a great enhancement to traditional firewall arena, for the very reason that the presence is not revealed. A simple article on what are the advantages of having one in such a mode is described &#8230; Read More&#8230; One of the other reasons why I like Juniper Netscreen firewalls is the same [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.rsivanandan.com/wp-content/uploads/2007/06/ssg-family1.jpg" atomicselection="true"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="65" alt="ssg_family" src="http://www.rsivanandan.com/wp-content/uploads/2007/06/ssg-family-thumb1.jpg" width="93" border="0"></a> Transparent firewalls are definitely a great enhancement to traditional firewall arena, for the very reason that the presence is not revealed.</p>
<p>A simple article on what are the advantages of having one in such a mode is described &#8230; <a href="http://www.securityfocus.com/infocus/1737" target="_blank"><font color="#0080ff">Read More&#8230;</font></a></p>
<p>One of the other reasons why I like <a href="http://www.juniper.net" target="_blank">Juniper Netscreen firewalls</a> is the same again. All of the models can work as Transparent mode firewalls (it doesn&#8217;t mean the drawback is like you can&#8217;t have VPN on it, even I thought so but these firewalls also allow you to build a VPN while in Xparent mode.</p>
<div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:ec5c1864-2205-430a-9813-b7a560be4ad4" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px">del.icio.us tags: <a href="http://del.icio.us/popular/Firewalls" rel="tag">Firewalls</a>, <a href="http://del.icio.us/popular/VPN" rel="tag">VPN</a>, <a href="http://del.icio.us/popular/Juniper" rel="tag">Juniper</a>, <a href="http://del.icio.us/popular/Netscreen" rel="tag">Netscreen</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.rsivanandan.com/2007/06/02/transparent-firewalls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Packet Sniffing in SWITCHED Networks!</title>
		<link>http://www.rsivanandan.com/2006/12/04/packet-sniffing-in-switched-networks/</link>
		<comments>http://www.rsivanandan.com/2006/12/04/packet-sniffing-in-switched-networks/#comments</comments>
		<pubDate>Mon, 04 Dec 2006 09:43:15 +0000</pubDate>
		<dc:creator>rsivanandan</dc:creator>
				<category><![CDATA[Paper Of The Day]]></category>

		<guid isPermaLink="false">http://www.rsivanandan.com/?p=59</guid>
		<description><![CDATA[If you&#8217;re one among who *knows* the basics but haven&#8217;t thought about it in action since you AREN&#8217;T a hacker, you would love this paper. ARP Spoofing isn&#8217;t a new thingy in attack world but the paper puts some insight into what you already know but haven&#8217;t seen it in any form. Another good read [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re one among who *knows* the basics but haven&#8217;t thought about it in action since you AREN&#8217;T a hacker, you would love this paper.</p>
<p>ARP Spoofing isn&#8217;t a new thingy in attack world but the paper puts some insight into what you already know but haven&#8217;t seen it in any form. Another good read from SANS</p>
<p>[<a href="http://www.sans.org/reading_room/whitepapers/networkdevs/244.php?portal=6a67912690d1f2f18fbe7ecd7cb820ef" target="_blank">Click Here</a>]</p>
<p>Happy Reading&#8230;..</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rsivanandan.com/2006/12/04/packet-sniffing-in-switched-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Egress Filtering</title>
		<link>http://www.rsivanandan.com/2006/07/23/egress-filtering/</link>
		<comments>http://www.rsivanandan.com/2006/07/23/egress-filtering/#comments</comments>
		<pubDate>Sun, 23 Jul 2006 15:49:19 +0000</pubDate>
		<dc:creator>rsivanandan</dc:creator>
				<category><![CDATA[Paper Of The Day]]></category>

		<guid isPermaLink="false">http://www.rsivanandan.com/?p=34</guid>
		<description><![CDATA[The egress filtering is often forgotten since the theory of Enterprises is that &#8216;allow everything from my internal network to go outside&#8217; and by default nothing will be allowed back into internal from Internet. This seems to make a lot of people happy about their networks nevertheless, it is good and needed for certain scenarios [...]]]></description>
			<content:encoded><![CDATA[<p>The egress filtering is often forgotten since the theory of Enterprises is that &#8216;allow everything from my internal network to go outside&#8217; and by default nothing will be allowed back into internal from Internet. This seems to make a lot of people happy about their networks nevertheless, it is good and needed for certain scenarios but not &#8216;the best solution&#8217;.</p>
<p>This paper describes about Egress Filtering and I would highly recommend everybody to take a look at it;</p>
<p><a href="http://www.sans.org/reading_room/whitepapers/firewalls/1059.php" target="_blank">[Click to redirect to the article] </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rsivanandan.com/2006/07/23/egress-filtering/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Intelligent IDS Systems</title>
		<link>http://www.rsivanandan.com/2006/07/22/intelligent-ids-systems/</link>
		<comments>http://www.rsivanandan.com/2006/07/22/intelligent-ids-systems/#comments</comments>
		<pubDate>Sat, 22 Jul 2006 08:08:27 +0000</pubDate>
		<dc:creator>rsivanandan</dc:creator>
				<category><![CDATA[Paper Of The Day]]></category>

		<guid isPermaLink="false">http://www.rsivanandan.com/?p=30</guid>
		<description><![CDATA[Some time back when I was testing the Cisco IDS system at a Cisco Offshore Development center, I often felt like we are in an era of &#8216;converged solutions&#8217; but often the elements are not converged at all. A distributed Intrusion Detection/Prevention System should be able to manage itself to a larger extent on the [...]]]></description>
			<content:encoded><![CDATA[<p>Some time back when I was testing the Cisco IDS system at a Cisco Offshore Development center, I often felt like we are in an era of &#8216;converged solutions&#8217; but often the elements are not converged at all.</p>
<p>A distributed Intrusion Detection/Prevention System should be able to manage itself to a larger extent on the operational side and should leverage the fuctionality of assessments to the Network Security Auditor</p>
<p>The article is a mix of ideas I brooded and published at <a target="_blank" href="http://www.securitydocs.com/">SecurityDocs</a></p>
<p><a target="_blank" href="http://www.securitydocs.com/library/2641">[Click to redirect to the article] </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rsivanandan.com/2006/07/22/intelligent-ids-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Metrics</title>
		<link>http://www.rsivanandan.com/2006/07/22/security-metrics/</link>
		<comments>http://www.rsivanandan.com/2006/07/22/security-metrics/#comments</comments>
		<pubDate>Sat, 22 Jul 2006 08:00:29 +0000</pubDate>
		<dc:creator>rsivanandan</dc:creator>
				<category><![CDATA[Paper Of The Day]]></category>

		<guid isPermaLink="false">http://www.rsivanandan.com/?p=29</guid>
		<description><![CDATA[&#8220;Any activity cannot be managed if it cannot be measured&#8230;&#8221; One of the things I love about this is, this is like a striking quote! Conveys a lot of message in a single sentence and I believe it is true. Shirley C Payne writes about &#8216;Security Metrics&#8217; at Sans.org, a highlevel guide for an approach [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Any activity cannot be managed if it cannot be measured&#8230;&#8221; One of the things I love about this is, this is like a striking quote! Conveys a lot of message in a single sentence and I believe it is true.</p>
<p>Shirley C Payne writes about &#8216;Security Metrics&#8217; at Sans.org, a highlevel guide for an approach of process-definition of how it can be started off. Any company can start a program like this if you really care about your management since it gives you the measurement.</p>
<p><a href="http://www.sans.org/reading_room/whitepapers/auditing/55.php" target="_blank">[Click to redirect to the article] </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rsivanandan.com/2006/07/22/security-metrics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Transparent Firewalls &#8211; Intro</title>
		<link>http://www.rsivanandan.com/2006/07/19/transparent-firewalls-intro/</link>
		<comments>http://www.rsivanandan.com/2006/07/19/transparent-firewalls-intro/#comments</comments>
		<pubDate>Wed, 19 Jul 2006 09:31:20 +0000</pubDate>
		<dc:creator>rsivanandan</dc:creator>
				<category><![CDATA[Paper Of The Day]]></category>

		<guid isPermaLink="false">http://www.rsivanandan.com/?p=24</guid>
		<description><![CDATA[It is a great feature enhancement we have now, the so called &#8216;transparent firewalls&#8217;. A firewall that works in Layer 2. Advantages ? Just plug into the network, nobody will even know that there is a firewall sitting in between and doing filtering of packets since there is no ip addresses involved and so neither [...]]]></description>
			<content:encoded><![CDATA[<p>It is a great feature enhancement we have now, the so called &#8216;transparent firewalls&#8217;. A firewall that works in Layer 2.</p>
<p>Advantages ? Just plug into the network, nobody will even know that there is a firewall sitting in between and doing filtering of packets since there is no ip addresses involved and so neither routing&#8230;.</p>
<p><a href="http://www.securityfocus.com/infocus/1737" target="_blank">Transparent, Bridging Firewalls </a></p>
<p>So if you are new to this, take a peek and have fun&#8230;. Though it is not a paper which covers in and out of the technology but it kinda gives you an overview. Commercial products &amp; Industry leaders like Cisco (PIX Firewall) &amp; Juniper (Netscreen Firewall), already have products for the game&#8230;</p>
<p><a href="http://www.securityfocus.com/infocus/1737" target="_blank">[Click to redirect to the article] </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rsivanandan.com/2006/07/19/transparent-firewalls-intro/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hardening the TCP/IP stack to SYN attacks</title>
		<link>http://www.rsivanandan.com/2006/07/18/hardening-the-tcpip-stack-to-syn-attacks/</link>
		<comments>http://www.rsivanandan.com/2006/07/18/hardening-the-tcpip-stack-to-syn-attacks/#comments</comments>
		<pubDate>Tue, 18 Jul 2006 09:10:33 +0000</pubDate>
		<dc:creator>rsivanandan</dc:creator>
				<category><![CDATA[Paper Of The Day]]></category>

		<guid isPermaLink="false">http://www.rsivanandan.com/?p=23</guid>
		<description><![CDATA[I&#8217;ve been in the habit of reading technical papers (one a day, sounds like a tablet). I believe, it would be a good idea to keep all of them in one place and so &#8216;Paper Of The Day&#8217; Hardening the TCP/IP stack to mitigate/hanle SYN attacks The paper brings in an interesting log of parameters [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been in the habit of reading technical papers (one a day, sounds like a tablet). I believe, it would be a good idea to keep all of them in one place and so &#8216;Paper Of The Day&#8217; <img src='http://www.rsivanandan.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><a href="http://www.securityfocus.com/infocus/1729">Hardening the TCP/IP stack to mitigate/hanle SYN attacks</a><br />
The paper brings in an interesting log of parameters that can be tuned/altered to protect servers from SYN flood attacks. Now it necessarily doesn&#8217;t mean that it will protect you cent percent but after tuning, the server will manage to survive a little better than the default configuration. Author has chosen to explain and give examples on RH Linux 7.3, Windows 2000, Sun Solaris 8 and HP-UX 11.0</p>
<p>It is quite interesting that these parameters are there still lot of servers (esp. web servers) are deployed with default configuration! Tweaking these settings aren&#8217;t &#8216;Rocket Science&#8217; especially when you have documentation like this by good authors&#8230;</p>
<p><a href="http://www.securityfocus.com/infocus/1729" target="_blank">[Click to redirect to the Article] </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rsivanandan.com/2006/07/18/hardening-the-tcpip-stack-to-syn-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

