<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The IPS Guy &#187; theipsguy</title>
	<atom:link href="http://theipsguy.com/author/theipsguy/feed/" rel="self" type="application/rss+xml" />
	<link>http://theipsguy.com</link>
	<description>Intrusion Prevention/Detection technologies.</description>
	<lastBuildDate>Thu, 19 Aug 2010 17:25:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Intel buys Mcafee</title>
		<link>http://theipsguy.com/intel-buys-mcafee/</link>
		<comments>http://theipsguy.com/intel-buys-mcafee/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 17:25:29 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=241</guid>
		<description><![CDATA[It was announced today that Intel will buy Mcafee for over $7 billion dollars in cash. There had been rumors that HP was looking to buy Mcafee which would have been interesting to see how they would have combined the Tippingpoint and Mcaffe intrusion prevention systems. At first glance the Intel merger does seem odd until you [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>It was announced today that Intel will buy Mcafee for over $7 billion dollars in cash. There had been rumors that HP was looking to buy Mcafee which would have been interesting to see how they would have combined the Tippingpoint and Mcaffe intrusion prevention systems. At first glance the Intel merger does seem odd until you begin to look at some of the benefits.</p>
<p>Intel is developing processors with AES instructions sets included. In many ways this allows Intel to provide hardware based encryption and they now own a product to directly integrate with this processor. They could also develop AV solutions running on chips which would dramatically increase the scanning speed.</p>
<p>If  handled correctly this could dramatically change the availability of these products. Why buy another solution if your hardware already has one.</p>
<div id="_mcePaste">Intel® AES-NI Impact</div>
<div id="_mcePaste">Testing with McAfee Endpoint Encryption* for PCs (EEPC) 6.0, encrypting a 32GB Intel® X25-E SATA SSD using the Intel® Xeon® processor 5600 series with Intel® AES-NI showed a 30% faster server SSD provisioning time compared to the prior generation processor without Intel AES-NI.</div>
<div></div>
<div>Link to Intel article.</div>
<div>http://bit.ly/9f3bKb</div>
<div></div>
<div>Article on CNN</div>
<div>http://bit.ly/aW36s1</div>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/intel-buys-mcafee/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Results for the CISM</title>
		<link>http://theipsguy.com/results-for-the-cism/</link>
		<comments>http://theipsguy.com/results-for-the-cism/#comments</comments>
		<pubDate>Mon, 16 Aug 2010 15:25:12 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=238</guid>
		<description><![CDATA[Well ISACA was not kidding when they said it takes 6-8 weeks to get the results. I received my email at 4:00pm exactly 8 weeks after taking the exam. The good news is that I passed the exam! I am now beginning the process of  verification of my work experience. ISACA says it takes 6-8 weeks for [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Well ISACA was not kidding when they said it takes 6-8 weeks to get the results. I received my email at 4:00pm exactly 8 weeks after taking the exam. The good news is that I passed the exam! I am now beginning the process of  verification of my work experience. ISACA says it takes 6-8 weeks for this as well and I am sure it will probably take the full 8 weeks.</p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/results-for-the-cism/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thoughts on the CISM exam</title>
		<link>http://theipsguy.com/thoughts-on-the-cism-exam/</link>
		<comments>http://theipsguy.com/thoughts-on-the-cism-exam/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 14:28:25 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=236</guid>
		<description><![CDATA[So I took the CISM exam in June 12th. I have not received the results back yet, it generally takes 6-8 weeks. The test was tough and I thought the practice database from ISACA was a good representation of the type of questions to expect. I do think though that they could reduce the number [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>So I took the CISM exam in June 12th. I have not received the results back yet, it generally takes 6-8 weeks. The test was tough and I thought the practice database from ISACA was a good representation of the type of questions to expect. I do think though that they could reduce the number of questions from 200. There were many repetitive questions and for only 5 domains they should either add more unique questions or reduce the number.</p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/thoughts-on-the-cism-exam/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Preparing for the CISM exam</title>
		<link>http://theipsguy.com/preparing-for-the-cism-exam/</link>
		<comments>http://theipsguy.com/preparing-for-the-cism-exam/#comments</comments>
		<pubDate>Sun, 30 May 2010 18:10:32 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=233</guid>
		<description><![CDATA[I have decided to sit for the CISM exam. The exam is scheduled for June 12th. ISACA only offers the exam two times per year so I figured this was the best time to take it. The CISM is growing in popularity and is becoming more common in job requirements, although it is still not [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I have decided to sit for the CISM exam. The exam is scheduled for June 12th. ISACA only offers the exam two times per year so I figured this was the best time to take it. The CISM is growing in popularity and is becoming more common in job requirements, although it is still not as popular as the CISSP. The CISM is more focused to those in management positions around Information Security and requires three years of actual management experience in Information Security.</p>
<p>The exam is 200 questions and you can take up to 4 hours to complete. It is considered very rigorous and at least as difficult as the CISSP. I am very excited to take this exam and will post some information in subsequent posts. More information on the CISM exam can be found below.</p>
<p><a title="http://bit.ly/a2Xclj" href="http://bit.ly/a2Xclj">http://bit.ly/a2Xclj</a></p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/preparing-for-the-cism-exam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symantec to purchase PGP and GuardianEdge</title>
		<link>http://theipsguy.com/symantec-to-purchase-pgp-and-guardianedge/</link>
		<comments>http://theipsguy.com/symantec-to-purchase-pgp-and-guardianedge/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 18:46:29 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=227</guid>
		<description><![CDATA[While not related directly to IPS it is still news worthy. Symantec announce today they are buying PGP and GuardianEdge for $370 million dollars! Symantec has somewhat languished over the last few years without alot of truly innovative security products. This now places Symantec as a major player in the encryption space. They can now [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>While not related directly to IPS it is still news worthy. Symantec announce today they are buying PGP and GuardianEdge for $370 million dollars! Symantec has somewhat languished over the last few years without alot of truly innovative security products. This now places Symantec as a major player in the encryption space. They can now compete with other companies such as Mcaffe, Sophos and Checkpoint in the encryption space.</p>
<p>Interesting note: Mcafee previously owned PGP and sold it. They then later purchased Safeboot and now Symantec owns PGP. I guess Mcafee should have just kept PGP. <img src='http://theipsguy.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>http://www.theregister.co.uk/2010/04/29/symantec_buys_pgp/</p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/symantec-to-purchase-pgp-and-guardianedge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virtual IPS vs. Virtualized IPS</title>
		<link>http://theipsguy.com/virtual-ips-vs-virtualized-ips/</link>
		<comments>http://theipsguy.com/virtual-ips-vs-virtualized-ips/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 17:48:14 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IBM]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[Sourcefire]]></category>
		<category><![CDATA[Virtual IPS]]></category>
		<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=223</guid>
		<description><![CDATA[Virtualization is a top priority for most organizations today. Security of these virtualized environments should also be a top priority and in the Intrusion Prevention market most vendors are developing or have developed virtual or virtualized solutions. The terms virtual IPS and virtualized IPS have different meanings and I want to take some time to [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Virtualization is a top priority for most organizations today. Security of these virtualized environments should also be a top priority and in the Intrusion Prevention market most vendors are developing or have developed virtual or virtualized solutions.</p>
<p>The terms virtual IPS and virtualized IPS have different meanings and I want to take some time to attempt to differentiate these terms. Most vendors have had virtual IPS for many years. Virtual IPS is the ability to apply different polices to certain types of traffic. This could be done using VLAN tags or physical interfaces. IBM does this using the Protection Domains feature which allows a different policy to be deployed to different VLAN&#8217;s. Mcafee does this by allowing different policies to be assigned to physical interfaces and can also support policies to be applied based no VLAN tags.</p>
<p>Virtualized IPS is what most of us think of today when we discuss virtualization. Virtualized IPS is an IPS appliance that runs in a virtual environment such as VmWare, Zen or Microsoft&#8217;s Hyper-V. The IPS is installed as a virtual server and can be configured so that all server to server traffic inside and outside the virtual environment can be monitored by an IPS.</p>
<p>It is important to be clear on these differences in terminology because not all vendors have virtualized IPS and most sales people will not know enough to properly answer the question, Do you support virtualization? Most will say yes, because they have heard their support teams talk about virtual IPS not virtualized IPS. Virtualized IPS will continue to grow in importance and eventually all the major Intrusion Prevention vendors will have these offerings. Until then do your homework and hold the vendors accountable.</p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/virtual-ips-vs-virtualized-ips/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Errors with Mcafee Endpoint Encryption</title>
		<link>http://theipsguy.com/errors-with-mcafee-endpoint-encryption/</link>
		<comments>http://theipsguy.com/errors-with-mcafee-endpoint-encryption/#comments</comments>
		<pubDate>Thu, 15 Apr 2010 23:00:10 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[EEPC]]></category>
		<category><![CDATA[Endpoint Encryption]]></category>
		<category><![CDATA[Mcafee]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=217</guid>
		<description><![CDATA[I have a client that is deploying Mcafee Endpoint Encryption, formerly known as Safeboot. The product integrates with Active Directory and the newest version can be managed through the ePO management console. Overall the product has experienced a number of problems. Most of these problems are documented and can be mitigated by defragmenting the disk [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I have a client that is deploying Mcafee Endpoint Encryption, formerly known as Safeboot. The product integrates with Active Directory and the newest version can be managed through the ePO management console. Overall the product has experienced a number of problems. Most of these problems are documented and can be mitigated by defragmenting the disk or removing software that replaces the MSGINA, such as the HP Protect Tools.</p>
<p>The one problem that they have not been able to correct though is the Sector Chain is Invalid error. This error generally happens right after installation but can happen at any time.  According to the support engineers I have spoken to the machine is generally unable to be recovered! This is a serious problem that Mcafee seems to not be addressing. They have said they are unable to replicate the problem but this issue has been brought up multiple times in different forums going back to 2008.</p>
<p>Come on Mcafee you need to fix this problem. You supposedly have hundreds of thousands of customers and you make the encryption used by the HP Protect Tools. You can fix this and need to ASAP.</p>
<p>HP Forums</p>
<p><a title="http://bit.ly/dalIDD" href="http://bit.ly/dalIDD">http://bit.ly/dalIDD</a></p>
<p>Mcafee Knowledgebase Article</p>
<p><a title="http://bit.ly/dCeL2q" href="http://bit.ly/dCeL2q">http://bit.ly/dCeL2q</a></p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/errors-with-mcafee-endpoint-encryption/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Intrusion Prevention Cabling</title>
		<link>http://theipsguy.com/intrusion-prevention-cabling/</link>
		<comments>http://theipsguy.com/intrusion-prevention-cabling/#comments</comments>
		<pubDate>Fri, 19 Mar 2010 16:57:46 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>
		<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[intrusion prevention]]></category>
		<category><![CDATA[Mcafee IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=212</guid>
		<description><![CDATA[As a follow up on my previous post on cabling an IPS I have attached an example that I have seen successful.This example is specific to a Mcafee M2750 device and assumes interfaces that are hard set. Note that the actual firewall and LAN switch are using Straight cables and not cross-over. The only cross-over [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>As a follow up on my previous post on cabling an IPS I have attached an example that I have seen successful.This example is specific to a Mcafee M2750 device and assumes interfaces that are hard set. Note that the actual firewall and LAN switch are using Straight cables and not cross-over. The only cross-over is placed between the Fail-open kit and the IPS.</p>
<p><a href="http://theipsguy.com/wp-content/uploads/2010/03/Cabling.png"><img class="aligncenter size-medium wp-image-213" title="Cabling" src="http://theipsguy.com/wp-content/uploads/2010/03/Cabling-300x280.png" alt="" width="300" height="280" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/intrusion-prevention-cabling/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Added Fortinet Visio Stencils</title>
		<link>http://theipsguy.com/added-fortinet-visio-stencils/</link>
		<comments>http://theipsguy.com/added-fortinet-visio-stencils/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 22:24:36 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=207</guid>
		<description><![CDATA[I have added Fortinet Visio Stencils. Fortinet is a company of great interest. The products range from the client security to database security to traditional UTM type devices and even vulnerability management. Originally they focused on small to mid-size companies but they have expanded into much larger enterprises including the U.S. Government. Based in Sunnyvale, [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I have added Fortinet Visio Stencils. Fortinet is a company of great interest. <span id="more-207"></span>The products range from the client security to database security to traditional UTM type devices and even vulnerability management. Originally they focused on small to mid-size companies but they have expanded into much larger enterprises including the U.S. Government. Based in Sunnyvale, CA they have offices all around EMEA and APAC. They seem to be gaining market share and should definitely be reviewed when considering IPS or UTM devices.</p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/added-fortinet-visio-stencils/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Added Cisco Visio Icons and Stencils</title>
		<link>http://theipsguy.com/added-cisco-visio-icons-and-stencils/</link>
		<comments>http://theipsguy.com/added-cisco-visio-icons-and-stencils/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 14:29:18 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=201</guid>
		<description><![CDATA[I have added Cisco Visio Icons. This includes most of the Cisco products and not just the security related icons. There are several .vss files as well as a PowerPoint document with lots of icons. Enjoy!]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><a href="http://theipsguy.com/wp-content/uploads/2010/03/cisco.gif"><img class="aligncenter size-full wp-image-230" title="cisco" src="http://theipsguy.com/wp-content/uploads/2010/03/cisco.gif" alt="" width="110" height="73" /></a></p>
<p>I have added Cisco Visio Icons. This includes most of the Cisco products and not just the security related icons. There are several .vss files as well as a PowerPoint document with lots of icons. Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/added-cisco-visio-icons-and-stencils/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
