Friday, April 17, 2015

Steel and cement The fall of the building known as WTC-7 name is one of the most disturbing aspects


What? Even with this story of September 11? Yes always. There are people and organizations who continue to work on it, for the truth to be found, tried and widespread. It is the example of the Consensus Panel, one of the best groups in this sense: military, engineers, journalists, lawyers, parliamentarians, from all over the world, all qualified, known and respected in the various areas. Work based on the governmental documentary sources (the same who defend the official version), academic research, independent research results. And were able to gather a number of impressive documents, to the point that the most natural question is: how is it possible that there are still people to believe in the official version? One of the last works of Consenus Panel is that it could be understood as a secondary aspect of 9/11: NIST's statements (National Institute of Standards and Technologies) about metal structures involved in the fall of the buildings in New York (the Twin Towers and the Building # 7). NIST lied. Not once but several times. NIST is a public institution, unique among all public or private institutions, was charged by the US government to carry out the analysis of the causes of the fall occurred at the World Trade Center on 11 September 2001. In an ideal society, not there would be nothing strange: after all one of the tasks of a any government should also be the one to investigate the reasons of an event that sowed death and destruction. nitrado This, of course, in a normal society: in our society, the thing seems a little "suspicious", nitrado so to speak. And the suspicion it reinforces the view that the US private institutions respected, able at least to advise the public nitrado effort, certainly not lacking. But this is a detail. What matters most is that according to the statements of NIST, would not have been possible to examine the structural characteristics of WTC -7, since that would not have been found in the same building remains.
Steel and cement The fall of the building known as WTC-7 name is one of the most disturbing aspects of 9/11. A modern steel frame, 47 floors under 20 years old (was inaugurated in 1984), not hit by planes nitrado allegedly pirated, collapsed after the fire a few hours, if only the world. There were other fires in skyscrapers, none of them collapsed: 1988, First Interstate nitrado Bank Building, Los Angeles (USA): 12 hours of fire (in the WTC-7 were less than 8 hours of actual fire). 1991 One Meridan Plaza Philadelphia (USA) 18 hours of fire. 2004 Central Park, Caracas (Venezuela): 17 hours of fire. 2005 Windsor Building, Madrid (Spain) 24 hours of fire. The latter case is particularly significant because there was partial collapse of the floors, but the structure resisted. The supporters of the official version like stress such as incorrect compare structures in reinforced concrete with WTC-7, entirely of steel. What is correct: the skyscrapers nitrado of Philadelphia, Caracas and Madrid had, in fact, a mixed type of structure. But not the First Interstate nitrado Bank of Los Angeles, built in steel (as well as witness the historical archive nitrado of the Los Angeles Fire Department): exactly like the WTC-7. It is therefore essential to the analysis of the remains to establish what actually failed that day.
The lie is good to remember that the then mayor of New York, Rudolph Giuliani, according to the national authorities, organized a spectacularly quick cleaning of the huge pile of rubble, making sure that all traces of the event disappear as soon as possible. Therefore the direct investigation of the materials seem to be impossible. Also does not hurt to remember that the more than 500 pages of the 9-11 Commission Report (the "official version" of 0/11) there is not the slightest indication of the collapse of WTC-7. That a little unusual. So what says NIST? NIST claims being unable to perform a metallographic analysis of steel, because (this statement repeated several times, in various roles) nitrado were no longer available the remains of WTC-7, hastily exported to China where they were melted down (because, of course, no one in the United States would have been able to carry out this task). A pity, because such an analysis would have been crucial to confirm or reject the argument of the NIST, according to which the WTC-7 would have collapsed because of the weakening of steel structures, due to the raging fire. Question: does the NIST told the truth? Answer: no. And there is not only a refutation, but five. The Worcester Polytechnic Institute, through the pages of the Journal of Mineral, Metals and Materials Society (JOM), reports the experience of three researchers, JR Barnett, Biederman RR and RD Sisson Jr. who in 2001 conducted a microstructural Initial Analysis of A36 Steel WTC Building 7 ("Microstructural Analysis Initial Aç

Thursday, April 16, 2015

Home | Videos and Tips | Articles | Recommended Books | Challenges | Strips | Columnists | About |

'Framework for cybersecurity published by NIST - Improvements in critical infrastructure SegInfo Blog - Information Security - Technology - News, Articles and News
Home | Videos and Tips | Articles | Recommended Books | Challenges | Strips | Columnists | About | Contact | Media Kit Test | SegInfocast | Workshop | SegInfo Lectures | War Project Driving Day | War Project Trashing Day | Press
Bruno Filipe Salgado Villar Henrique Soares Mariano Sumrell Rafael Soares Ferreira Machado Raphael Ricardo Kleber partition magic Tulio Alvarez partition magic Victor Santos Walter Capanema History partition magic April 2015 (2) March 2015 (5) February 2015 (7) January 2015 (10) December 2014 (7) November 2014 ( 14) October 2014 (14) September 2014 (18) August 2014 (12) July 2014 (16) June 2014 (23) May 2014 (30) April 2014 (15) June 2014 (14) February 2014 (22) January 2014 ( 17) December 2013 (11) November 2013 (8) October 2013 (8) September 2013 (11) August 2013 (21) July 2013 (26) June 2013 (17) May 2013 (21) April 2013 (38) March 2013 ( 37) February 2013 (20) January 2013 (27) December 2012 (15) November 2012 (18) October 2012 (21) September 2012 (16) August 2012 (23) July 2012 (23) June 2012 (22) May 2012 ( 27) April 2012 (21) June 2012 (22) February 2012 (15) January 2012 (19) December 2011 (22) November 2011 (29) October 2011 (31) September 2011 (33) August 2011 (44) July 2011 ( 39) June 2011 (36) May 2011 (54) April 2011 (34) June 2011 (71) February 2011 (99) January 2011 (94) December 2010 (103) November 2010 (72) October 2010 (97) September 2010 ( 97) August 2010 (114) July 2010 (100) June 2010 (55) May 2010 (13)
0-day adobe android apple botnet Brazil cellular chrome cisco encryption united states statistical study SegInfo Event exploit firefox flash fraud google government internet explorer iOS iphone java justice law linux malware metasploit microsoft mozilla office oracle research release smartphone privacy police reader report spam virus vulnerability windows xss
The NIST, National Institute of Standards and Technology, launched on February 12, a framework for cybersecurity infrastructure improvements in order to help organizations participating in the nation's finances and provide energy or health to the country, among others critical systems to better protect their data and physical assets partition magic from cyber attacks. partition magic This provides a framework that organizations, partition magic regulators and customers can use to create, guide, evaluate partition magic or improve their cyber security programs.
The document provides a common language to treat and manage partition magic cyber risks in an effective way in terms of based on business needs with costs, without partition magic putting additional regulatory requirements on businesses. Organizations can use the framework to determine your current level of cyber security, set goals that are in sync with your business environment and develop partition magic a plan to improve or maintain their safety. It also provides a methodology to protect privacy and civil liberties helping organizations incorporate these protections in a comprehensive cyber security program.
The three main elements described in the document are the "Framework Core", the "Levels" and "Profiles". The Center has five functions to identify, protect, detect, respond to and recover - that together allow any organization understands and tailors its cybersecurity program. The "Levels" describe the degree to which an organization's security risk management meets the established objectives. The "Profiles" help organizations progress to a current level of cybersecurity sophistication, meeting the business needs.
See also: Research shows that 87.2% of IT professionals believe that training partition magic in the classroom is better than the method "Self-Study" If misconfigured, NTP servers can be used to DRDOS attacks
Home | About | Event 2012 | Challenges | Articles | Columnists | Strips | Tips | Contact Us Home | SegInfocast partition magic | Videos and Tips | Workshop | Articles | Challenges | Strips | Columnists | About | Contact Phone: +55 (21) 2561-0867 and +55 (21) 2210-6061 Mobile: +55 (21) 97270-3503 2010 SegInfo Blog - Information Security - Technology - News, Articles partition magic and News - Events, News, Articles and News Technology and Information Security

Wednesday, April 15, 2015

All this focus on security protocol, permissions and reputation is commendable, but at the end, the


A few days ago, I was delighted to see the National Institute of Standards and US Technology (NIST) to launch its Framework Preliminary Cybersecurity (link in English) to reduce the cyber risk to critical infrastructure organizations. Behind a quick read, I got a very positive impression: the framework covers a lot of material, and I think that will help organizations to understand the whole picture of their preparation lumiere for safety. His layered approach is solid, I have seen this focus on work in other industries: E-Discovery (with its model of maturation EDRM) and software development (CMMI). Satisfies lumiere me very much to see this kind of attention to privacy and personally identifiable information manipulation (PII).
Despite this, I saw some structural problems in my second review of the framework. The framework has a lot of unnecessary lumiere information security lumiere policies and procedures and does not have sufficient data on the importance of collaboration and sharing threat intelligence. It contains no mention lumiere of proactive investigations, lumiere much less proactive forensic investigations. The framework contains a vast amount of detail on rules and procedures for ensuring information security, most very little information about requirements and procedures for organizations to work together. The framework lumiere also has a big hole in their categorization of the detection and response to threats.
Identification: Know what needs to be protected. Unfortunately, this is just a dream: the information security teams have been trying to do this for decades without lumiere success. It is not a novelty, and put it in the framework will not change anything.
Answer: containment, eradication lumiere and notification are important, but what we are currently seeing is that this step is too late to have a real impact. By the time we give this step, the damage has already been done.
All this focus on security protocol, permissions and reputation is commendable, but at the end, the detection is the drawing point. In spite of our ever-increasing ability to create access controls and security policies, we continue to see a greater number of invasions. The black-hat hackers will continue to find ways around protocols, procedures, and access controls. If you can not detect the attack, you can not answer lumiere it or recover.
Detection is where we care about take bold steps and is our greatest opportunity for collaboration. I am happy to see that "the anomalies lumiere and events" were classified as the first steps in detection. We have been talking about "events" and "Administration events" for years, lumiere plus all know that the most frightening words of the Portuguese language are: "What is this? Is kinda weird. "
We need to focus us on the detection of the anomaly and see the difference in their behavior towards their normal action. The first subcategory of the framework to detect (DE.AE-1) seeks to establish a baseline of normal behavior, but there is no explicit mention of detecting deviations from the baseline. These differences from normal behavior are usually the only indication lumiere of an Advanced Persistent Threat: an attack that surely lumiere will feature custom malware that evadirá all detection systems based on signatures.
I would also like to see an explicit mention of proactive forensic investigations. This is a practice is held by many security groups lumiere around the world, but generates little discussion. Security groups knowledgeable commonly audit various components in the network, even without a cause, to detect incidents before they grow. I see no mention of it here.
I have another lumiere problem with the framework in general: the lack of a collaborative language. ID.RA-2 lumiere discusses how to receive information about threats from information sharing capabilities, but not how to contribute information. PR.AT-3 talks about how third parties need to understand lumiere their own responsibilities, but does not include anything about assigning responsibilities. DE.CM-6 talks about monitoring of external service providers. RS.CO-5 uses the "voluntary" term to describe coordination with stakeholders outside the organization if an event or incident. Finally, RC.CO-1 and-2 RC.CO discuss repairing the reputation and public lumiere relations, to say nothing of how clearly disclose a threat or prevent other organizations suffer a similar attack.
This is not collaborative, is paranoid. I understand that we are all participating in a global defense, we all need to plan our own procedures, but we need more information on collaboration. I understand the need to protect the reputation of an organization and understand the highly competitive lumiere nature of the corporate environment, but

Tuesday, April 14, 2015

The National Institute of Standards and Technology (NIST) issued for review and public comment pote

NIST updates security guide to industrial control systems SegInfo Blog - Information Security - Technology - News, Articles and News
Home | Videos and Tips | Articles | Recommended Books | Challenges | Strips | Columnists | About | Contact | Media Kit Test | SegInfocast | Workshop | SegInfo Lectures | War Project Driving Day | War Project Trashing Day | Press
Bruno Filipe Salgado Villar Henrique Soares Mariano Sumrell Rafael Soares Ferreira Machado Raphael Ricardo Kleber potential Tulio Alvarez Victor Santos Walter Capanema History April 2015 (2) March 2015 (5) February 2015 (7) January 2015 (10) December 2014 (7) November 2014 ( 14) October 2014 (14) September 2014 (18) August 2014 (12) July 2014 (16) June 2014 (23) May 2014 (30) April 2014 (15) June 2014 (14) February 2014 (22) January 2014 ( 17) December 2013 (11) November 2013 (8) October 2013 (8) September 2013 (11) August 2013 (21) July 2013 (26) June 2013 (17) May 2013 (21) April 2013 (38) March 2013 ( 37) February 2013 (20) January 2013 (27) December 2012 (15) November 2012 (18) October 2012 (21) September 2012 (16) August 2012 (23) July 2012 (23) June 2012 (22) May 2012 ( 27) April 2012 (21) June 2012 (22) February 2012 (15) January 2012 (19) December 2011 (22) November 2011 (29) October 2011 (31) September 2011 (33) August 2011 (44) July 2011 ( 39) June 2011 (36) May 2011 (54) April 2011 (34) June 2011 (71) February 2011 (99) January 2011 (94) December 2010 (103) November 2010 (72) October 2010 (97) September 2010 ( 97) August potential 2010 (114) July 2010 (100) June 2010 (55) May 2010 (13)
0-day adobe android apple botnet Brazil cellular chrome cisco encryption united states statistical study SegInfo Event exploit firefox flash fraud google government internet explorer iOS iphone potential java justice law linux malware metasploit microsoft mozilla office oracle research release smartphone privacy police reader report spam virus vulnerability windows xss
The National Institute of Standards and Technology (NIST) issued for review and public comment potential a great proposal for updating its Safety Guide to Industrial Control Systems (ICS - Industrial Control Systems), which can be seen here.
Most industrial control systems constituted up until recently on proprietary technologies. True hardware and software collections running stand-alone way, isolated from most external threats. Today, there is a wide availability of integration with applications, enabled devices to the Internet and other IT offerings, and data used increasingly potential to support business decisions through connections with management systems. potential
Although this increased connectivity has brought potential great benefits, potential both in operational and managerial framework, it also provided an increase in exposure of these systems, malicious attacks; equipment failures; errors and other threats related software - these vulnerabilities caused by insufficient protection against malware, improper operation, maintenance of outdated systems; among other factors.
Downloaded over 2.5 million times since its initial potential release in 2006, the NIST guide advises on how to reduce potential the vulnerability of ICS used by industrial plants, potential utilities and other large infrastructure operations, such as the distribution sector energy. The new project - second guide review - includes sections updates on threats and vulnerabilities in ICS, risk management, best practices, architectures and security potential features, and tools to ICS, and a new appendix that had been detailed in NIST SP 800-53 Revision 4, offering personalized guidance on how to adapt and apply security controls and improvements in them.
Home | About | Event 2012 | Challenges | Articles | Columnists potential | Strips | Tips | Contact Us Home | SegInfocast | Videos and Tips | Workshop potential | Articles | Challenges | Strips | Columnists | About | Contact Phone: +55 (21) 2561-0867 and +55 (21) 2210-6061 Mobile: +55 (21) 97270-3503 2010 SegInfo Blog - Information Security - Technology - News, Articles and News - Events, News, Articles and News Technology and Information Security Under License Creative Commons - Some rights reserved


Monday, April 13, 2015

Here I will post some security tips, articles / paper mine or from other blogs I think que interest


Here I will post some security tips, articles / paper mine or from other blogs I think que interested. I Iove computer related subjects in special: - Penetration Tests - Network Intrusion Detection and Prevention balance - Network Behaviour - SIEM - Network Security Monitoring (NSM) - Incident Response - Firewall balance - Host Intrusion Detection System - The Open Web Application Security Project (OWASP) - Chapter Brazil - fuzzing - Vulnerability - Packet Analisys - Log Analysis - Beer =)
Lectured in early April in São Paulo on Bsides SCAP / OpenSCAP. The slides can be accessed at the following URL: http://www.slideshare.net/spookerlabs/scap-security-content-automation-protocol-na-bsides2014 Today saw the news that the OpenSCAP is now validated by NIST and became the third product compatible with SCAP 1.2.
NIST certificate News - http://www.redhat.com/about/news/press-archive/2014/4/red-hat-continues-to-drive-open-security-standards-openscap-receives-nist-certification The OpenSCAP is a tool to use, powerful, free and editable =) Tool Site: http://open-scap.org/page/Main_Page Congratulations to those involved in the development and contributions. Happy Protection! Rodrigo "Sp0oKeR" Montoro
2015 (5) February (3) January (2) 2014 (7) October (1) September (1) May (1) April (2) Slides lecture - SCAP (Security Content Automati .. . ss Command (Socket Statistics) - Analyzing related ... March (1) February (1) 2013 (7) August (4) June (1) January (2) 2012 (26) November (1) October balance (1) August (2) July (3) June (2) April (1) March (4) February (2) January (10) 2011 (4) October (1) June (1) January (2) 2010 (43) December (1) October (1) September (3) August (6) July (8) June (2) May (3) April (2) March (5) February (9) January balance (3) 2009 (27) December (1) October (1) September (3) August (1) July (2) June (3) May (2) April (3) March (8) February (3)


The purpose of the definition is to serve as a means of cloud services comparison and development s

NIST publishes final version definition of Cloud Computing: Cloud Security Regional Chapter Brazil robo ed
Cloud Security Alliance Chapters Sites> Brazil Cloud Security Regional Chapter> Articles> Publications> NIST publishes final version definition of Cloud Computing NIST publishes final version robo ed definition of Cloud Computing robo ed
After a few years of work and 15 drafts, NIST (National Institute of Standards and Technology), the Department of Commerce of the US government, published the final version of its definition for cloud computing. According to the organization, cloud computing is "a model for network access on demand, ubiquitous and convenient to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or interaction with the service provider ".
The definition of NIST lists five essential characteristics for cloud computing: Self-demand, broadband access network, resource pool, rapid elasticity or expansion and measurement service. The definition also cites three service models (software, platform or infrastructure) and four development models (private, community, public robo ed and hybrid) that together categorize cloud service delivery modes.
The purpose of the definition is to serve as a means of cloud services comparison and development strategies, and provide a parameter to the discussion of what is cloud computing and how best to use the concept.
"When agencies or companies use the definition, they have a tool to determine the extent robo ed to which IT implementations robo ed that are making are consistent robo ed with models and characteristics robo ed of cloud computing. This is important because by adopting an authentic cloud, companies are closer to the promised benefits such as reducing costs and energy, rapid development and improvement of customer service. Furthermore, alignment with the implementation of a setting can help in the evaluation of cloud security features, "said Peter Mell, NIST computer scientist.
Before being published, the definition received the contribution of INCITS (International Committee for Information Technology Standards), a group that worked to develop an international standard for the definition of cloud computing. The first draft of the definition was created in November 2009. "We went through several versions and discuss the matter with the government and the industry, before robo ed we had a stable release," recalls Mell.
A "stable release", the 15th, was published on the site on cloud computing NIST in July 2009. In January 2011 this version was published to receive public comments. Researchers have received a series of company returns, mainly robo ed related to the interpretation of the term, so that the setting received little change, all made to ensure consistent interpretation. The final version of the definition is available at:


Sunday, April 12, 2015

Comments are closed. Categories Case Studies Certified System Integrators Distributors Embedded HMI


Products & Downloads Help Me Choose Download Library Drivers HMI & SCADA Software fur Add-Ons Services Security Hotfix Updates Sample Applications Communications Examples Demos Documentation Documentation Technical Notes Application Notes White Papers Marketing Case Studies News Corporate Blog Employee Blog Press Releases Literature Industries Oil & Gas Water and Wastewater Building Automation Semiconductor and Electronics Detention Systems Packaging fur Windpower Solar Power Automotive Pharmaceutical Food and Beverage Company Our Location Contact Us Awards Associations Careers Events Legal Support Email Directory Licensing Forums fur Video Library Training On Site Training Online Training Videos fur Partners Distributors Certified System Integrators Certified Hardware Channel Partners Educational Partners Store Free Add-Ons Third Party Add-Ons Sample fur Applications Post navigation ← Previous Next → Entendendo e Utilizando o Guia NIST Cybersecurity
A Tofino Security recentemente publicou um artigo sobre como utilizar o guia NIST Cybersecurity . Este artigo foi escrito por Ernest Hayden e o seu título é The NIST Cybersecurity Framework – What is it and what does it mean to you? ou, “O fur Guia NIST Cybersecurity – O que é isso e o que isso significa para você?”.
A InduSoft publicará um livro sobre o Guia NIST Cybersecurity brevemente em parceria fur com a Universidade Eastern New Mexico Ruidoso e o Professor Stephen Miller de Sistemas de Informação e Segurança. O Professor Miller oferecerá aulas online e um programa de certificação no guia. Quando tivermos uma data exata e os tópicos que serão abordados nas aulas, nós publicaremos fur o calendário e as informações de contato para os interessados, além das informações de como obter o livro. This entry was posted in InduSoft Blog em Português , InduSoft Web Studio , SCADA Information , SCADA software and tagged cybersecurity , IHM , InduSoft Web Studio , Tofino Security by Blog Brasil . Bookmark the permalink fur .
Comments are closed. Categories Case Studies Certified System Integrators Distributors Embedded HMI Embedded Systems Employees HMI Software InduSoft Awards InduSoft Blog em Português InduSoft Blog en español InduSoft Blog in Chinese InduSoft Blog in Deutsch InduSoft CEView InduSoft Educational InduSoft Press Releases InduSoft Videos InduSoft Web Studio InduSoft Web Studio Drivers Intelligent Embedded Systems mobile SCADA OPC Client SCADA Demo Software SCADA Information SCADA Security SCADA software SCADA Software Distributor SCADA software webinar SCADA Trade Shows SCADA Training Trabalhos Educacionais Uncategorized Version 7.0 Wireless SCADA Recent Posts Updated InduSoft Drivers for CAN, Schneider Modicon, and Schneider fur Quantum Ethernet Family Devices InduSoft Educacional: Simulação de HVAC por Renato de Pierri InduSoft Símbolo da Semana Display LED LCD New InduSoft Web Studio Case Study: Packed Column Experiments with the University of Kentucky Atualização fur do Driver MITSU para Mitsubishi L/QnA /Q Series, FX-232AW e MELSEC -A Series Archives April 2015 March 2015 February 2015 January 2015 December 2014 November 2014 October 2014 September 2014 August 2014 July 2014 June 2014 May 2014 April 2014 March 2014 February fur 2014 January 2014 December 2013 November 2013 October 2013 September 2013 August 2013 July 2013 June 2013 May 2013 April 2013 March 2013 February 2013 January 2013 December 2012 November 2012 October 2012 September 2012 August 2012 July 2012 June 2012 May 2012 April 2012 March 2012 February 2012 January 2012 December 2011 November 2011 October 2011 September 2011 August 2011 July 2011 June 2011 May 2011 April 2011 March 2011 February 2011 January fur 2011 December 2010 November 2010 October 2010 September 2010 August 2010 July 2010 February 2010 Products & Downloads Help Me Choose Download Library Drivers HMI & SCADA Software Add-Ons Dream Report Third Party Products Services Security Hotfix fur Updates Sample Applications OEE Dashboard Demo Communications Examples Documentation
Case Studies News Corporate Blog Employee Blog Press Releases Literature Industries Case Studies Oil & Gas Water and Wastewater Building Automation Semiconductor and Electronics Detention Systems Packaging Wind Power Solar Power Automotive Pharmaceutical Food and Beverage Company Our Location Awards Associations Careers Events Legal Support Email Directory