<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Static in the Ether &#187; Vizualization</title>
	<atom:link href="http://lair.moria.org/blog/archives/tag/vizualization/feed" rel="self" type="application/rss+xml" />
	<link>http://lair.moria.org/blog</link>
	<description>Unix, Information Security &#38; Systems Administration</description>
	<lastBuildDate>Thu, 10 Feb 2011 21:44:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>Internet Attack Barometer</title>
		<link>http://lair.moria.org/blog/archives/205</link>
		<comments>http://lair.moria.org/blog/archives/205#comments</comments>
		<pubDate>Tue, 30 Jun 2009 08:16:51 +0000</pubDate>
		<dc:creator>Barry Irwin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Systems Administration]]></category>
		<category><![CDATA[Vizualization]]></category>
		<category><![CDATA[Network Telescope]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://lair.moria.org/blog/?p=205</guid>
		<description><![CDATA[Interoute has launched a new online Internet Barometer detailing attacks as observed from their 22 monitoring stations across the European portion of the Internet. The site provides rich graph and chart interfaces, which are nicely interactive.  There are definatley some ideas I want to incorporate form this into my own Network Telescope management console.  It [...]]]></description>
			<content:encoded><![CDATA[<p>Interoute has launched a new online <a href="http://barometer.interoute.com/barom_main.php" target="_blank">Internet Barometer</a> detailing attacks as observed from their 22 monitoring stations across the European portion of the Internet.</p>
<p>The site provides rich graph and chart interfaces, which are nicely interactive.  There are definatley some ideas I want to incorporate form this into my own Network Telescope management console.  It is however worth bearing in mind that his is a Eurocentric view and is only based on their observed traffic. As such the &#8220;<a href="http://barometer.interoute.com/barom_attack_from.php">attacking countries</a>&#8221; view seems to be a bit skewed.</p>
<div id="attachment_206" class="wp-caption aligncenter" style="width: 310px"><a href="http://lair.moria.org/blog/wp-content/uploads/2009/06/map5.jpeg" rel="lightbox"><img class="size-medium wp-image-206" title="world_map" src="http://lair.moria.org/blog/wp-content/uploads/2009/06/map5-300x191.jpg" alt="Interoute World view 2009-06-30" width="300" height="191" /></a><p class="wp-caption-text">Interoute World view 2009-06-30</p></div>
<p>After digging around with squid and wireshark, its evident that a lot of the data is actually served up as XML files, and as such can potentially be postprocessed. The Adobe AIR <a href="http://barometer.interoute.com/widget">Barometer Widget</a> they provide also makes use of these. One issue I had getting this installed is you need Air 1.5.1, and the 1.0.8 version I had wouldn&#8217;t auto upgrade correctly.  A little disappointing in that I was expecting a map view, it provides the basics of a total count and cycles through various country stats.</p>
<div id="attachment_207" class="wp-caption aligncenter" style="width: 278px"><a href="http://lair.moria.org/blog/wp-content/uploads/2009/06/widget1.PNG"  rel="lightbox"><img class="size-full wp-image-207" title="Widget Sample" src="http://lair.moria.org/blog/wp-content/uploads/2009/06/widget1.PNG" alt="Interroute Barometer Widget" width="268" height="182" /></a><p class="wp-caption-text">Interoute Barometer Widget</p></div>
<p>Where the real value  comes form is having another independent source of reporting ( even at the highly granular level) that can be used to correlate observations with my own data sets, and those available form places like dShield and ISC. Maybe I should dust off my old Infocon alert plugin for Firefox and integrate some of this data.</p>
]]></content:encoded>
			<wfw:commentRss>http://lair.moria.org/blog/archives/205/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Visualizing Viruses</title>
		<link>http://lair.moria.org/blog/archives/51</link>
		<comments>http://lair.moria.org/blog/archives/51#comments</comments>
		<pubDate>Thu, 12 Jun 2008 06:45:03 +0000</pubDate>
		<dc:creator>Barry Irwin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Vizualization]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://lair.moria.org/blog/?p=51</guid>
		<description><![CDATA[Wired has a article on the Artwork done by MIT Media Lab&#8217;s grad student Alex Dragulescu. Working under contract to MessageLabs he has produced a number number of pictures, showing images of Mydoom, Ghost Keylogger and other bits of Malware. While all quite pretty there seems to be no detail of how they were created [...]]]></description>
			<content:encoded><![CDATA[<p>Wired has a article on the Artwork done by MIT Media Lab&#8217;s grad student <a title="Alex Dragulescu Homepage" href="http://www.sq.ro/">Alex Dragulescu</a>. Working under contract to  MessageLabs he has produced a number  number of <a href="http://www.wired.com/politics/security/multimedia/2008/04/gallery_viruses">pictures</a>,  showing images of Mydoom, Ghost Keylogger and other bits of Malware.<br />
While all quite pretty there seems to be no detail of how they were created in the original post although the <a href="http://www.sq.ro/malwarez.php">MalWarez</a> link on his homepage describes the process as follows:</p>
<blockquote><p>..For each piece of disassembled code, API calls, memory addresses and subroutines are tracked and analyzed. Their frequency, density and grouping are mapped to the inputs of an algorithm that grows a virtual 3D entity.</p></blockquote>
<p>The <a title="Storm Worm Vizualisation" href="http://www.sq.ro/viewer.php?i=125">Storm Worm</a> is probably my favorite visualizations. He also has an interesting set of images entitled <a href="http://www.sq.ro/spamplants.php">SpamPlants</a>, based on input relating to the ASCII character frequency of spam messages.</p>
<p>Now this sounds like a great project for an aspiring security researcher with a graphical bent.</p>
]]></content:encoded>
			<wfw:commentRss>http://lair.moria.org/blog/archives/51/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

