<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://unam.honeynet.org" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>French  Chapter</title>
 <link>http://unam.honeynet.org/chapters/france</link>
 <description>French Chapter, led by Sebastien Tricaud</description>
 <language>en</language>
<item>
 <title>Know Your Tools: use Picviz to find attacks</title>
 <link>http://unam.honeynet.org/node/500</link>
 <description>We are very excited to announce the publication of our first paper in the new Know Your Tools paper series: “KYT: use Picviz to find attacks” authored by Sebastien Tricaud from the French Chapter and Victor Amaducci from the University of Campinas. &lt;br/&gt;
&lt;br/&gt;
The paper can be downloaded at &lt;a href=&quot;https://www.honeynet.org/node/499&quot;&gt;Know Your Tools: use Picviz to find attacks&lt;/a&gt;.&lt;br/&gt;
&lt;br/&gt;
&lt;em&gt;Paper Abstract&lt;br/&gt;
Picviz is a parallel coordinates plotter which enables easy scripting from various input (tcpdump, syslog, iptables logs, apache logs, etc..) to visualize data and discover interesting aspects of that data quickly. Picviz uncovers previously hidden data that is difficult to identify with traditional analysis methods.&lt;br/&gt;
&lt;br/&gt;
In the first paper of our new Know Your Tools series, Sebastien Tricaud from the French Honeynet Project Chapter and Victor Amaducci from the University of Campinas, focus on Picviz. After a brief overview on parallel coordinates, Picviz architecture, and installation procedure, three real-world examples are presented that illustrate how to identify attacks from large amounts of data: Picviz is used to analyze SSH logs, Apache access logs and network traffic. With these examples, it is demonstrated how Picviz can find attacks that previously have been hidden.
 &lt;/em&gt;&lt;br/&gt;
&lt;br/&gt;
Recent additions to Picviz GUI have been made by Victor Amaducci under the mentorship of Sebastien Tricaud as part of the Google Summer of Code program 2009. The most recent version of Picviz is freely available for download from its project site at &lt;a href=&quot;http://www.wallinfire.net/picviz&quot;&gt;http://www.wallinfire.net/picviz&lt;/a&gt; and support can be sought from the Picviz mailing list at &lt;a href=&quot;http://www.wallinfire.net/cgi-bin/mailman/listinfo/picviz&quot;&gt;http://www.wallinfire.net/cgi-bin/mailman/listinfo/picviz&lt;/a&gt;..&lt;br/&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/france&quot; class=&quot;og_links&quot;&gt;French  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://unam.honeynet.org/chapters/france" xmlns="http://drupal.org/project/og">French  Chapter</group>
 <category domain="http://unam.honeynet.org/taxonomy/term/113">KYE</category>
 <category domain="http://unam.honeynet.org/taxonomy/term/114">KYT</category>
 <category domain="http://unam.honeynet.org/taxonomy/term/24">picviz</category>
 <pubDate>Thu, 26 Nov 2009 12:27:54 -0500</pubDate>
 <dc:creator>christian.seifert</dc:creator>
 <guid isPermaLink="false">500 at http://unam.honeynet.org</guid>
</item>
<item>
 <title>Picviz 0.5 out</title>
 <link>http://unam.honeynet.org/node/346</link>
 <description>The new release 0.5 of Picviz is out. This version comes with real-time mode enabled (and adds the libevent dependency) among other things, such as new properties and variables.

Get it from &lt;a href=&quot;http://www.wallinfire.net/picviz&quot;&gt;the usual place&lt;/a&gt;.

&lt;strong&gt;What is Picviz?&lt;/strong&gt;
&lt;p&gt;
When considering log files for security, usual applications available today
either look for patterns using signature databases or use a behavioral
approach. In both cases, information can be missed. The problem becomes
bigger with systems receiving a massive amount of logs.
&lt;/p&gt;&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/france&quot; class=&quot;og_links&quot;&gt;French  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://unam.honeynet.org/chapters/france" xmlns="http://drupal.org/project/og">French  Chapter</group>
 <category domain="http://unam.honeynet.org/taxonomy/term/24">picviz</category>
 <category domain="http://unam.honeynet.org/taxonomy/term/25">visualization</category>
 <pubDate>Sun, 25 Jan 2009 08:23:53 -0500</pubDate>
 <dc:creator>sebastien.tricaud</dc:creator>
 <guid isPermaLink="false">346 at http://unam.honeynet.org</guid>
</item>
<item>
 <title>French Chapter - Chapter Status Report For 2008</title>
 <link>http://unam.honeynet.org/node/344</link>
 <description>&lt;p&gt;&lt;strong&gt;ORGANIZATION &lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Changes in the structure of your organization.&lt;/li&gt;
&lt;p&gt;Just like the phoenix, the French Honeynet project resurrected: thanks to attackers not taking any break, making us willing to understand what&#039;s going on. The project re-started in December 2008.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/france&quot; class=&quot;og_links&quot;&gt;French  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://unam.honeynet.org/node/344&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://unam.honeynet.org/chapters/france" xmlns="http://drupal.org/project/og">French  Chapter</group>
 <pubDate>Sat, 24 Jan 2009 17:42:05 -0500</pubDate>
 <dc:creator>sebastien.tricaud</dc:creator>
 <guid isPermaLink="false">344 at http://unam.honeynet.org</guid>
</item>
<item>
 <title>My usenix WASL 2008 slides are available</title>
 <link>http://unam.honeynet.org/node/260</link>
 <description>&lt;p&gt;I gave a lecture on Picviz during &lt;a href=&quot;http://www.usenix.org/events/wasl08/tech/&quot;&gt;the Usenix Workshop on the Analysis of System Logs&lt;/a&gt; (WASL 2008).&lt;/p&gt;
&lt;p&gt;My slides &#039;Picviz: finding a needle in a haystack&#039; are &lt;a href=&quot;http://www.wallinfire.net/files/picviz-usenix-wasl2008.pdf&quot;&gt;available right here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I also ran for the Cray log analysis contest analysis. Slides of stuff I discovered are &lt;a href=&quot;http://www.wallinfire.net/files/wasl2008-craylog-contest.pdf&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/france&quot; class=&quot;og_links&quot;&gt;French  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description>
 <group domain="http://unam.honeynet.org/chapters/france" xmlns="http://drupal.org/project/og">French  Chapter</group>
 <pubDate>Mon,  8 Dec 2008 12:59:07 -0500</pubDate>
 <dc:creator>sebastien.tricaud</dc:creator>
 <guid isPermaLink="false">260 at http://unam.honeynet.org</guid>
</item>
<item>
 <title>About The Honeynet Project</title>
 <link>http://unam.honeynet.org/about</link>
 <description>&lt;p&gt;Founded in 1999, The Honeynet Project is an international, non-profit (501c3) research organization dedicated to improving the security of the Internet at no cost to the public. With Chapters around the world, our volunteers are firmly committed to the ideals of OpenSource. Our goal, simply put, is to make a difference. We accomplish this goal in the following three ways.  &lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/chicago&quot; class=&quot;og_links&quot;&gt;Chicago  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://unam.honeynet.org/about&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://unam.honeynet.org/chapters/westpoint" xmlns="http://drupal.org/project/og">West Point Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/uncc" xmlns="http://drupal.org/project/og">UNCC Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/unam" xmlns="http://drupal.org/project/og">UNAM Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/uk" xmlns="http://drupal.org/project/og">UK Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/taiwan" xmlns="http://drupal.org/project/og">Taiwan Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/spartandevils" xmlns="http://drupal.org/project/og">Spartan Devils Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/spain" xmlns="http://drupal.org/project/og">Spanish Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/singapore" xmlns="http://drupal.org/project/og">Singapore Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/portugal" xmlns="http://drupal.org/project/og">Portuguese Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/philippines" xmlns="http://drupal.org/project/og">Philippines Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/pakistan" xmlns="http://drupal.org/project/og">Pakistan Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/orangecounty" xmlns="http://drupal.org/project/og">Orange County  Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/norway" xmlns="http://drupal.org/project/og">Norwegian Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/newzealand" xmlns="http://drupal.org/project/og">New Zealand Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/mexico" xmlns="http://drupal.org/project/og">Mexican Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/malaysia" xmlns="http://drupal.org/project/og">Malaysian Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/hongkong" xmlns="http://drupal.org/project/og">Hong Kong Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/hawaii" xmlns="http://drupal.org/project/og">Hawaiin Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/global" xmlns="http://drupal.org/project/og">Global Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/germany" xmlns="http://drupal.org/project/og">German Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/france" xmlns="http://drupal.org/project/og">French  Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/czech" xmlns="http://drupal.org/project/og">Czech Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/malaysia2" xmlns="http://drupal.org/project/og">CyberSecurity Malaysia Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/canada" xmlns="http://drupal.org/project/og">Canadian Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/brazil" xmlns="http://drupal.org/project/og">Brazilian  Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/australia" xmlns="http://drupal.org/project/og">Australian  Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/alaska" xmlns="http://drupal.org/project/og">Alaskan  Chapter</group>
 <group domain="http://unam.honeynet.org/chapters/chicago" xmlns="http://drupal.org/project/og">Chicago  Chapter</group>
 <pubDate>Sun, 10 Aug 2008 20:54:48 -0400</pubDate>
 <dc:creator>drupal</dc:creator>
 <guid isPermaLink="false">67 at http://unam.honeynet.org</guid>
</item>
</channel>
</rss>
