SubZero: Cyber Crime Risk Management Blog
The SubZero: Cyber Crime Risk Management Blog will examine and explore global cyber crime trends, threat intelligence, risk management, advanced persistent threats and more.

Enterprise security intelligence: 3 steps to get started

To secure your enterprise, you must have an integrated view of your data and IT systems at all times. By establishing enterprise security intelligence (ESI) in your organization as a basis for your security strategy, you’ll enable your team—and your fellow executives—to maintain a clear, universal view of the organization’s security and risk management profile.

Is Your Organization Smart Enough to Outsmart the Threat Landscape?

Achieving Security through Greater Intelligence


As enterprise IT infrastructures continue to morph and grow, taking on new and exciting characteristics such as “cloud computing” and ever increasing mobility, so too does the risk posed by cyber criminals and industrial espionage agents.  It’s 2012 folks, though some of the things I write about sound like they bounced off the pages of a Clancy or Ludlum novel I can assure, they are all too real and implications to brand and risk posture is great.  The greatest threat comes in the form of the human being. 

Forensics in the Cloud

Yesterday I received an interesting call asking for my opinions on Cloud Computing and Forensics.  I don’t consider myself a ‘Cloud’ guy.  I’m a security guy with a lot of experience in forensics and incident response, among other things, so this call intrigued me. Raf Los

Zen and the art of Defeating Malware: Japan's CyberWeapon Exposed

Proactive Approach to an Unprovoked Threat


Japan has thrown down the gauntlet.  A bold move was reported publicly on the wire January 2, 2012 on the part of the Japanese government and their partner, Fujitsu Systems.  The plan was to develop a cyberweapon that has the ability to track, identify and disable sources of online attacks.  Simple right?  Let’s take a closer look. 

H0 H0 N0! I’ve been P0WN3D for the H0l1D@Y5!

The holiday season is upon us.  It’s a time to reflect and consider all that year has brought us; the good, the bad, the happy the sad and be thankful for those things we’re fortunate to share with our family, friends, and neighbors.  It’s also a time for sending carefully crafted notes, letters and cards to those same loved ones providing them with a review of our lives (and those of our families) in addition to season’s greetings.  It’s also a time to be weary.  Weary? That’s an odd choice of word for looks to be a festive blog post isn’t it?  Well yes and no.  I think it’s appropriate and here’s why. 

Cha-Cha-DNS-Changes...The "DNS Changer" Botnet and You!

A little more than a month ago the U.S. Department of Justice announced what has been called the largest botnet takedown in history.  Many people failed to notice the events that were described by the U.S. DoJ however I feel it’s important revisit it.  This botnet was different.  It was roughly twice the size of the Rustock botnet which you may recall was taken down by Microsoft attorneys and U.S. Marshalls.  At its peak, Rustock consisted of approximately 1.6 million compromised hosts with command and control servers being hosted by five different web hosting providers in seven different U.S. cities.  The botnet that was taken down in November has been dubbed the “DNS Changer” botnet and consisted of more than 4 million compromised systems. 

Ferris Bueller, cyber- crime, Risk Management and the search for Truth in Security

This is a great day!  It’s November 11, 2011, and this marks the first installment y for my new blog here at HP Software, SubZERO: The Cyber Crime and Risk Management Blog.  I’m thrilled to be in the Captain’s chair charting a new course for us to follow as we set off in search of truth, not FUD!

About the Author(s)
  • Judy Redman has been writing about all areas of technology for more than 20 years.
  • Will Gragido is the product line manager for HP DVLabs with oversight over the various DV related services and other DVLabs projects. Will has deep expertise and knowledge in operations, vulnerability and threat analysis, management, professional services & consultancy, pre-sales / architecture and business development within the information security industry. Prior to HP TippingPoint, Will has worked extensively with McAfee, Internet Security Systems, International Network Services and the United States Marine Corps. Will is a long standing member of the ISC2, ISACA, and ISSA. Will holds the CISSP and CISA certifications, as well as accreditations in the National Security Agency's Information Security Assessment Methodology (IAM) and Information Security Evaluation Methodology (IEM). He resides in the Chicagoland area, is a graduate of DePaul University and is currently preparing for graduate school. Will is an active speaker who has been featured at conferences such as Toorcon, Security BSides, and SANS. Additionally, Will is currently authoring a book for Syngress Press on Cybercrime and Espionage due out in the Spring of 2011. Appearances: Beyond IPS 2011-10-17 SecTor The Rise of the Chaotic Actor: Adapting to the Age of Anonymous 2011-10-13 RSA Europe 2011 The Modern Threat Landscape and Our Ability to React Intelligently 2011-02-15 Security B-Sides SanFran The Threat Landscape 2010-09-09 ISSA Chicago Through the rabbit hole: An Expose of Darknets and the Onion Routed Underground 2010-07-31 Security BSides Blog Entries Hammer of the Botgods: A New Variant of the ZeuS Botnet May Be Upon Us created 2011-04-06 (0 comments, 3699 views) Has Sapphire ‘Slammed’ Itself Out of Existence? created 2011-03-28 (1 comments, 3753 views) DoS and DDoS Yesterday and Today created 2011-02-28 (1 comments, 4990 views) Obfuscated Attacks: What You Can't See Will Hurt You created 2011-02-24 (0 comments, 3014 views) Network Forensics: A New Era of Visibility created 2011-02-23 (1 comments, 2984 views) Slaying The Dragon: An Analysis of the 'Night Dragon' Attack created 2011-02-10 (1 comments, 5405 views) Blackhatnomics ™ created 2010-09-28 (0 comments, 4235 views) Elegant Worm: How Stuxnet Is Redefining The Game created 2010-09-23 (2 comments, 4716 views)


Follow Us