<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		
		<title>PreludeIDS Technologies</title>
		<link>http://www.prelude-ids.com/</link>
		<description>PreludeIDS Feeds</description>
		<language>en</language>
		<image>
			<title>PreludeIDS Technologies</title>
			<url>http://www.prelude-ids.com/EXT:tt_news/ext_icon.gif</url>
			<link>http://www.prelude-ids.com/</link>
			<width></width>
			<height></height>
			<description>PreludeIDS Feeds</description>
		</image>
		<generator>TYPO3 - get.content.right</generator>
		<docs>http://blogs.law.harvard.edu/tech/rss</docs>
		
		
		
		<lastBuildDate>Fri, 19 Sep 2008 19:57:00 +0200</lastBuildDate>
		
		
		<item>
			<title>Libprelude, the Prelude library, now compile and run under Win32 native!</title>
			<link>http://www.prelude-ids.com/en/news/article/libprelude-la-bibliotheque-prelude-compile-et-sexecute-maintenant-nativement-sur-systeme-win32/index.html</link>
			<description>The new Libprelude version 0.9.21 is compatible with the Windows operating system. 

It allows...</description>
			<content:encoded><![CDATA[<p class="bodytext"><b>The new Libprelude version 0.9.21 is compatible with the Windows operating system. </b></p>
<p class="bodytext">&nbsp;</p>
<p class="bodytext">It allows connecting sensors from Windows systems, or to create your own Prelude sensors for this platform. </p>
<p class="bodytext">By installing libprelude on a Windows system, your Windows sensors will be able to send their events to a remote Prelude-Manager. </p>
<p class="bodytext">Reported events (Windows / Unix) will be correlated together, thanks to Prelude-Correlator, and visualized in the Prewikka interface.<br /><br /><br /></p>]]></content:encoded>
			<category>Développement</category>
			
			
			<pubDate>Fri, 19 Sep 2008 19:02:00 +0200</pubDate>
			
		</item>
		
		<item>
			<title>Prelude Conference at the 2008 LSM</title>
			<link>http://www.prelude-ids.com/en/news/article/conference-prelude-aux-rmll-2008/index.html</link>
			<description>&quot;The LSM (Libre Software Meeting) are an opportunity for all sort of public to come together...</description>
			<content:encoded><![CDATA[<p class="bodytext">&quot;<i>The LSM (Libre Software Meeting) are an opportunity for all sort of public to come together around the free software. Over 5 days, conferences and workshops welcome everyone. This event is organized each year and for the 9th edition is hosted in the town of Mont de Marsan, from 1 to 5 July 2008.</i>&quot; <a href="http://2008.rmll.info/?lang=en" title="Opens external link in new window" target="_blank" class="external-link-new-window" >From the LSM Website</a></p>
<p class="bodytext">&nbsp;</p>
<p class="bodytext">On July 2008, for the 2008 LSM, Yoann Vandoorselaere, Prelude creator and PreludeIDS Technologies CTO, will give  a talk entitled &quot;Prelude, State of the Art&quot;.</p>
<p class="bodytext">In this talk, in english, we will introduce the Prelude system and describe the current state of the art: correlation, new programming interface suitable for scripting languages, and individuals improvements made to each Prelude modules.</p>
<p class="bodytext">&nbsp;</p>
<p class="bodytext"><b>See Also:</b></p><ul><li><a href="http://2008.rmll.info/?lang=en" title="Opens external link in new window" target="_blank" class="external-link-new-window" >The 2008 LSM Website</a></li><li><a href="fileadmin/templates/pdf/RMLL_2008.pdf" title="Initiates file download" target="_top" class="download" >The &quot;Prelude, State of the art&quot; talk</a> (pdf)</li><li><a href="en/development/community/index.html#c938" title="Opens internal link in current window" target="_top" class="internal-link" >All Prelude conferences</a></li></ul>]]></content:encoded>
			<category>Agenda</category>
			
			
			<pubDate>Wed, 02 Jul 2008 14:45:00 +0200</pubDate>
			
		</item>
		
		<item>
			<title>Prelude-Correlator Beta1 release</title>
			<link>http://www.prelude-ids.com/en/news/article/sortie-de-prelude-correlator-beta1/index.html</link>
			<description>PreludeIDS Technologies is proud to announce the first Prelude-Correlator beta...</description>
			<content:encoded><![CDATA[<p class="bodytext">PreludeIDS Technologies is proud to announce the first Prelude-Correlator beta release.</p>
<p class="bodytext">Prelude-Correlator serves to correlate, in real time, the multiple events received by Prelude. Several isolated alerts, generated from different sensors, can thus trigger a single correlation alert should the events be related. This correlation alert then appears within the Prewikka interface and indicates the potential target information via the set of correlation rules. </p>
<p class="bodytext">Signature creation with Prelude-Correlator is based on the powerful programming language Lua.</p><ul><li>See the <a href="en/solutions/correlation-engine/index.html" title="Opens internal link in current window" target="_top" class="internal-link" >Correlation Engine</a> page</li><li><a href="en/development/download/index.html" title="Opens internal link in current window" target="_top" class="internal-link" >Download</a> Prelude-Correlator</li></ul><p class="bodytext">&nbsp;</p>
<p class="bodytext">&nbsp;</p>]]></content:encoded>
			<category>Développement</category>
			
			
			<pubDate>Fri, 27 Jun 2008 13:28:00 +0200</pubDate>
			
		</item>
		
		<item>
			<title>The Mail Reporting plugin now open source!</title>
			<link>http://www.prelude-ids.com/en/news/article/le-mail-reporting-plugin-maintenant-disponible-en-open-source/index.html</link>
			<description>The commercial extension Mail Reporting plugin is now open source! This functionality is now...</description>
			<content:encoded><![CDATA[<p class="bodytext">The commercial extension Mail Reporting plugin is now open source! This functionality is now integrated to Prelude-Manager starting from version 0.9.13.</p>
<p class="bodytext">&nbsp;</p>
<p class="bodytext">The Mail Reporting Plugin automatically sends emails containing a textual description of events reported to Prelude to a configured list of recipients. The body of the generated email can be the full event, or specific part of it by using a customized template.</p>
<p class="bodytext">Additionally, this plugin is optionally capable of querying the Prelude database in order to include information concerning older events tied to an incoming event. </p>
<p class="bodytext">Using the Mail Reporting Plugin in combination with Prelude-Manager filtering functionality, it is possible to generate email only on events matching specific criteria or threshold. </p>
<p class="bodytext">&nbsp;</p>
<p class="bodytext"><a href="en/development/download/index.html" title="Opens internal link in current window" target="_top" class="internal-link" >Download Prelude-Manager 0.9.13.</a></p>
<p class="bodytext">&nbsp;</p>]]></content:encoded>
			<category>Développement</category>
			
			
			<pubDate>Fri, 27 Jun 2008 13:34:00 +0200</pubDate>
			
		</item>
		
		<item>
			<title>Launch of the new Prelude Website</title>
			<link>http://www.prelude-ids.com/en/news/article/sortie-du-nouveau-site-internet-prelude/index.html</link>
			<description>The new Prelude Website is online. 
The Prelude team has updated its communication and knowledge...</description>
			<content:encoded><![CDATA[<p class="bodytext"><b>The new Prelude Website is online. </b></p>
<p class="bodytext">The Prelude team has updated its communication and knowledge sharing tool and will now feature a revised format, new articles and an improved organization of headings to make the browsing experience smoother and more effective. </p>
<p class="bodytext">&nbsp;</p>
<p class="bodytext">Yet <b>the fundamental change lies in merging the Prelude-ids.com and Prelude-ids.org sites</b>, in the same objective of streamlining and facilitating the browsing experience. The content of the Prelude Project site will be completely integrated and directly accessible via a heading entitled &quot;Development&quot;. The merger will come about naturally; former site users will not feel lost and new visitors will find their visit to the site an enjoyable one. </p>
<p class="bodytext">&nbsp;</p>
<p class="bodytext">The launch of this site will also provide the occasion to refresh and enhance some of the most practical content, including the site's documentation features. Number of original headings and functionality should also make their way onto the site. </p>
<p class="bodytext">&nbsp;</p>
<p class="bodytext">We hope you'll find this updated site every bit as attractive as the Prelude team has tried to make it. Should you have any comments or wish to correct any site content, please feel free to contact: <a href="mailto:webmaster@prelude-ids.com" title="Opens window for sending email" class="mail" >webmaster@prelude-ids.com</a></p>
<p class="bodytext">&nbsp;</p>]]></content:encoded>
			<category>Entreprise</category>
			
			
			<pubDate>Thu, 26 Jun 2008 13:53:00 +0200</pubDate>
			
		</item>
		
		<item>
			<title>INL-PreludeIDS Breakfast conference at ’Arts-et-Métiers’ museum, Paris, France</title>
			<link>http://www.prelude-ids.com/en/news/article/petit-dejeuner-conference-inl-preludeids-au-musee-des-arts-et-metiers/index.html</link>
			<description>On monday march 18 2008, INL and PreludeIDS organized a Breakfast Conference on the subject: Make...</description>
			<content:encoded><![CDATA[<p class="bodytext">On monday march 18 2008, <a href="http://www.inl.fr" target="_blank" class="external-link-new-window" >INL</a> and PreludeIDS organized a Breakfast Conference on the subject: Make your security solutions cooperate: Increase your efficiency. </p>
<p class="bodytext">The opportunity for both sides to present new opportunities offered by the cooperation between NuFW (Firewall by INL) and Prelude.</p>]]></content:encoded>
			<category>Agenda</category>
			
			
			<pubDate>Tue, 18 Mar 2008 11:48:00 +0100</pubDate>
			
		</item>
		
		<item>
			<title>OpenSource Security - PreludeIDS Partnership Technologies</title>
			<link>http://www.prelude-ids.com/en/news/article/partenariat-opensource-security-preludeids-technologies/index.html</link>
			<description>OpenSource Security becomes PreludeIDS Certified Partner for Germany, United Kingdom, Austria and...</description>
			<content:encoded><![CDATA[<p class="bodytext"><strong><a href="http://www.os-s.net/" target="_blank" class="external-link-new-window" >OpenSource Security</a> becomes PreludeIDS Certified Partner for Germany, United Kingdom, Austria and the Netherlands.</strong> </p>
<p class="bodytext">PreludeIDS is proud to count the OpenSource Security company among its Certified Partners. OpenSource Security is owned by Ralf Spenneberg, an open source security expert. In that capacity, he is the author of several books including « Intrusion Detection und Prevention mit Snort 2 &amp; Co. » (in German) in which he devotes a chapter to the Prelude system. </p>
<p class="bodytext"><a href="en/partners/partners/index.html" target="_top" class="internal-link" >Read the <strong>OpenSource Security</strong> company profile on PreludeIDS website</a></p>
<p class="bodytext">&nbsp;</p>]]></content:encoded>
			<category>Entreprise</category>
			
			
			<pubDate>Tue, 11 Mar 2008 11:22:00 +0100</pubDate>
			
		</item>
		
		<item>
			<title>New prelude sensor: Auditd</title>
			<link>http://www.prelude-ids.com/en/news/article/nouvelle-sonde-prelude-auditd/index.html</link>
			<description>Steve Grubb from Red Hat wrote the prelude plugin for Auditd, the SELinux daemon which logs...</description>
			<content:encoded><![CDATA[<p class="bodytext">Steve Grubb from Red Hat wrote the prelude plugin for Auditd, the SELinux daemon which logs policies violations. </p>
<p class="bodytext">The plugin can currently detect and message: Apps that terminate abnormally (gcc stack overflow/glibc FORTIFY_SOURCE/plain old segfault), SE Linux AVCs, Logins, MAX failed login attempts reached, MAX concurrent sessions reached. This is all done in real-time and not based on a cron job. The audit daemon is capable of being run directly from init if you wanted to do it that way. </p>
<p class="bodytext">The package, installation instructions are available at: <a href="http://people.redhat.com/sgrubb/audit/" target="_blank" class="external-link-new-window" ><br />http://people.redhat.com/sgrubb/audit/</a>. </p>
<p class="bodytext">If you run fedora core 8, you can try it easily by running: </p>
<p class="bodytext">&nbsp;</p>
<p class="csc-frame-frame1">yum --enablerepo=updates-testing install audispd-plugins </p>
<p class="bodytext">&nbsp;</p>
<p class="bodytext">To do testing on Fedora rawhide (which will become Fedora 9), you will need to put selinux in permissive mode, &quot;setenforce 0&quot;. </p>
<p class="bodytext">More information available in Steve’s <a href="http://people.redhat.com/sgrubb/audit/prelude.txt" target="_blank" class="external-link-new-window" >auditd+prelude HOWTO</a>.</p>]]></content:encoded>
			<category>Développement</category>
			
			
			<pubDate>Wed, 06 Feb 2008 12:29:00 +0100</pubDate>
			
		</item>
		
		<item>
			<title>Book: Security Power Tools</title>
			<link>http://www.prelude-ids.com/en/news/article/livre-security-power-tools/index.html</link>
			<description>Prelude among Security Power Tools!</description>
			<content:encoded><![CDATA[<p class="bodytext"><strong>Authors:</strong> Bryan Burns, Jennifer Stisa Granick, Steve Manzuik, Paul Guersch, Dave Killion, Nicolas Beauchesne, Eric Moret, Julien Sobrier, Michael Lynn, Eric Markham, Chris Iezzoni, Philippe Biondi, and Avishai Avivi<em> </em> </p>
<p class="bodytext"><strong>Publisher:</strong> O’Reilly Media </p>
<p class="bodytext"><strong>Publication: </strong>08/2007 </p>
<p class="bodytext"><strong>Pages:</strong> 692 - 694 (Chapter 20.13 : Host Monitoring in Large Environments with Prelude-IDS) </p>
<p class="bodytext"><strong>Description:</strong> What if you could sit down with some of the most talented security engineers in the world and ask any network security question you wanted? Security Power Tools lets you do exactly that! Members of Juniper Networks' Security Engineering team and a few guest experts reveal how to use, tweak, and push the most popular network security applications, utilities, and tools available using Windows, Linux, Mac OS X, and Unix platforms. Designed to be browsed, Security Power Tools offers you multiple approaches to network security via 23 cross-referenced chapters that review the best security tools on the planet for both black hat techniques and white hat defense tactics. It's a must-have reference for network administrators, engineers and consultants with tips, tricks, and how-to advice for an assortment of freeware and commercial tools, ranging from intermediate level command-line operations to advanced programming of self-hiding exploits. Security Power Tools details best practices for: Reconnaissance -- including tools for network scanning such as nmap; vulnerability scanning tools for Windows and Linux; LAN reconnaissance; tools to help with wireless reconnaissance; and custom packet generation Penetration -- such as the Metasploit framework for automated penetration of remote computers; tools to find wireless networks; exploitation framework applications; and tricks and tools to manipulate shellcodes Control -- including the configuration of several tools for use as backdoors; and a review of known rootkits for Windows and Linux Defense -- including host-based firewalls; host hardening for Windows and Linux networks; communication security with ssh; email security and anti-malware; anddevice security testing Monitoring -- such as tools to capture, and analyze packets; network monitoring with Honeyd and snort; and host monitoring of production servers for file changes Discovery -- including The Forensic Toolkit, SysInternals and other popular forensic tools; application fuzzer and fuzzing techniques; and the art of binary reverse engineering using tools like Interactive Disassembler and Ollydbg A practical and timely network security ethics chapter written by a Stanford University professor of law completes the suite of topics and makes this book a goldmine of security information. Save yourself a ton of headaches and be prepared for any network security dilemma with Security Power Tools.</p>
<p class="bodytext"><a href="http://www.oreilly.com/catalog/9780596009632/" target="_blank" class="external-link-new-window" >Publisher website</a></p>]]></content:encoded>
			<category>Revue de Presse</category>
			
			
			<pubDate>Sat, 01 Sep 2007 11:40:00 +0200</pubDate>
			
		</item>
		
		<item>
			<title>New prelude sensor: Ossec</title>
			<link>http://www.prelude-ids.com/en/news/article/nouvelle-sonde-prelude-ossec/index.html</link>
			<description>OSSEC HIDS is a host based intrusion detection system that performs log analysis, integrity...</description>
			<content:encoded><![CDATA[<p class="bodytext"><a href="http://www.ossec.net/" target="_blank" class="external-link-new-window" >OSSEC HIDS</a> is a host based intrusion detection system that performs log analysis, integrity checking, Windows registry monitoring, rootkit detection, real-time alerting and active response. </p>
<p class="bodytext">&nbsp;</p>
<p class="bodytext">It is now able to communicate and use all the features of the Prelude framework. You can find more informations about this in the email that I sent on the mailing list <a href="pipermail/prelude-devel/2007-October/001920.html" target="_top" class="external-link-new-window" >here</a>. </p>
<p class="bodytext">&nbsp;</p>
<p class="bodytext">Please test and report bugs, so that the upcoming release will have a strong and rocking prelude support.</p>]]></content:encoded>
			<category>Développement</category>
			
			
			<pubDate>Fri, 10 Aug 2007 11:55:00 +0200</pubDate>
			
		</item>
		
	</channel>
</rss>