<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7652481.post114666570574415909..comments</id><updated>2012-02-21T00:57:21.589-05:00</updated><category term='MySQL'/><category term='Tor'/><category term='NSM'/><category term='dns'/><category term='Snort'/><category term='book review'/><category term='Sguil'/><category term='apt'/><category term='hacking'/><category term='Perl'/><category term='Events'/><category term='WTF?'/><category term='OSSEC'/><category term='management'/><title type='text'>Comments on Infosec Potpourri: A traffic-analysis approach to detecting DNS tunne...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.vorant.com/feeds/114666570574415909/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/114666570574415909/comments/default'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2006/05/traffic-analysis-approach-to-detecting.html'/><author><name>David Bianco</name><uri>http://www.blogger.com/profile/09760835714791462863</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7652481.post-114670871992127081</id><published>2006-05-03T22:11:00.000-04:00</published><updated>2006-05-03T22:11:00.000-04:00</updated><title type='text'>Thanks, though I can't take the credit for the ide...</title><content type='html'>Thanks, though I can't take the credit for the idea of traffic analysis, or even for analysis to detect DNS tunnels.  I do think it's the most general solution, though.  The trick is finding the right type of analysis. &lt;BR/&gt;&lt;BR/&gt;In fact, I've been set straight about an error I made interpreting the DNS protocol, so I'm working on a couple of other possible ideas now, even involving some basic statistical analysis.  It's not my area of specialty (yet??) but I hope to have more to report soon.v</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/114666570574415909/comments/default/114670871992127081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/114666570574415909/comments/default/114670871992127081'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2006/05/traffic-analysis-approach-to-detecting.html?showComment=1146708660000#c114670871992127081' title=''/><author><name>David Bianco</name><uri>http://www.blogger.com/profile/09760835714791462863</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2006/05/traffic-analysis-approach-to-detecting.html' ref='tag:blogger.com,1999:blog-7652481.post-114666570574415909' source='http://www.blogger.com/feeds/7652481/posts/default/114666570574415909' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2136160136'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-114669889858015011</id><published>2006-05-03T19:28:00.000-04:00</published><updated>2006-05-03T19:28:00.000-04:00</updated><title type='text'>Fsking brilliant.  &lt;br&gt;&lt;br&gt;No matter what they do,...</title><content type='html'>Fsking brilliant.  &lt;BR/&gt;&lt;BR/&gt;No matter what they do, they'll stand out by some means or other.  I can see this approach applied in all sorts of ways.  Nice work!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/114666570574415909/comments/default/114669889858015011'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/114666570574415909/comments/default/114669889858015011'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2006/05/traffic-analysis-approach-to-detecting.html?showComment=1146698880000#c114669889858015011' title=''/><author><name>JimmytheGeek</name><uri>http://www.blogger.com/profile/07443526997444888294</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2006/05/traffic-analysis-approach-to-detecting.html' ref='tag:blogger.com,1999:blog-7652481.post-114666570574415909' source='http://www.blogger.com/feeds/7652481/posts/default/114666570574415909' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1076843725'/></entry></feed>
