<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>barns.blog &#187; Research</title>
	<atom:link href="http://www.barns.co.za/category/research/feed" rel="self" type="application/rss+xml" />
	<link>http://www.barns.co.za</link>
	<description>Richard Barnett's thoughts on Computing, Culture and Life</description>
	<lastBuildDate>Tue, 15 Sep 2009 17:56:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>2009, An Overview of the Year Ahead</title>
		<link>http://www.barns.co.za/research/masters/2009-an-overview-of-the-year-ahead</link>
		<comments>http://www.barns.co.za/research/masters/2009-an-overview-of-the-year-ahead#comments</comments>
		<pubDate>Sat, 07 Feb 2009 11:35:37 +0000</pubDate>
		<dc:creator>Barns</dc:creator>
				<category><![CDATA[Masters]]></category>
		<category><![CDATA[CISSE]]></category>
		<category><![CDATA[ISSA]]></category>
		<category><![CDATA[journal]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[SAICSIT]]></category>
		<category><![CDATA[SATNAC]]></category>
		<category><![CDATA[sfportscan]]></category>
		<category><![CDATA[Snort]]></category>

		<guid isPermaLink="false">http://www.barns.co.za/?p=177</guid>
		<description><![CDATA[With 2009 already under-way, progress is happening in my Masters at a steady pace. With just under six months to go until the end of July, my work is in full swing, with a mixture of writing, algorithmic construction, testing and other activities. Over the next month, most of the development work should be completed. [...]]]></description>
			<content:encoded><![CDATA[<p>With 2009 already under-way, progress is happening in my Masters at a steady pace. With just under six months to go until the end of July, my work is in full swing, with a mixture of writing, algorithmic construction, testing and other activities. Over the next month, most of the development work should be completed. This is, of course, somewhat dependant on my teaching not getting too much in the way.</p>
<p>Thereafter, my algorithms and the <em>sfPortscan</em> algorithm from Snort will be tested and statistically analysed. Thereafter, I plan on finalising my write-up and handing in.</p>
<p>In the interim, I have plans to submit papers to several conferences during the course of the year, the first list includes ISSA, RAID, SATNAC, SAICSIT and CISSE (in chronological order of submission dates). I also hope to get a journal article out during the course of the year.</p>
<p>So, onward with 2009&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barns.co.za/research/masters/2009-an-overview-of-the-year-ahead/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAICSIT ‘08 &#8211; Part Two</title>
		<link>http://www.barns.co.za/research/papers/saicsit-08-part-two</link>
		<comments>http://www.barns.co.za/research/papers/saicsit-08-part-two#comments</comments>
		<pubDate>Thu, 09 Oct 2008 05:20:44 +0000</pubDate>
		<dc:creator>Barns</dc:creator>
				<category><![CDATA[Papers]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[SAICSIT]]></category>

		<guid isPermaLink="false">http://www.barns.co.za/?p=86</guid>
		<description><![CDATA[After a stormy close to the conference, we have now returned and settled in Frontier Country. Overall, this was a very worthwhile experience. The conference closed with my presentation in Stream A and despite the fact that I was not asked any questions, I feel that it was a good presentation. Unfortunately, it was the [...]]]></description>
			<content:encoded><![CDATA[<p>After a stormy close to the conference, we have now returned and settled in Frontier Country. Overall, this was a very worthwhile experience. The conference closed with my presentation in Stream A and despite the fact that I was not asked any questions, I feel that it was a good presentation. Unfortunately, it was the only paper of its kind at the conference and was tacked onto a stream of IS papers. I know it went over the heads of some people.</p>
<p>The presented papers encompassed a wide variety of fields and it was interesting to see this variety and to get an idea of what research occurs in IS. Despite the fact that most of the research was of little interest to me, there are always those little gems which emerge from the conference. Its now time to get back into forward gear and concentrate on getting the next paper out&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barns.co.za/research/papers/saicsit-08-part-two/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>SAICSIT &#8216;08 &#8211; Part One</title>
		<link>http://www.barns.co.za/research/papers/saicsit-08-part-one</link>
		<comments>http://www.barns.co.za/research/papers/saicsit-08-part-one#comments</comments>
		<pubDate>Tue, 07 Oct 2008 12:30:52 +0000</pubDate>
		<dc:creator>Barns</dc:creator>
				<category><![CDATA[Papers]]></category>
		<category><![CDATA[amazon ec2]]></category>
		<category><![CDATA[knysna]]></category>
		<category><![CDATA[SAICSIT]]></category>
		<category><![CDATA[wilderness]]></category>

		<guid isPermaLink="false">http://www.barns.co.za/?p=84</guid>
		<description><![CDATA[Greetings from a sunny, but slightly chilly Wilderness. So far a lot has come out of this conference that I thought I would report on. In an egotistical manner, the best is still to come!
Firstly, we drove down on Sunday and had a wonderful relaxed drive. We stopped for lunch at Storms River and then [...]]]></description>
			<content:encoded><![CDATA[<p>Greetings from a sunny, but slightly chilly Wilderness. So far a lot has come out of this conference that I thought I would report on. In an egotistical manner, the best is still to come!</p>
<p>Firstly, we drove down on Sunday and had a wonderful relaxed drive. We stopped for lunch at Storms River and then visited the Tsitsikamma Big Tree. We have enjoyed a good social atmosphere with a large group of people from both the CS and IS departments and it has been enjoyable interacting with them all on a social level. As Kevin observed last night: Three generations of Computing Sciences at one table.</p>
<p>The Masters and Doctoral Symposium yesterday was rather rewarding even for those of us who were not participating in it. I took a few things away from it which could be tackled in the Department or actually at Rhodes in general. The following general comments were made:</p>
<ul>
<li>Students frequently don&#8217;t structure their research objectives (research question) properly.</li>
<li>Some of the work being conducted was not research in the sense that students are not illustrating what their work is achieving. In particular, a software project is not a research goal.</li>
<li>Students need to be more articulate about what is their research and what was others research. Here they also need to sell the research.</li>
<li>Also, it is important in the research to answer the questions WHAT, WHY, HOW and most importantly, the SO WHAT.</li>
</ul>
<p>My presentation will be rather different as I was not contributing in the M&amp;D, but rather to SAICSIT itself. This means that I am unlikely to get as much feedback from the audience, but also less criticism.</p>
<p>The presentations today were of mixed value to me, but the most interesting was a discussion of high performance scientific computing using the Amazon EC2. It left me with a few ideas.</p>
<p>The conference hotel is reasonable, but not outstanding. Last nights cruise from Knysna to the Featherbed Nature Reserve and supper in the trees was absolutely superb and will be one of the highlights of the conference.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barns.co.za/research/papers/saicsit-08-part-one/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SAICSIT Paper</title>
		<link>http://www.barns.co.za/research/papers/saicsit-paper</link>
		<comments>http://www.barns.co.za/research/papers/saicsit-paper#comments</comments>
		<pubDate>Sun, 17 Aug 2008 12:13:51 +0000</pubDate>
		<dc:creator>Barns</dc:creator>
				<category><![CDATA[Papers]]></category>
		<category><![CDATA[ACM]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[SAICSIT]]></category>
		<category><![CDATA[taxonomy]]></category>

		<guid isPermaLink="false">http://www.barns.co.za/?p=66</guid>
		<description><![CDATA[It has been a while since I commented about anything that I am doing at the moment. This has mainly because I have been altogether too busy to write anything.
In a previous post I commented on how I almost worked myself to death in pursuit of submitting a half-decent paper to SAICSIT for their 2008 [...]]]></description>
			<content:encoded><![CDATA[<p>It has been a while since I commented about anything that I am doing at the moment. This has mainly because I have been altogether too busy to write anything.</p>
<p>In a previous post I commented on how I almost worked myself to death in pursuit of submitting a half-decent paper to SAICSIT for their 2008 conference. Well, I was fairly happy with the submission that I did make, and so it was very rewarding to have it accepted.</p>
<p>Hannah, Colin and I will be attending SAICSIT later in the year and will get the opportunity to present our work at that forum. What was rewarding for this paper is that not only will it be indexed by the ACM, the comments on the proposed taxonomy were in agreement. This gives some credability to the process that I am currently taking in the development of my Scan-Detection engine.</p>
<p>Here comes October&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barns.co.za/research/papers/saicsit-paper/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SAICSIT 2008 Paper</title>
		<link>http://www.barns.co.za/research/papers/saicsit-2008-paper</link>
		<comments>http://www.barns.co.za/research/papers/saicsit-2008-paper#comments</comments>
		<pubDate>Mon, 23 Jun 2008 12:26:38 +0000</pubDate>
		<dc:creator>Barns</dc:creator>
				<category><![CDATA[Papers]]></category>
		<category><![CDATA[network intrusion detection systems]]></category>
		<category><![CDATA[reconnaissance]]></category>
		<category><![CDATA[scanning]]></category>
		<category><![CDATA[taxonomy]]></category>

		<guid isPermaLink="false">http://www.barns.co.za/?p=31</guid>
		<description><![CDATA[Well, I have finally submitted my SAICSIT paper. It was a very long process, which nearly killed me. On Friday at 11am we decided to change track entirely and with the deadline on Monday at 2pm.
Its now completed under its new title, &#8220;Towards a Taxonomy of Network Scanning Techniques&#8221;
Abstract:
Network scanning is a common reconnaissance activity [...]]]></description>
			<content:encoded><![CDATA[<p>Well, I have finally submitted my SAICSIT paper. It was a very long process, which nearly killed me. On Friday at 11am we decided to change track entirely and with the deadline on Monday at 2pm.</p>
<p>Its now completed under its new title, &#8220;Towards a Taxonomy of Network Scanning Techniques&#8221;</p>
<p><strong>Abstract:</strong></p>
<p style="padding-left: 30px;">Network scanning is a common reconnaissance activity in network intrusion. Despite this, it&#8217;s classifcation remains vague and detection systems in current Network Intrusion Detection Systems are incapable of detecting many forms of scanning traffic.</p>
<p style="padding-left: 30px;">This paper presents a classifcation of network scanning and illustrates how complex and varied this activity is. The presented classifcation extends previous, well known, definitions of scanning traffic in a manner which refects this complexity.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barns.co.za/research/papers/saicsit-2008-paper/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Layout with Graphviz</title>
		<link>http://www.barns.co.za/research/masters/layout-with-graphviz</link>
		<comments>http://www.barns.co.za/research/masters/layout-with-graphviz#comments</comments>
		<pubDate>Sun, 22 Jun 2008 19:06:00 +0000</pubDate>
		<dc:creator>Barns</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Masters]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[graphs]]></category>
		<category><![CDATA[Graphviz]]></category>

		<guid isPermaLink="false">http://www.barns.co.za/?p=30</guid>
		<description><![CDATA[Writing code to draw graphs rather than using a tool such as Visio sounds like a dream come true, but it comes at a price. Graphviz is a nifty tool which does just this. In this sense, I refer to real graphs, those which have nodes and edges connect nodes together.
Conceptually, and practically, it works [...]]]></description>
			<content:encoded><![CDATA[<p>Writing code to draw graphs rather than using a tool such as Visio sounds like a dream come true, but it comes at a price. Graphviz is a nifty tool which does just this. In this sense, I refer to real graphs, those which have nodes and edges connect nodes together.</p>
<p>Conceptually, and practically, it works pretty well, but its layout engine does not always produce something visually appealing, or simple. It tool a wile to discover how to force it to draw nodes in a specific order. It turns out that you connect them with an edge. Sounds silly to add unwanted edges, but you can tell Grahviz that these nodes are invisible. This allows the problem to be solved.</p>
<p>In practice, it still takes forever to do, as it really is a trial and error process. Despite this, it still produces very nice graphics. Unfortunately it cant produce EPS out of the box, but it will create PostScript. If you use the &#8220;ps&#8221; type (rather than the &#8220;ps2&#8243; type) it is a simple matter of running ps2epsi on it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barns.co.za/research/masters/layout-with-graphviz/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISSA Paper: Camera Ready Submitted</title>
		<link>http://www.barns.co.za/research/masters/issa-paper-camera-ready-submitted</link>
		<comments>http://www.barns.co.za/research/masters/issa-paper-camera-ready-submitted#comments</comments>
		<pubDate>Wed, 04 Jun 2008 10:10:48 +0000</pubDate>
		<dc:creator>Barns</dc:creator>
				<category><![CDATA[Masters]]></category>
		<category><![CDATA[Papers]]></category>
		<category><![CDATA[Bro]]></category>
		<category><![CDATA[ISSA]]></category>
		<category><![CDATA[network intrusion detection systems]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[Snort]]></category>

		<guid isPermaLink="false">http://www.barns.co.za/?p=26</guid>
		<description><![CDATA[I have now submitted the camera-ready version of the ISSA Paper. It will be published under the title An Evaluation of Scan-Detection Algorithms in Network Intrusion Detection Systems.
Abstract:
Network Intrusion Detection Systems are becoming more prevalent as devices to protect a network. However, the methods they use for some forms of detection are flawed. This paper [...]]]></description>
			<content:encoded><![CDATA[<p>I have now submitted the camera-ready version of the ISSA Paper. It will be published under the title <strong>An Evaluation of Scan-Detection Algorithms in Network Intrusion Detection Systems</strong>.</p>
<h4>Abstract:</h4>
<p style="padding-left: 30px;">Network Intrusion Detection Systems are becoming more prevalent as devices to protect a network. However, the methods they use for some forms of detection are flawed. This paper builds upon existing research by van Riel and Irwin which illustrated these flaws in Snort and Bro&#8217;s scan-detection engines. Indeed, it has been ascertained that a number of different scanning techniques are not identified by either Snort or Bro.</p>
<p style="padding-left: 30px;">This paper highlights current research into the improvement of these scan-detection algorithms and presents insight into how this research is being conducted at Rhodes University. This research will improve on the scan-detection engines in Snort and Bro, permitting them to be used in a production environment without fear of succumbing to the false negative problem which currently exists.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barns.co.za/research/masters/issa-paper-camera-ready-submitted/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMware for Research</title>
		<link>http://www.barns.co.za/research/vmware-for-research</link>
		<comments>http://www.barns.co.za/research/vmware-for-research#comments</comments>
		<pubDate>Wed, 04 Jun 2008 07:57:51 +0000</pubDate>
		<dc:creator>Barns</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://www.barns.co.za/?p=24</guid>
		<description><![CDATA[Yesterday, I was looking at the VMware site with an intention of getting VMware Server 2 (Beta) and posibly getting pricing for Workstation and ESX Server. As all of this revolves about some of my research, I found myself looking at the VMware Academic Program.
This program allows Universities to obtain VMware software free of charge [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday, I was looking at the VMware site with an intention of getting VMware Server 2 (Beta) and posibly getting pricing for Workstation and ESX Server. As all of this revolves about some of my research, I found myself looking at the VMware Academic Program.</p>
<p>This program allows Universities to obtain VMware software free of charge for research purposes. Of even more interest, it permits publications on this research without prior concent from VMware themselves. This is a major shift from what I was doing last year, and should allow me to redo my work for publishing purposes.</p>
<p>Barry has applied for the program and we should hear back from them within the next week. Read more about the program <a href="http://www.vmware.com/partners/academic/">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barns.co.za/research/vmware-for-research/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SATNAC WIP Paper</title>
		<link>http://www.barns.co.za/research/masters/satnac-wip-paper</link>
		<comments>http://www.barns.co.za/research/masters/satnac-wip-paper#comments</comments>
		<pubDate>Tue, 03 Jun 2008 12:53:03 +0000</pubDate>
		<dc:creator>Barns</dc:creator>
				<category><![CDATA[Masters]]></category>
		<category><![CDATA[Papers]]></category>
		<category><![CDATA[Bro]]></category>
		<category><![CDATA[network intrusion detection systems]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[SATNAC]]></category>
		<category><![CDATA[Snort]]></category>

		<guid isPermaLink="false">http://www.barns.co.za/?p=22</guid>
		<description><![CDATA[I have submitted my Work In Progress Paper for SATNAC, under the title of An Analysis of Network Scanning Traffic as it relates to Scan-Detection in Network Intrusion Detection Systems.
Abstract
Network Intrusion Detection is, in a modern network, a useful tool to detect a wide variety of malicious traffic. The ever present prevalence of scanning activity [...]]]></description>
			<content:encoded><![CDATA[<p>I have submitted my Work In Progress Paper for SATNAC, under the title of <strong>An Analysis of Network Scanning Traffic as it relates to Scan-Detection in Network Intrusion Detection Systems</strong>.</p>
<h4>Abstract</h4>
<p style="padding-left: 30px;">Network Intrusion Detection is, in a modern network, a useful tool to detect a wide variety of malicious traffic. The ever present prevalence of scanning activity on the Internet is fair justification to warrant scan detection as a component of network intrusion detection. Whilst current systems are able to perform scan-detection, the methods they use are often flawed and exhibit an inability to detect scans in an efficient and scalable manner.</p>
<p style="padding-left: 30px;">Existing research by van Riel and Irwin has illustrated a number of flaws present in the open source systems Snort and Bro. This paper builds on this by describing current research at Rhodes University in which these flaws are being addressed. In particular, this research will address the flaws in the scan-detection engines in Snort and Bro by developing new plug-ins for these systems which take into consideration the improvements which are identified over the course of the research.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barns.co.za/research/masters/satnac-wip-paper/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISSA 2008 Results</title>
		<link>http://www.barns.co.za/research/papers/issa-2008-results</link>
		<comments>http://www.barns.co.za/research/papers/issa-2008-results#comments</comments>
		<pubDate>Mon, 26 May 2008 13:21:43 +0000</pubDate>
		<dc:creator>Barns</dc:creator>
				<category><![CDATA[Papers]]></category>
		<category><![CDATA[InetVis]]></category>
		<category><![CDATA[ISSA]]></category>
		<category><![CDATA[Paper]]></category>

		<guid isPermaLink="false">http://www.barns.co.za/?p=18</guid>
		<description><![CDATA[As promised, ISSA got back to us today with the result of submissions to this years conference. My submission was accepted as a work in progress paper. It was submitted as a work in progress paper and so I am more than satisfied with the result.
It is also good to receive some feedback on the [...]]]></description>
			<content:encoded><![CDATA[<p>As promised, ISSA got back to us today with the result of submissions to this years conference. My submission was accepted as a work in progress paper. It was submitted as a work in progress paper and so I am more than satisfied with the result.</p>
<p>It is also good to receive some feedback on the paper from the reviewers. Most notably, a discussion was given on the lack of discussion over the InetVis image, and the scope of the new work in relation to the related work section. Unfortunately, I feel that one of the reviewers did not consider the paper in the context of a work in progress submission and so not all of the feedback was useful.</p>
<p>Altogether a worthwhile result and so I guess a trip to JHB in July is now required&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barns.co.za/research/papers/issa-2008-results/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
