<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>imchris.org</title>
	<atom:link href="http://www.imchris.org/wp/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.imchris.org/wp</link>
	<description>chris grier's web site</description>
	<lastBuildDate>Sun, 22 Apr 2012 16:38:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>censoring political speech on twitter</title>
		<link>http://www.imchris.org/wp/2012/04/12/censoring-political-speech-on-twitter/</link>
		<comments>http://www.imchris.org/wp/2012/04/12/censoring-political-speech-on-twitter/#comments</comments>
		<pubDate>Thu, 12 Apr 2012 17:30:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=349</guid>
		<description><![CDATA[We have a paper this year at LEET &#8212; it&#8217;s a interesting look at policitically motivated spam on Twitter. We caught this thanks to an article Brian Krebs wrote (https://krebsonsecurity.com/2011/12/twitter-bots-drown-out-anti-kremlin-tweets/) and followed up investigaing the attack. Not only did this &#8230; <a href="http://www.imchris.org/wp/2012/04/12/censoring-political-speech-on-twitter/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2012/04/12/censoring-political-speech-on-twitter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>paper at IEEE S&amp;P 2012</title>
		<link>http://www.imchris.org/wp/2012/04/12/paper-at-ieee-sp-2012/</link>
		<comments>http://www.imchris.org/wp/2012/04/12/paper-at-ieee-sp-2012/#comments</comments>
		<pubDate>Thu, 12 Apr 2012 17:21:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=345</guid>
		<description><![CDATA[I&#8217;m a co-author on a paper this year at IEEE S&#38;P that looks at the methodology behind how malware experiments have been conducted in recent papers at top-tier venues. &#8220;Prudent Practices for Designing Malware Experiments: Status Quo and Outlook,&#8221; Christian &#8230; <a href="http://www.imchris.org/wp/2012/04/12/paper-at-ieee-sp-2012/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2012/04/12/paper-at-ieee-sp-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMware vSphere Java examples</title>
		<link>http://www.imchris.org/wp/2012/02/13/vmware-vsphere-java-examples/</link>
		<comments>http://www.imchris.org/wp/2012/02/13/vmware-vsphere-java-examples/#comments</comments>
		<pubDate>Mon, 13 Feb 2012 07:12:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=332</guid>
		<description><![CDATA[I had to automate some VMware tasks the other day, and with the latest ESXi it seems the best way is the <a href="http://vijava.sourceforge.net/">VI Java API</a>. Note: I typically not code in Java! <a href="http://www.imchris.org/wp/2012/02/13/vmware-vsphere-java-examples/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2012/02/13/vmware-vsphere-java-examples/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chrome extensions and security</title>
		<link>http://www.imchris.org/wp/2011/10/03/chrome-extensions-and-security/</link>
		<comments>http://www.imchris.org/wp/2011/10/03/chrome-extensions-and-security/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 20:17:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=272</guid>
		<description><![CDATA[Adrienne wrote a blog post about some of her recent work analyzing Google Chrome extensions for security related bugs. It&#8217;s a nice read and illuminates mistakes made by a surprisingly large number of extension developers (27 / 100 extensions leak &#8230; <a href="http://www.imchris.org/wp/2011/10/03/chrome-extensions-and-security/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/10/03/chrome-extensions-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>paper at IMC 2011</title>
		<link>http://www.imchris.org/wp/2011/09/16/paper-at-imc-2011/</link>
		<comments>http://www.imchris.org/wp/2011/09/16/paper-at-imc-2011/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 08:26:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=264</guid>
		<description><![CDATA[This year we have a paper studying the activity of suspended users on Twitter, which will appear at IMC in November. The title is &#8220;Suspended Accounts In Retrospect: An Analysis of Twitter Spam&#8220;, and the paper presents a unique perspective &#8230; <a href="http://www.imchris.org/wp/2011/09/16/paper-at-imc-2011/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/09/16/paper-at-imc-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anti-virus labels are not suitable for system evaluation</title>
		<link>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/</link>
		<comments>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/#comments</comments>
		<pubDate>Fri, 02 Sep 2011 22:11:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=256</guid>
		<description><![CDATA[I won't name names, but there's plenty of researchers out there that rely on anti-virus labeling in their research. While this could work, without manual validation there's very little chance the AV labels can be used as any sort of ground truth.

Here's 5 reports:
1. fc39ce1593cfb6ca1eb0c289a2ca561c
2. c4d93b536f35b350a992a402dfd72e12
3. c77ba55255c1db38568ca3a73d4b8a72
4. e57d938e0754e4fbb3b87cf818a0fc69
5. e397696b7835ccdcfad9d768cf1a091c

Quick highlights in classification from each report:
1. Bredolab, Krap, Ursnif, Downloader, Generic, etc...
2. Krap, Kryptic, Generic packed, etc...
3. Bredolab, Oficla, Krap, Zbot, Ldpinch, etc...
4. Bredolab, Harnig, Krap, Ursnif, etc...
5. FakeAV, Bubnix, etc... <a href="http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Click Trajectories press!</title>
		<link>http://www.imchris.org/wp/2011/06/14/click-trajectories-press/</link>
		<comments>http://www.imchris.org/wp/2011/06/14/click-trajectories-press/#comments</comments>
		<pubDate>Wed, 15 Jun 2011 06:22:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=226</guid>
		<description><![CDATA[The paper, “Click Trajectories: End-to-End Analysis of the Spam Value Chain”, got quite a bit of pres recently so there&#8217;s a number of great articles that summarize the paper content and have gone out to get quotes from banks and &#8230; <a href="http://www.imchris.org/wp/2011/06/14/click-trajectories-press/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/06/14/click-trajectories-press/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Papers at 2011 IEEE Symp. on S&amp;P</title>
		<link>http://www.imchris.org/wp/2011/05/19/papers-at-2011-ieee-symp-on-sp/</link>
		<comments>http://www.imchris.org/wp/2011/05/19/papers-at-2011-ieee-symp-on-sp/#comments</comments>
		<pubDate>Thu, 19 May 2011 21:24:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=183</guid>
		<description><![CDATA[We had two papers at Oakland this year, and I&#8217;ve put the PDFs up online. Kirill and Kurt  presented on Tuesday afternoon (schedule) NYT Article on the &#8220;Click Trajectories&#8221; work: http://nyti.ms/j6sf5c “Click Trajectories: End-to-End Analysis of the Spam Value Chain”, &#8230; <a href="http://www.imchris.org/wp/2011/05/19/papers-at-2011-ieee-symp-on-sp/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/05/19/papers-at-2011-ieee-symp-on-sp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Naming some popular spambots</title>
		<link>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/</link>
		<comments>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/#comments</comments>
		<pubDate>Tue, 19 Oct 2010 20:52:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=187</guid>
		<description><![CDATA[Part of what I've been doing lately is finding, running, and maintaining bots in a controlled environment. The first part, finding, which includes identifying the binaries I'm running, turns out to be difficult to do. <a href="http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>presenting at CCS Tuesday</title>
		<link>http://www.imchris.org/wp/2010/10/03/presenting-at-ccs-tuesday/</link>
		<comments>http://www.imchris.org/wp/2010/10/03/presenting-at-ccs-tuesday/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 01:53:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=179</guid>
		<description><![CDATA[I&#8217;m going to be at CCS 2010 in Chicago this week presenting @spam: The Underground on 140 Characters or Less. My presentation is the 3rd talk of the conference in the security session (on the first day).]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/10/03/presenting-at-ccs-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

