<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Channel 9 - Entries tagged with sdl-lob</title>
    <atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Tags/sdl-lob/RSS"></atom:link>
    <itunes:summary></itunes:summary>
    <itunes:author>Microsoft</itunes:author>
    <itunes:subtitle></itunes:subtitle>
    <image>
      <url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url>
      <title>Channel 9 - Entries tagged with sdl-lob</title>
      <link>http://channel9.msdn.com/Tags/sdl-lob</link>
    </image>
    <itunes:image href=""></itunes:image>
    <itunes:category text="Technology"></itunes:category>
    <description>Channel 9 keeps you up to date with the latest news and behind the scenes info from Microsoft that developers love to keep up with. From LINQ to SilverLight – Watch videos and hear about all the cool technologies coming and the people behind them.</description>
    <link>http://channel9.msdn.com/Tags/sdl-lob</link>
    <language>en</language>
    <pubDate>Thu, 23 May 2013 23:26:58 GMT</pubDate>
    <lastBuildDate>Thu, 23 May 2013 23:26:58 GMT</lastBuildDate>
    <generator>Rev9</generator>
    <c9:totalResults>8</c9:totalResults>
    <c9:pageCount>1</c9:pageCount>
    <c9:pageSize>25</c9:pageSize>
  <item>
      <title>Technical Preview for CAT.NET 2.0</title>
      <description><![CDATA[Maqbool Malik and Anil Revuru (RV), from <a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">
Microsoft Information Security</a>, talk about the newly designed version of CAT.NET which will be part of the&nbsp;<a shape="rect" href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/" target="_blank" shape="rect">Assessment &amp; Protection
 (A&amp;P)</a> suite.<br /><br />CAT.NET&nbsp;is a static analysis tool on Visual Studio&nbsp;that helps find vulnerabilities like SQL Injection, CSRF, XSS among others, within managed code.&nbsp;This version is currently&nbsp;a technical preview which works on the command line only though for its release it
 will be integrated with Visual Studio's UI&nbsp;under the&nbsp;Code Analysis tab. In this interview you can learn all the new features as well as details on how to provide feedback on the tool.<br /><br />The CTP (Community Technology Preview) for this tool is available in <a shape="rect" href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank" shape="rect">
Microsoft Connect – Information Security Tools</a>. <br /><br /><a shape="rect" href="http://blogs.msdn.com/securitytools/archive/tags/CAT.NET/default.aspx" target="_blank" shape="rect">Learn more</a>&nbsp;about this tool by reading examples on how to run it&nbsp;by following the&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools" target="_blank" shape="rect">Security
 Tools Team</a> blog.  <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sdl-lob/RSS&WT.dl=0&WT.entryid=Entry:RSSView:37c907c065d64c119a6d9deb001b8f28">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Technical-Preview-for-CATNET-20</comments>
      <itunes:summary>Maqbool Malik and Anil Revuru (RV), from 
Microsoft Information Security, talk about the newly designed version of CAT.NET which will be part of the&amp;nbsp;Assessment &amp;amp; Protection
 (A&amp;amp;P) suite.CAT.NET&amp;nbsp;is a static analysis tool on Visual Studio&amp;nbsp;that helps find vulnerabilities like SQL Injection, CSRF, XSS among others, within managed code.&amp;nbsp;This version is currently&amp;nbsp;a technical preview which works on the command line only though for its release it
 will be integrated with Visual Studio&#39;s UI&amp;nbsp;under the&amp;nbsp;Code Analysis tab. In this interview you can learn all the new features as well as details on how to provide feedback on the tool.The CTP (Community Technology Preview) for this tool is available in 
Microsoft Connect – Information Security Tools. Learn more&amp;nbsp;about this tool by reading examples on how to run it&amp;nbsp;by following the&amp;nbsp;Security
 Tools Team blog. </itunes:summary>
      <itunes:duration>1221</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Technical-Preview-for-CATNET-20</link>
      <pubDate>Fri, 11 Dec 2009 19:32:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Technical-Preview-for-CATNET-20</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/512199_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/512199_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_2MB_ch9.wmv" expression="full" duration="1221" fileSize="149464552" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_ch9.mp3" expression="full" duration="1221" fileSize="9776817" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_ch9.mp4" expression="full" duration="1221" fileSize="90630071" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_ch9.wma" expression="full" duration="1221" fileSize="9891135" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_ch9.wmv" expression="full" duration="1221" fileSize="133190621" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_Zune_ch9.wmv" expression="full" duration="1221" fileSize="88742673" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/9/9/1/2/1/5/CATnetCTP_2MB_ch9.wmv" length="149464552" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Technical-Preview-for-CATNET-20/RSS</wfw:commentRss>
      <category>cat.net</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>Tools</category>
    </item>
  <item>
      <title>SDL-LOB Phase 3: Implementation</title>
      <description><![CDATA[<span id="ctl00_MainPlaceHolder_Starter_BodyLabel">The third phase of the <a shape="rect" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank" shape="rect">
<span>SDL-LOB </span></a>(Security Development Lifecycle for Line-of-Business applications) includes
<span><a shape="rect" href="http://msdn.microsoft.com/en-us/library/dd831972.aspx" target="_blank" shape="rect"><span>Implementation</span></a>.</span><br>
<br>
Eugene Siu, from <a shape="rect" href="http://www.msinfosec.com" target="_blank" shape="rect">
Microsoft Information Security</a>, describes some of the security pillars&nbsp;that are key in this phase, including code review, authentication, authorization and configuration settings. Also, he&nbsp;explains how penetration testing can complement your code review
 when bulletproofing your code against vulnerabilities.<br>
<br>
Read more on the Implementation Phase&nbsp;<a shape="rect" href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" target="_blank" shape="rect">here</a>.<br>
</span> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sdl-lob/RSS&WT.dl=0&WT.entryid=Entry:RSSView:b18ee43f9f404acd9acc9deb017310f2">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/SDL-LOB-Phase-3-Implementation</comments>
      <itunes:summary>The third phase of the 
SDL-LOB (Security Development Lifecycle for Line-of-Business applications) includes
Implementation.

Eugene Siu, from 
Microsoft Information Security, describes some of the security pillars&amp;nbsp;that are key in this phase, including code review, authentication, authorization and configuration settings. Also, he&amp;nbsp;explains how penetration testing can complement your code review
 when bulletproofing your code against vulnerabilities.

Read more on the Implementation Phase&amp;nbsp;here.
</itunes:summary>
      <itunes:duration>1099</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/SDL-LOB-Phase-3-Implementation</link>
      <pubDate>Mon, 20 Jul 2009 17:54:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/SDL-LOB-Phase-3-Implementation</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/479451_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/479451_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_2MB_ch9.wmv" expression="full" duration="1099" fileSize="134509761" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp3" expression="full" duration="1099" fileSize="8798169" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp4" expression="full" duration="1099" fileSize="81603875" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wma" expression="full" duration="1099" fileSize="17803689" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wmv" expression="full" duration="1099" fileSize="154844037" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_Zune_ch9.wmv" expression="full" duration="1099" fileSize="97484017" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/1/5/4/9/7/4/lobSDLdev_s_ch9.wmv" expression="full" duration="1099" fileSize="199" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wmv" length="154844037" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>2</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/SDL-LOB-Phase-3-Implementation/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Development</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
    </item>
  <item>
      <title>Anti-XSS 3.0 Released</title>
      <description><![CDATA[
<p>Vineet Batta and Anil Revuru (RV), from <a shape="rect" href="http://www.msinfosec.com" target="_blank" shape="rect">
Microsoft&nbsp;Information Security</a>,&nbsp;talk about the release of the new version of the Anti-XSS library, which is&nbsp;designed to encode output to help developers protect their ASP.NET web-based applications from&nbsp;cross-site scripting&nbsp;attacks.<br>
<br>
They explain the new features and benefits found on version 3.0, including:</p>
<ul>
<li>Extended white list </li><li>Better performance </li><li>MSDN Style Help documentation </li><li>Marked Anti-XSS Output </li><li>Security Runtime Engine (SRE) </li></ul>
<p>To learn more about this library read the following blogs from the <a shape="rect" href="http://blogs.msdn.com/securitytools/archive/tags/Anti-XSS/default.aspx" target="_blank" shape="rect">
Security Tools Team blog</a>&nbsp;and previous <a shape="rect" href="http://blogs.msdn.com/cisg/archive/tags/Anti-XSS/default.aspx" target="_blank" shape="rect">
posts</a>.</p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sdl-lob/RSS&WT.dl=0&WT.entryid=Entry:RSSView:c9a3a5ada73c4a08827d9deb0173162e">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-30-Released</comments>
      <itunes:summary>
Vineet Batta and Anil Revuru (RV), from 
Microsoft&amp;nbsp;Information Security,&amp;nbsp;talk about the release of the new version of the Anti-XSS library, which is&amp;nbsp;designed to encode output to help developers protect their ASP.NET web-based applications from&amp;nbsp;cross-site scripting&amp;nbsp;attacks.

They explain the new features and benefits found on version 3.0, including: 

Extended white list Better performance MSDN Style Help documentation Marked Anti-XSS Output Security Runtime Engine (SRE) 
To learn more about this library read the following blogs from the 
Security Tools Team blog&amp;nbsp;and previous 
posts. 
</itunes:summary>
      <itunes:duration>1055</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-30-Released</link>
      <pubDate>Wed, 15 Jul 2009 16:12:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-30-Released</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/478820_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/478820_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv" expression="full" duration="1055" fileSize="47180833" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp3" expression="full" duration="1055" fileSize="8447064" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp4" expression="full" duration="1055" fileSize="79917703" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.wma" expression="full" duration="1055" fileSize="17085733" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_Zune_ch9.wmv" expression="full" duration="1055" fileSize="103371753" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_Zune_ch9.wmv" length="103371753" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Anti-XSS-30-Released/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Antixss</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>ist</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>Tools</category>
    </item>
  <item>
      <title>Threat Modeling LOB Applications with TAM 3.0</title>
      <description><![CDATA[
<p>Andrew Law, from <a href="http://www.msinfosec.com" target="_blank">Microsoft Information Security</a>, walks us through the creation of a threat model for a line-of-business application using the Threat Analysis &amp; Modeling tool version 3.0. This screencast
 includes the definition and purpose of a threat model as well as its alignment with the
<a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank">SDL-LOB</a>.
</p>
<p>Threat Model ownership is discussed as well as the use of the central repository, common task list and how to leverage them to automatically generate threats.</p>
<p>Learn more&nbsp;on the&nbsp;<a href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" target="_blank">Threat Modeling</a> site &amp;&nbsp;<a href="http://blogs.msdn.com/securitytools" target="_blank">Information Security Tools</a>&nbsp;blog.</p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sdl-lob/RSS&WT.dl=0&WT.entryid=Entry:RSSView:93644617a0db420994e09deb00db584a">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30</comments>
      <itunes:summary>
Andrew Law, from Microsoft Information Security, walks us through the creation of a threat model for a line-of-business application using the Threat Analysis &amp;amp; Modeling tool version 3.0. This screencast
 includes the definition and purpose of a threat model as well as its alignment with the
SDL-LOB.
 
Threat Model ownership is discussed as well as the use of the central repository, common task list and how to leverage them to automatically generate threats. 
Learn more&amp;nbsp;on the&amp;nbsp;Threat Modeling site &amp;amp;&amp;nbsp;Information Security Tools&amp;nbsp;blog. 
</itunes:summary>
      <itunes:duration>2925</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30</link>
      <pubDate>Mon, 06 Jul 2009 22:38:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/477063_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/477063_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_2MB_ch9.wmv" expression="full" duration="2925" fileSize="132391501" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp3" expression="full" duration="2925" fileSize="23406707" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp4" expression="full" duration="2925" fileSize="77895311" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wma" expression="full" duration="2925" fileSize="47320993" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wmv" expression="full" duration="2925" fileSize="127654993" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_Zune_ch9.wmv" expression="full" duration="2925" fileSize="97750973" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/3/6/0/7/7/4/tam3onLOB_s_ch9.wmv" expression="full" duration="2925" fileSize="199" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wmv" length="127654993" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>tam</category>
      <category>threat modeling</category>
      <category>Tools</category>
    </item>
  <item>
      <title>SQL Detect</title>
      <description><![CDATA[SQL Detect is&nbsp;a SQL injection filter in real-time mode. When a request happens in the application the tool applies different heuristics to the data and tries to identify the attack. After the request is validated it proceeds.<br>
<br>
Maqbool Malik, from <a shape="rect" href="http://www.msinfosec.com" target="_blank" shape="rect">
Microsoft Information Security</a>, describes how this is one of the tools to be included in the to-be-released Security Runtime Engine (SRE).<br>
<br>
To learn more about their tools, read the&nbsp;<a shape="rect" href="http://blogs.msdn.com/securitytools/" target="_blank" shape="rect">Information Security Tools</a> blog.<br>
<br>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sdl-lob/RSS&WT.dl=0&WT.entryid=Entry:RSSView:773562286bb64bc38c379deb00db5c51">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/SQL-Detect</comments>
      <itunes:summary>SQL Detect is&amp;nbsp;a SQL injection filter in real-time mode. When a request happens in the application the tool applies different heuristics to the data and tries to identify the attack. After the request is validated it proceeds.

Maqbool Malik, from 
Microsoft Information Security, describes how this is one of the tools to be included in the to-be-released Security Runtime Engine (SRE).

To learn more about their tools, read the&amp;nbsp;Information Security Tools blog.

</itunes:summary>
      <itunes:duration>734</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/SQL-Detect</link>
      <pubDate>Mon, 06 Jul 2009 19:41:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/SQL-Detect</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/477052_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/477052_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_2MB_ch9.wmv" expression="full" duration="734" fileSize="89893228" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp3" expression="full" duration="734" fileSize="5880981" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp4" expression="full" duration="734" fileSize="45367124" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wma" expression="full" duration="734" fileSize="11897825" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wmv" expression="full" duration="734" fileSize="95065847" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_Zune_ch9.wmv" expression="full" duration="734" fileSize="54601827" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/2/5/0/7/7/4/SQLdetect_s_ch9.wmv" expression="full" duration="734" fileSize="199" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wmv" length="95065847" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>2</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/SQL-Detect/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>sre</category>
      <category>Tools</category>
    </item>
  <item>
      <title>Architecture Behind CAT.NET</title>
      <description><![CDATA[
<p>Ben Livshits, from Microsoft Research, talks about the architecture behind <a shape="rect" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&amp;displaylang=en" target="_blank" shape="rect">
CAT.NET</a>, which is a static analysis tool on Visual Studio&nbsp;that helps find vulnerabilities like SQL Injection, CSRF, &nbsp;XSS among others, within managed code.
<br>
<br>
Ben’s knowledge on static and dynamic dataflow analysis made him a key contributor on the creation of CAT.NET. He walks us through different examples of how the data analysis happens depending on complexity and explains how precision varies.
<br>
<br>
Learn more about <a shape="rect" href="http://blogs.msdn.com/securitytools/default.aspx" target="_blank" shape="rect">
Microsoft Information Security Tools</a>.&nbsp;<br>
<br>
<a shape="rect" href="http://www.msinfosec.com" shape="rect">www.msinfosec.com</a>&nbsp;</p>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sdl-lob/RSS&WT.dl=0&WT.entryid=Entry:RSSView:b31a7863ee494b97a5109deb00db613d">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Architecture-behind-CATNET</comments>
      <itunes:summary>
Ben Livshits, from Microsoft Research, talks about the architecture behind 
CAT.NET, which is a static analysis tool on Visual Studio&amp;nbsp;that helps find vulnerabilities like SQL Injection, CSRF, &amp;nbsp;XSS among others, within managed code.


Ben’s knowledge on static and dynamic dataflow analysis made him a key contributor on the creation of CAT.NET. He walks us through different examples of how the data analysis happens depending on complexity and explains how precision varies.


Learn more about 
Microsoft Information Security Tools.&amp;nbsp;

www.msinfosec.com&amp;nbsp; 
</itunes:summary>
      <itunes:duration>1067</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Architecture-behind-CATNET</link>
      <pubDate>Mon, 29 Jun 2009 22:24:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Architecture-behind-CATNET</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/476042_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/476042_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_2MB_ch9.wmv" expression="full" duration="1067" fileSize="130500881" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp3" expression="full" duration="1067" fileSize="8540072" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp4" expression="full" duration="1067" fileSize="77800586" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wma" expression="full" duration="1067" fileSize="17268977" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wmv" expression="full" duration="1067" fileSize="150763845" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_Zune_ch9.wmv" expression="full" duration="1067" fileSize="90075825" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/2/4/0/6/7/4/catNET_s_ch9.wmv" expression="full" duration="1067" fileSize="193" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wmv" length="150763845" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>1</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Architecture-behind-CATNET/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>cat.net</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>RiSE</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>Tools</category>
    </item>
  <item>
      <title>Threat Analysis &amp; Modeling Tool - TAM 3.0</title>
      <description><![CDATA[Anil Revuru (RV), from <a shape="rect" href="http://blogs.msdn.com/securitytools/default.aspx" target="_blank" shape="rect">
Information Security Tools</a>, provides an overview of the new version of TAM (Threat Analysis &amp; Modeling), an asset-centric tool which&nbsp;uses an objective methodology to analyze applications for&nbsp;threats and define mitigation plans for them. TAM aligns to the&nbsp;<a shape="rect" href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank" shape="rect">SDL-LOB</a>
 as part of the Design phase.<br>
<br>
RV describes the new features in this version,&nbsp;including&nbsp;the online repository for the attack countermeasures,&nbsp;automated use cases creation, composite threats, among others.<br>
<br>
Learn more:<br>
<ol>
<li><a shape="rect" href="http://www.msinfosec.com/" target="_blank" shape="rect">Microsoft Information Security</a>
</li><li><a shape="rect" href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" target="_blank" shape="rect">TAM Tool Site</a>&nbsp;
</li></ol>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sdl-lob/RSS&WT.dl=0&WT.entryid=Entry:RSSView:056ccc53c07c480f8a3c9deb00db65c7">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Thread-Analysis--Modeling-Tool-TAM-30</comments>
      <itunes:summary>Anil Revuru (RV), from 
Information Security Tools, provides an overview of the new version of TAM (Threat Analysis &amp;amp; Modeling), an asset-centric tool which&amp;nbsp;uses an objective methodology to analyze applications for&amp;nbsp;threats and define mitigation plans for them. TAM aligns to the&amp;nbsp;SDL-LOB
 as part of the Design phase.

RV describes the new features in this version,&amp;nbsp;including&amp;nbsp;the online repository for the attack countermeasures,&amp;nbsp;automated use cases creation, composite threats, among others.

Learn more:

Microsoft Information Security
TAM Tool Site&amp;nbsp;

</itunes:summary>
      <itunes:duration>961</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Thread-Analysis--Modeling-Tool-TAM-30</link>
      <pubDate>Mon, 29 Jun 2009 20:43:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Thread-Analysis--Modeling-Tool-TAM-30</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/476038_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/476038_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_2MB_ch9.wmv" expression="full" duration="961" fileSize="117606784" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.mp3" expression="full" duration="961" fileSize="7697076" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.mp4" expression="full" duration="961" fileSize="65596326" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wma" expression="full" duration="961" fileSize="15574721" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wmv" expression="full" duration="961" fileSize="131291209" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_Zune_ch9.wmv" expression="full" duration="961" fileSize="79195189" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/8/3/0/6/7/4/TAM3_s_ch9.wmv" expression="full" duration="961" fileSize="189" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wmv" length="131291209" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>2</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Thread-Analysis--Modeling-Tool-TAM-30/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
      <category>tam</category>
      <category>threat modeling</category>
      <category>Tools</category>
    </item>
  <item>
      <title>Security Design Reviews</title>
      <description><![CDATA[Security is not something we just add at the end of the implementation phase...it should be
<em>baked</em> into the application all the way from design. <br>
<br>
Anmol Malhotra, from <a shape="rect" href="http://www.msinfosec.com" target="_blank" shape="rect">
Microsoft Information Security</a>, provides more than enough reasons why Security Design Reviews make sense and why they are so important...let him walk you through the SDLC phases and how security tasks are found in each step.<br>
<br>
To learn more about security on line-of-business applications using the SDL-LOB go&nbsp;<a shape="rect" href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank" shape="rect">here</a>.
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sdl-lob/RSS&WT.dl=0&WT.entryid=Entry:RSSView:e6e19c534ac147ea84ea9deb00db6b09">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Jossie/Security-Design-Reviews</comments>
      <itunes:summary>Security is not something we just add at the end of the implementation phase...it should be
baked into the application all the way from design. 

Anmol Malhotra, from 
Microsoft Information Security, provides more than enough reasons why Security Design Reviews make sense and why they are so important...let him walk you through the SDLC phases and how security tasks are found in each step.

To learn more about security on line-of-business applications using the SDL-LOB go&amp;nbsp;here.
</itunes:summary>
      <itunes:duration>1083</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Jossie/Security-Design-Reviews</link>
      <pubDate>Wed, 24 Jun 2009 16:07:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Jossie/Security-Design-Reviews</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/475065_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/475065_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_2MB_ch9.wmv" expression="full" duration="1083" fileSize="263445138" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp3" expression="full" duration="1083" fileSize="8670049" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp4" expression="full" duration="1083" fileSize="106866291" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.wmv" expression="full" duration="1083" fileSize="153867941" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_Zune_ch9.wmv" expression="full" duration="1083" fileSize="153579921" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/5/6/0/5/7/4/designRev_s_ch9.wmv" expression="full" duration="1083" fileSize="199" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.wmv" length="153867941" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Jossie</dc:creator>
      <itunes:author>Jossie</itunes:author>
      <slash:comments>2</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Jossie/Security-Design-Reviews/RSS</wfw:commentRss>
      <category>ace</category>
      <category>ace team</category>
      <category>Information</category>
      <category>information security</category>
      <category>infosec</category>
      <category>LOB</category>
      <category>Simple DirectMedia Layer</category>
      <category>sdl-lob</category>
      <category>Security</category>
    </item>    
</channel>
</rss>