<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" media="screen" href="/App_Themes/default/rss.xslt"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:evnet="http://www.mscommunities.com/rssmodule/"><channel><title>jossie</title><atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/posts/jossie/rss/default.aspx" /><image><url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url><title>jossie</title><link>http://channel9.msdn.com/posts/Jossie/</link></image><description>Channel 9 Blog for Jossie</description><link>http://channel9.msdn.com/posts/Jossie/</link><language>en-us</language><pubDate>Thu, 19 Nov 2009 18:51:24 GMT</pubDate><lastBuildDate>Thu, 19 Nov 2009 18:51:24 GMT</lastBuildDate><generator>EvNet (EvNet, Version=1.0.3608.3122, Culture=neutral, PublicKeyToken=null)</generator><item><title>Web Application Configuration Analyzer (WACA)</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_85_ch9.png" border="0" /&gt;Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduces a configuration verification tool that will be part of a suite of tools that will help you assess your code as well as protect it. For more info watch the &lt;a href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/" target="_blank"&gt;Assessment &amp;amp; Protection (A&amp;amp;P) Suite&lt;/a&gt; video.&lt;br /&gt;
&lt;br /&gt;
WACA is designed to scan your development environment against best practices for .NET security configuration, IIS settings, SQL Server Security best practices and some Windows permission settings. It is helpful for verifying your configuration while unit testing and ensuring there are no issues when the application is in production.&lt;br /&gt;
&lt;br /&gt;
The CTP (Community Technology Preview) for this tool is available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
Read &lt;a href="http://blogs.msdn.com/infosec/archive/2009/11/16/infosec-assessment-protection-a-p-suite-released.aspx" target="_blank"&gt;CTP announcement&lt;/a&gt; and follow the &lt;a href="http://blogs.msdn.com/securitytools" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog.&lt;img src="http://channel9.msdn.com/507560/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Web-Application-Configuration-Analyzer-WACA/</comments><link>http://channel9.msdn.com/posts/Jossie/Web-Application-Configuration-Analyzer-WACA/</link><pubDate>Fri, 20 Nov 2009 22:21:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wmv</guid><evnet:views>1722</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/507560/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduces a configuration verification tool that will be part of a suite of tools that will help you assess your code as well as protect it. For more info watch the &lt;a href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/" target="_blank"&gt;Assessment &amp;amp; Protection (A&amp;amp;P) Suite&lt;/a&gt; video.&lt;br /&gt;
&lt;br /&gt;
WACA is designed to scan your development environment against best practices for .NET security configuration, IIS settings, SQL Server Security best practices and some Windows permission settings. It is helpful for verifying your configuration while unit testing and ensuring there are no issues when the application is in production.</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.mp4" expression="full" duration="943" fileSize="103910191" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.mp3" expression="full" duration="943" fileSize="7549118" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.mp4" expression="full" duration="943" fileSize="103910191" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wma" expression="full" duration="943" fileSize="7635131" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wmv" expression="full" duration="943" fileSize="150098729" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_2MB_ch9.wmv" expression="full" duration="943" fileSize="115402475" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_Zune_ch9.wmv" expression="full" duration="943" fileSize="93794781" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_512_ch9.png" expression="full" duration="943" type="image/jpeg" medium="image" /><media:content url="http://ss.channel9.msdn.com/ch9/0/6/5/7/0/5/WACA.ism/Manifest" expression="full" duration="943" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wmv" expression="full" duration="943" fileSize="150098729" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/0/6/5/7/0/5/WACA_ch9.wmv" length="150098729" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Web-Application-Configuration-Analyzer-WACA/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/507560/Trackback.aspx</trackback:ping><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category><category>waca</category></item><item><title>Assessment and Protection Suite</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_85_ch9.png" border="0" /&gt;&lt;p&gt;Anil Revuru (RV) and Mark Curphey, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduce what would be in the future a suite of tools that will help you assess your code as well as protect it. This is called the Assessment &amp;amp; Protection (A&amp;amp;P) Suite and it includes the following tools: &lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Web Protection Library (WPL) – which includes Anti-XSS, SRE, mitigation of SQL Injection, CSRF among others &lt;/li&gt;
    &lt;li&gt;CAT.NET &lt;/li&gt;
    &lt;li&gt;Web Application Configuration Analyzer (WACA) &lt;/li&gt;
    &lt;li&gt;and room for more future add-ons &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The CTP (Community Technology Preview) for these tools are available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. These are currently individual as they shift to one-install.&lt;br /&gt;
&lt;br /&gt;
Read &lt;a href="http://blogs.msdn.com/infosec/archive/2009/11/16/infosec-assessment-protection-a-p-suite-released.aspx" target="_blank"&gt;CTP announcement&lt;/a&gt; and follow the &lt;a href="http://blogs.msdn.com/securitytools" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog. &lt;/p&gt;&lt;img src="http://channel9.msdn.com/505599/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/</comments><link>http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/</link><pubDate>Thu, 12 Nov 2009 17:21:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wmv</guid><evnet:views>2697</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/505599/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;Anil Revuru (RV) and Mark Curphey, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduce what would be in the future a suite of tools that will help you assess your code as well as protect it. This is called the Assessment &amp;amp; Protection (A&amp;amp;P) Suite and it includes the following tools: &lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Web Protection Library (WPL) – which includes Anti-XSS, SRE, mitigation of SQL Injection, CSRF among others &lt;/li&gt;
    &lt;li&gt;CAT.NET &lt;/li&gt;
    &lt;li&gt;Web Application Configuration Analyzer (WACA) &lt;/li&gt;
    &lt;li&gt;and room for more future add-ons &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The CTP (Community Technology Preview) for these tools are available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. These are currently individual as they shift to one-install.&lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.mp4" expression="full" duration="1044" fileSize="115680604" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.mp3" expression="full" duration="1044" fileSize="8359931" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.mp4" expression="full" duration="1044" fileSize="115680604" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wma" expression="full" duration="1044" fileSize="8458227" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wmv" expression="full" duration="1044" fileSize="169620143" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_2MB_ch9.wmv" expression="full" duration="1044" fileSize="127779102" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_Zune_ch9.wmv" expression="full" duration="1044" fileSize="112564195" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_512_ch9.png" expression="full" duration="1044" type="image/jpeg" medium="image" /><media:content url="http://mschannel9.vo.msecnd.net/ss1/ch9/9/9/5/5/0/5/AnPoverview.ism/Manifest" expression="full" duration="1044" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wmv" expression="full" duration="1044" fileSize="169620143" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/9/9/5/5/0/5/AnPoverview_ch9.wmv" length="169620143" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/505599/Trackback.aspx</trackback:ping><category>antixss</category><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category><category>wpl</category></item><item><title>Enhanced Web Protection Library</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_85_ch9.png" border="0" /&gt;&lt;p&gt;Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduces the expansion of what used to be the Anti-XSS Library. But web vulnerabilities are not only around Cross-Site Scripting (XSS) attacks. This enhanced version of the library will introduce mitigation to other attacks like:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;SQL Injection &lt;/li&gt;
    &lt;li&gt;Cross-Site Request Forgery (CSRF) &lt;/li&gt;
    &lt;li&gt;Setting Enforcement like SSL &amp;amp; HTTP_ONLY cookies &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine for SQL Injection &amp;amp; XSS &lt;/li&gt;
    &lt;li&gt;Among others &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The CTP (Community Technology Preview) is available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
Read &lt;a href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx" target="_blank"&gt;CTP announcement&lt;/a&gt; and follow the &lt;a href="http://blogs.msdn.com/securitytools" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog. &lt;/p&gt;&lt;img src="http://channel9.msdn.com/505597/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Enhanced-Web-Protection-Library/</comments><link>http://channel9.msdn.com/posts/Jossie/Enhanced-Web-Protection-Library/</link><pubDate>Thu, 12 Nov 2009 17:21:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wmv</guid><evnet:views>2946</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/505597/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, introduces the expansion of what used to be the Anti-XSS Library. But web vulnerabilities are not only around Cross-Site Scripting (XSS) attacks. This enhanced version of the library will introduce mitigation to other attacks like:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;SQL Injection &lt;/li&gt;
    &lt;li&gt;Cross-Site Request Forgery (CSRF) &lt;/li&gt;
    &lt;li&gt;Setting Enforcement like SSL &amp;amp; HTTP_ONLY cookies &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine for SQL Injection &amp;amp; XSS &lt;/li&gt;
    &lt;li&gt;Among others &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The CTP (Community Technology Preview) is available in &lt;a href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" target="_blank"&gt;Microsoft Connect – Information Security Tools&lt;/a&gt;. &lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.mp4" expression="full" duration="928" fileSize="125005100" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.mp3" expression="full" duration="928" fileSize="7428509" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.mp4" expression="full" duration="928" fileSize="125005100" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wma" expression="full" duration="928" fileSize="7517981" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wmv" expression="full" duration="928" fileSize="169042525" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_2MB_ch9.wmv" expression="full" duration="928" fileSize="113545072" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_Zune_ch9.wmv" expression="full" duration="928" fileSize="105714577" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_512_ch9.png" expression="full" duration="928" type="image/jpeg" medium="image" /><media:content url="http://mschannel9.vo.msecnd.net/ss1/ch9/7/9/5/5/0/5/WPL.ism/Manifest" expression="full" duration="928" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wmv" expression="full" duration="928" fileSize="169042525" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/7/9/5/5/0/5/WPL_ch9.wmv" length="169042525" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Enhanced-Web-Protection-Library/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/505597/Trackback.aspx</trackback:ping><category>antixss</category><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category><category>wpl</category></item><item><title>Anti-XSS Library v3.1: Find, Fix, and Verify Errors</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_85_ch9.png" border="0" /&gt;&lt;p&gt;Anil Revuru (RV) from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; gives a demonstration of the new features on the Anti-XSS Library v3.1  including HTML Sanitization which provides new methods to the Anti-XSS class to strip malicious characters or scripts off of HTML and returns safe HTML.&lt;br /&gt;
&lt;br /&gt;
He talks about:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;
    &lt;div&gt;What is Cross-Site Scripting Attack (XSS)&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;How to detect Cross Site Scripting Vulnerabilities&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;Introduction of Anti-XSS Library&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;What’s new in Anti-XSS Library 3.1&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;Anti-XSS 3.1 demo&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;Security Runtime Engine (SRE)&lt;/div&gt;
    &lt;/li&gt;
    &lt;li&gt;
    &lt;div&gt;SRE Demo&lt;/div&gt;
    &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To learn more about this application and stay up to date on the latest news, read the following blogs from &lt;a href="http://blogs.msdn.com/infosec/archive/2009/09/17/anti-xss-3-1-released.aspx" target="_blank"&gt;Information Security&lt;/a&gt; and previous posts from the &lt;a href="http://blogs.msdn.com/securitytools/archive/tags/Anti-XSS/default.aspx" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/" target="_blank"&gt;Overview of the Anti-XSS Library&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=051ee83c-5ccf-48ed-8463-02f56a6bfc09&amp;amp;displaylang=en" target="_blank"&gt;Download: Microsoft Anti-Cross Site Scripting Library v3.1&lt;/a&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/493696/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Anti-XSS-Library-v31-Find-Fix-and-Verify-Errors/</comments><link>http://channel9.msdn.com/posts/Jossie/Anti-XSS-Library-v31-Find-Fix-and-Verify-Errors/</link><pubDate>Wed, 23 Sep 2009 17:20:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wmv</guid><evnet:views>2783</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/493696/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;Anil Revuru (RV) from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; gives a demonstration of the new features on the Anti-XSS Library v3.1 including HTML Sanitization which provides new methods to the Anti-XSS class to strip malicious characters or scripts off of HTML and returns safe HTML.&lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.mp4" expression="full" duration="1311" fileSize="30406648" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.mp3" expression="full" duration="1311" fileSize="10494270" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.mp4" expression="full" duration="1311" fileSize="30406648" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wma" expression="full" duration="1311" fileSize="10612095" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wmv" expression="full" duration="1311" fileSize="44119933" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_2MB_ch9.wmv" expression="full" duration="1311" fileSize="190365309" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_Zune_ch9.wmv" expression="full" duration="1311" fileSize="31639861" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_512_ch9.png" expression="full" duration="1311" type="image/jpeg" medium="image" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wmv" expression="full" duration="1311" fileSize="44119933" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/6/9/6/3/9/4/antiXSS31_ch9.wmv" length="44119933" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>4</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Anti-XSS-Library-v31-Find-Fix-and-Verify-Errors/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/493696/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>antixss</category><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category></item><item><title>Connected Information Security Framework: Core Components</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_85_ch9.png" border="0" /&gt;&lt;p&gt;Marius Grigoriu and Vineet Batta, from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; talk about the technical components for the first version of &lt;b&gt;C&lt;/b&gt;onnected &lt;b&gt;I&lt;/b&gt;nformation &lt;b&gt;S&lt;/b&gt;ecurity &lt;b&gt;F&lt;/b&gt;ramework (&lt;a href="http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/" target="_blank"&gt;CISF&lt;/a&gt;).  A software development framework comprising of API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions like &lt;a href="http://edge.technet.com/Media/Risk-Tracker/" target="_blank"&gt;Risk Tracker&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Microsoft’s IT Information Security Tools Team designs and develops CISF to “engineer the security delta” meaning as a way to rapidly meet business requirements and create functionality that doesn’t exist or is not yet available in their product range.&lt;br /&gt;
&lt;br /&gt;
They explain the core pieces CISF consists of like: Business Intelligent, Portal, Notification, and others that help build information security applications cheaper, faster, and better &lt;/p&gt;
&lt;p&gt;To learn more about this framework and stay up to date on the latest news, read the following blogs from &lt;a href="http://blogs.msdn.com/infosec/archive/tags/CISF/default.aspx" target="_blank"&gt;Information Security&lt;/a&gt; and previous posts from the  &lt;a href="http://blogs.msdn.com/securitytools/archive/tags/CISF/default.aspx" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog&lt;/p&gt;
&lt;p&gt;To see an overview of what CISF is watch the video: &lt;a href="http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/" target="_blank"&gt;CISF: Build Custom Security Solutions&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;a href="http://cisf.codeplex.com/" target="_blank"&gt;CISF CTP download&lt;/a&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/493725/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Connected-Information-Security-Framework-Core-Components/</comments><link>http://channel9.msdn.com/posts/Jossie/Connected-Information-Security-Framework-Core-Components/</link><pubDate>Wed, 23 Sep 2009 17:19:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.wmv</guid><evnet:views>5812</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/493725/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Marius Grigoriu and Vineet Batta, from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; talk about the technical components for the first version of &lt;b&gt;C&lt;/b&gt;onnected &lt;b&gt;I&lt;/b&gt;nformation &lt;b&gt;S&lt;/b&gt;ecurity &lt;b&gt;F&lt;/b&gt;ramework (&lt;a href="http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/"&gt;CISF&lt;/a&gt;). A software development framework comprising of API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions like &lt;a href="http://edge.technet.com/Media/Risk-Tracker/" target="_blank"&gt;Risk Tracker&lt;/a&gt;.</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.mp4" expression="full" duration="1326" fileSize="142845363" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.mp3" expression="full" duration="1326" fileSize="10612355" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.mp4" expression="full" duration="1326" fileSize="142845363" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.wma" expression="full" duration="1326" fileSize="10735265" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.wmv" expression="full" duration="1326" fileSize="192376149" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_2MB_ch9.wmv" expression="full" duration="1326" fileSize="162366459" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_Zune_ch9.wmv" expression="full" duration="1326" fileSize="104040077" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_512_ch9.png" expression="full" duration="1326" type="image/jpeg" medium="image" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/5/2/7/3/9/4/cisfTech_ch9.wmv" length="192376149" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Connected-Information-Security-Framework-Core-Components/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/493725/Trackback.aspx</trackback:ping><category>cisf</category><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category></item><item><title>CISF: Build Custom Security Solutions</title><description>&lt;img src="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_85_ch9.png" border="0" /&gt;Mark Curphey and Marius Grigoriu, from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; talk about the release of the first version of &lt;b&gt;C&lt;/b&gt;onnected &lt;b&gt;I&lt;/b&gt;nformation &lt;b&gt;S&lt;/b&gt;ecurity &lt;b&gt;F&lt;/b&gt;ramework (CISF).  A software development framework comprising of API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions like &lt;a href="http://edge.technet.com/Media/Risk-Tracker/" target="_blank"&gt;Risk Tracker&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Microsoft’s IT Information Security Tools Team designs and develops CISF to “engineer the security delta” meaning as a way to rapidly meet business requirements and create functionality that doesn’t exist or is not yet available in their product range.&lt;br /&gt;
&lt;br /&gt;
They explain benefits found on this framework including:
&lt;ul&gt;
    &lt;li&gt;Building information security applications cheaper, faster, and better &lt;/li&gt;
    &lt;li&gt;Migrate applications efficiently and effectively to their products when they become available &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To learn more about this framework and stay up to date on the latest news, read the following blogs from &lt;a href="http://blogs.msdn.com/infosec/archive/tags/CISF/default.aspx" target="_blank"&gt;Information Security&lt;/a&gt; and previous posts from the  &lt;a href="http://blogs.msdn.com/securitytools/archive/tags/CISF/default.aspx" target="_blank"&gt;Security Tools Team&lt;/a&gt; blog. &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://cisf.codeplex.com/" target="_blank"&gt;CISF CTP download&lt;/a&gt; &lt;/p&gt;&lt;img src="http://channel9.msdn.com/492501/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/</comments><link>http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/</link><pubDate>Fri, 18 Sep 2009 03:31:00 GMT</pubDate><guid isPermaLink="false">http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.wmv</guid><evnet:views>3876</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/492501/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Mark Curphey and Marius Grigoriu, from &lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security,&lt;/a&gt; talk about the release of the first version of &lt;b&gt;C&lt;/b&gt;onnected &lt;b&gt;I&lt;/b&gt;nformation &lt;b&gt;S&lt;/b&gt;ecurity &lt;b&gt;F&lt;/b&gt;ramework (CISF).  A software development framework comprising of API’s and reusable components that is designed to create bespoke or custom information security and risk management solutions like &lt;a href="http://edge.technet.com/Media/Risk-Tracker/" target="_blank"&gt;Risk Tracker&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;</evnet:previewtext><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_320_ch9.png" height="240" width="320" /><media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_85_ch9.png" height="64" width="85" /><media:group><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.mp4" expression="full" duration="1182" fileSize="102375658" type="video/mp4" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.mp3" expression="full" duration="1182" fileSize="9464808" type="audio/mp3" medium="audio" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.mp4" expression="full" duration="1182" fileSize="102375658" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.wma" expression="full" duration="1182" fileSize="9575715" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.wmv" expression="full" duration="1182" fileSize="231270127" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_2MB_ch9.wmv" expression="full" duration="1182" fileSize="369989037" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_Zune_ch9.wmv" expression="full" duration="1182" fileSize="128822055" type="video/x-ms-wmv" medium="video" /><media:content url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_512_ch9.png" expression="full" duration="1182" type="image/jpeg" medium="image" /></media:group><enclosure url="http://ecn.channel9.msdn.com/o9/ch9/1/0/5/2/9/4/CISFoverview_ch9.wmv" length="231270127" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/CISF-Build-Custom-Security-Solutions/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/492501/Trackback.aspx</trackback:ping><category>cisf</category><category>information security</category><category>infosec</category><category>ist</category><category>Security</category><category>Tools</category></item><item><title>SDL-LOB Phase 3: Implementation</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_small_ch9.png" border="0" /&gt;&lt;span id="ctl00_MainPlaceHolder_Starter_BodyLabel"&gt;The third phase of the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank"&gt;&lt;span&gt;SDL-LOB &lt;/span&gt;&lt;/a&gt;(Security Development Lifecycle for Line-of-Business applications) includes &lt;span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd831972.aspx" target="_blank"&gt;&lt;span&gt;Implementation&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Eugene Siu, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes some of the security pillars that are key in this phase, including code review, authentication, authorization and configuration settings. Also, he explains how penetration testing can complement your code review when bulletproofing your code against vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
Read more on the Implementation Phase &lt;a href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" target="_blank"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;/span&gt;&lt;img src="http://channel9.msdn.com/479451/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/SDL-LOB-Phase-3-Implementation/</comments><link>http://channel9.msdn.com/posts/Jossie/SDL-LOB-Phase-3-Implementation/</link><pubDate>Mon, 20 Jul 2009 17:54:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wmv</guid><evnet:views>5089</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/479451/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;span id="ctl00_MainPlaceHolder_Starter_BodyLabel"&gt;The third phase of the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank"&gt;&lt;span&gt;SDL-LOB &lt;/span&gt;&lt;/a&gt;(Security Development Lifecycle for Line-of-Business applications) includes &lt;span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd831972.aspx" target="_blank"&gt;&lt;span&gt;Implementation&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Eugene Siu, from Microsoft Information Security, describes some of the security pillars that are key in this phase, including code review, authentication, authorization and configuration settings. Also, he explains how penetration testing can complement your code review when bulletproofing your code against vulnerabilities.&lt;/span&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp4" expression="full" duration="1099" fileSize="81603875" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp3" expression="full" duration="1099" fileSize="8798169" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.mp4" expression="full" duration="1099" fileSize="81603875" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wma" expression="full" duration="1099" fileSize="17803689" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wmv" expression="full" duration="1099" fileSize="154844037" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_2MB_ch9.wmv" expression="full" duration="1099" fileSize="134509761" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_Zune_ch9.wmv" expression="full" duration="1099" fileSize="97484017" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/5/4/9/7/4/lobSDLdev_ch9.wmv" length="154844037" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/SDL-LOB-Phase-3-Implementation/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/479451/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>development</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category></item><item><title>Anti-XSS 3.0 Released</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_small_ch9.png" border="0" /&gt;&lt;p&gt;Vineet Batta and Anil Revuru (RV), from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, talk about the release of the new version of the Anti-XSS library, which is designed to encode output to help developers protect their ASP.NET web-based applications from cross-site scripting attacks.&lt;br /&gt;
&lt;br /&gt;
They explain the new features and benefits found on version 3.0, including:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Extended white list &lt;/li&gt;
    &lt;li&gt;Better performance &lt;/li&gt;
    &lt;li&gt;MSDN Style Help documentation &lt;/li&gt;
    &lt;li&gt;Marked Anti-XSS Output &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine (SRE) &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To learn more about this library read the following blogs from the &lt;a href="http://blogs.msdn.com/securitytools/archive/tags/Anti-XSS/default.aspx" target="_blank"&gt;Security Tools Team blog&lt;/a&gt; and previous &lt;a href="http://blogs.msdn.com/cisg/archive/tags/Anti-XSS/default.aspx" target="_blank"&gt;posts&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://channel9.msdn.com/478820/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/</comments><link>http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/</link><pubDate>Wed, 15 Jul 2009 16:12:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv</guid><evnet:views>6139</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/478820/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Vineet Batta and Anil Revuru (RV), from Microsoft Information Security, talk about the release of the new version of the Anti-XSS library, which is designed to encode output to help developers protect their ASP.NET web-based applications from cross-site scripting attacks. &lt;br /&gt;
&lt;br /&gt;
They explain the new features and benefits found on version 3.0, including: &lt;br /&gt;
&lt;ul&gt;
    &lt;li&gt;Extended white list &lt;/li&gt;
    &lt;li&gt;Better performance &lt;/li&gt;
    &lt;li&gt;MSDN Style Help documentation &lt;/li&gt;
    &lt;li&gt;Marked Anti-XSS Output &lt;/li&gt;
    &lt;li&gt;Security Runtime Engine (SRE) &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt; &lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp4" expression="full" duration="1055" fileSize="79917703" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp3" expression="full" duration="1055" fileSize="8447064" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.mp4" expression="full" duration="1055" fileSize="79917703" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_ch9.wma" expression="full" duration="1055" fileSize="17085733" type="audio/x-ms-wma" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv" expression="full" duration="1055" fileSize="47180833" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_Zune_ch9.wmv" expression="full" duration="1055" fileSize="103371753" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv" expression="full" duration="1055" fileSize="47180833" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/0/2/8/8/7/4/antixss3_2MB_ch9.wmv" length="47180833" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/478820/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>antixss</category><category>information security</category><category>infosec</category><category>ist</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>Tools</category></item><item><title>Silverlight 2 Security</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_small_ch9.png" border="0" /&gt;The usage of Silverlight to provide users a rich internet experience continues to increase. As it becomes a key element on our web applications, it is good to keep in mind that it still runs code on the user's machine.&lt;br /&gt;
&lt;br /&gt;
That is why Maqbool Malik, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes some key features added on the second version of Silverlight to enhance security.&lt;br /&gt;
&lt;br /&gt;
Among the features discussed, Maqbool talks about XAP files, cross-domain policy files, HTML access, etc.&lt;img src="http://channel9.msdn.com/477261/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Silverlight-20-Security/</comments><link>http://channel9.msdn.com/posts/Jossie/Silverlight-20-Security/</link><pubDate>Tue, 14 Jul 2009 00:43:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.wmv</guid><evnet:views>7391</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477261/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>The usage of Silverlight to provide users a rich internet experience continues to increase. As it becomes a key element on our web applications, it is good to keep in mind that it still runs code on the user's machine.&lt;br /&gt;
&lt;br /&gt;
That is why Maqbool Malik, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes some key features added on the second version of Silverlight to enhance security.&lt;br /&gt;
&lt;br /&gt;
Among the features discussed, Maqbool talks about XAP files, cross-domain policy files, HTML access, etc.</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.mp4" expression="full" duration="1120" fileSize="110340362" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.mp3" expression="full" duration="1120" fileSize="8961987" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.mp4" expression="full" duration="1120" fileSize="110340362" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.wma" expression="full" duration="1120" fileSize="18134129" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.wmv" expression="full" duration="1120" fileSize="158924157" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_2MB_ch9.wmv" expression="full" duration="1120" fileSize="136994891" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_Zune_ch9.wmv" expression="full" duration="1120" fileSize="145052137" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/6/2/7/7/4/silverlightSec_ch9.wmv" length="158924157" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Silverlight-20-Security/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/477261/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>Security</category><category>Silverlight 2</category></item><item><title>Threat Modeling LOB Applications with TAM 3.0</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_small_ch9.png" border="0" /&gt;&lt;p&gt;Andrew Law, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, walks us through the creation of a threat model for a line-of-business application using the Threat Analysis &amp;amp; Modeling tool version 3.0. This screencast includes the definition and purpose of a threat model as well as its alignment with the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank"&gt;SDL-LOB&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;Threat Model ownership is discussed as well as the use of the central repository, common task list and how to leverage them to automatically generate threats.&lt;/p&gt;
&lt;p&gt;Learn more on the &lt;a href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" target="_blank"&gt;Threat Modeling&lt;/a&gt; site &amp;amp; &lt;a href="http://blogs.msdn.com/securitytools" target="_blank"&gt;Information Security Tools&lt;/a&gt; blog.&lt;/p&gt;&lt;img src="http://channel9.msdn.com/477063/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30/</comments><link>http://channel9.msdn.com/posts/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30/</link><pubDate>Mon, 06 Jul 2009 22:38:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wmv</guid><evnet:views>3297</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477063/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;Andrew Law, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, walks us through the creation of a threat model for a line-of-business application using the Threat Analysis &amp;amp; Modeling tool version 3.0. This screencast includes the definition and purpose of a threat model as well as its alignment with the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank"&gt;SDL-LOB&lt;/a&gt;. &lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp4" expression="full" duration="2925" fileSize="77895311" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp3" expression="full" duration="2925" fileSize="23406707" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.mp4" expression="full" duration="2925" fileSize="77895311" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wma" expression="full" duration="2925" fileSize="47320993" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wmv" expression="full" duration="2925" fileSize="127654993" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_2MB_ch9.wmv" expression="full" duration="2925" fileSize="132391501" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_Zune_ch9.wmv" expression="full" duration="2925" fileSize="97750973" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/6/0/7/7/4/tam3onLOB_ch9.wmv" length="127654993" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Threat-Modeling-LOB-Applications-with-TAM-30/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/477063/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>tam</category><category>threat modeling</category><category>Tools</category></item><item><title>SQL Detect</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_small_ch9.png" border="0" /&gt;SQL Detect is a SQL injection filter in real-time mode. When a request happens in the application the tool applies different heuristics to the data and tries to identify the attack. After the request is validated it proceeds.&lt;br /&gt;
&lt;br /&gt;
Maqbool Malik, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes how this is one of the tools to be included in the to-be-released Security Runtime Engine (SRE).&lt;br /&gt;
&lt;br /&gt;
To learn more about their tools, read the &lt;a href="http://blogs.msdn.com/securitytools/" target="_blank"&gt;Information Security Tools&lt;/a&gt; blog.&lt;br /&gt;
&lt;br /&gt;&lt;img src="http://channel9.msdn.com/477052/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/SQL-Detect/</comments><link>http://channel9.msdn.com/posts/Jossie/SQL-Detect/</link><pubDate>Mon, 06 Jul 2009 19:41:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wmv</guid><evnet:views>6062</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477052/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>SQL Detect is a SQL injection filter in real-time mode. When a request happens in the application the tool applies different heuristics to the data and tries to identify the attack. After the request is validated it proceeds.&lt;br /&gt;
&lt;br /&gt;
Maqbool Malik, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, describes how this is one of the tools to be included in the to-be-released Security Runtime Engine (SRE).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp4" expression="full" duration="734" fileSize="45367124" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp3" expression="full" duration="734" fileSize="5880981" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.mp4" expression="full" duration="734" fileSize="45367124" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wma" expression="full" duration="734" fileSize="11897825" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wmv" expression="full" duration="734" fileSize="95065847" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_2MB_ch9.wmv" expression="full" duration="734" fileSize="89893228" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_Zune_ch9.wmv" expression="full" duration="734" fileSize="54601827" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/5/0/7/7/4/SQLdetect_ch9.wmv" length="95065847" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/SQL-Detect/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/477052/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>sre</category><category>Tools</category></item><item><title>Architecture Behind CAT.NET</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_small_ch9.png" border="0" /&gt;&lt;p&gt;Ben Livshits, from Microsoft Research, talks about the architecture behind &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&amp;amp;displaylang=en" target="_blank"&gt;CAT.NET&lt;/a&gt;, which is a static analysis tool on Visual Studio that helps find vulnerabilities like SQL Injection, CSRF,  XSS among others, within managed code. &lt;br /&gt;
&lt;br /&gt;
Ben’s knowledge on static and dynamic dataflow analysis made him a key contributor on the creation of CAT.NET. He walks us through different examples of how the data analysis happens depending on complexity and explains how precision varies. &lt;br /&gt;
&lt;br /&gt;
Learn more about &lt;a href="http://blogs.msdn.com/securitytools/default.aspx" target="_blank"&gt;Microsoft Information Security Tools&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.msinfosec.com"&gt;www.msinfosec.com&lt;/a&gt; &lt;/p&gt;&lt;img src="http://channel9.msdn.com/476042/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Architecture-behind-CATNET/</comments><link>http://channel9.msdn.com/posts/Jossie/Architecture-behind-CATNET/</link><pubDate>Mon, 29 Jun 2009 22:24:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wmv</guid><evnet:views>3002</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/476042/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Ben Livshits, from Microsoft Research, talks about the architecture behind CAT.NET, which is a static analysis tool on Visual Studio that helps find vulnerabilities like SQL Injection, CSRF,  XSS among others, within managed code.   &lt;br /&gt;
&lt;br /&gt;
Ben’s knowledge on static and dynamic dataflow analysis made him a key contributor on the creation of CAT.NET. He walks us through different examples of how the data analysis happens depending on complexity and explains how precision varies.   Learn more about Microsoft Information Security Tools.</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp4" expression="full" duration="1067" fileSize="77800586" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp3" expression="full" duration="1067" fileSize="8540072" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.mp4" expression="full" duration="1067" fileSize="77800586" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wma" expression="full" duration="1067" fileSize="17268977" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wmv" expression="full" duration="1067" fileSize="150763845" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_2MB_ch9.wmv" expression="full" duration="1067" fileSize="130500881" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_Zune_ch9.wmv" expression="full" duration="1067" fileSize="90075825" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/2/4/0/6/7/4/catNET_ch9.wmv" length="150763845" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Architecture-behind-CATNET/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/476042/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>cat.net</category><category>information security</category><category>infosec</category><category>LOB</category><category>rise</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>Tools</category></item><item><title>Threat Analysis &amp; Modeling Tool - TAM 3.0</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_small_ch9.png" border="0" /&gt;Anil Revuru (RV), from &lt;a href="http://blogs.msdn.com/securitytools/default.aspx" target="_blank"&gt;Information Security Tools&lt;/a&gt;, provides an overview of the new version of TAM (Threat Analysis &amp;amp; Modeling), an asset-centric tool which uses an objective methodology to analyze applications for threats and define mitigation plans for them. TAM aligns to the &lt;a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank"&gt;SDL-LOB&lt;/a&gt; as part of the Design phase.&lt;br /&gt;
&lt;br /&gt;
RV describes the new features in this version, including the online repository for the attack countermeasures, automated use cases creation, composite threats, among others.&lt;br /&gt;
&lt;br /&gt;
Learn more:&lt;br /&gt;
&lt;ol&gt;
    &lt;li&gt;&lt;a href="http://www.msinfosec.com/" target="_blank"&gt;Microsoft Information Security&lt;/a&gt; &lt;/li&gt;
    &lt;li&gt;&lt;a href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" target="_blank"&gt;TAM Tool Site&lt;/a&gt;  &lt;/li&gt;
&lt;/ol&gt;&lt;img src="http://channel9.msdn.com/476038/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Thread-Analysis--Modeling-Tool-TAM-30/</comments><link>http://channel9.msdn.com/posts/Jossie/Thread-Analysis--Modeling-Tool-TAM-30/</link><pubDate>Mon, 29 Jun 2009 20:43:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wmv</guid><evnet:views>5328</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/476038/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Anil Revuru (RV), from Information Security Tools, provides an overview of the new version of TAM (Threat Analysis &amp;amp; Modeling), an asset-centric tool which uses an objective methodology to analyze applications for threats and define mitigation plans for them. TAM aligns to the SDL-LOB as part of the Design phase.&lt;br /&gt;
&lt;br /&gt;
RV describes the new features in this version, including the online repository for the attack countermeasures, automated use cases creation, composite threats, among others.</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.mp4" expression="full" duration="961" fileSize="65596326" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.mp3" expression="full" duration="961" fileSize="7697076" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.mp4" expression="full" duration="961" fileSize="65596326" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wma" expression="full" duration="961" fileSize="15574721" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wmv" expression="full" duration="961" fileSize="131291209" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_2MB_ch9.wmv" expression="full" duration="961" fileSize="117606784" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_Zune_ch9.wmv" expression="full" duration="961" fileSize="79195189" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/8/3/0/6/7/4/TAM3_ch9.wmv" length="131291209" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Thread-Analysis--Modeling-Tool-TAM-30/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/476038/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category><category>tam</category><category>threat modeling</category><category>Tools</category></item><item><title>Security Design Reviews</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_small_ch9.png" border="0" /&gt;Security is not something we just add at the end of the implementation phase...it should be &lt;em&gt;baked&lt;/em&gt; into the application all the way from design. &lt;br /&gt;
&lt;br /&gt;
Anmol Malhotra, from &lt;a href="http://www.msinfosec.com" target="_blank"&gt;Microsoft Information Security&lt;/a&gt;, provides more than enough reasons why Security Design Reviews make sense and why they are so important...let him walk you through the SDLC phases and how security tasks are found in each step.&lt;br /&gt;
&lt;br /&gt;
To learn more about security on line-of-business applications using the SDL-LOB go &lt;a href="http://msdn.microsoft.com/en-us/library/dd831970.aspx" target="_blank"&gt;here&lt;/a&gt;.&lt;img src="http://channel9.msdn.com/475065/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/</comments><link>http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/</link><pubDate>Wed, 24 Jun 2009 16:07:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.wmv</guid><evnet:views>5335</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/475065/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Security is not something we just add at the end of the implementation phase...it should be baked into the application all the way from design. &lt;br /&gt;
&lt;br /&gt;
Anmol Malhotra, from Microsoft Information Security, provides more than enough reasons why Security Design Reviews make sense and why they are so important...let him walk you through the SDLC phases and how security tasks are found in each step.</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp4" expression="full" duration="1083" fileSize="106866291" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp3" expression="full" duration="1083" fileSize="8670049" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp4" expression="full" duration="1083" fileSize="106866291" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp3" expression="full" duration="1083" fileSize="8670049" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.wmv" expression="full" duration="1083" fileSize="153867941" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_2MB_ch9.wmv" expression="full" duration="1083" fileSize="263445138" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_Zune_ch9.wmv" expression="full" duration="1083" fileSize="153579921" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.mp4" expression="full" duration="1083" fileSize="106866291" type="video/mp4" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/5/6/0/5/7/4/designRev_ch9.wmv" length="153867941" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/475065/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>LOB</category><category>SDL</category><category>sdl-lob</category><category>Security</category></item><item><title>ACE's Performance Development Lifecycle for IT (PDL-IT)</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_small_ch9.png" border="0" /&gt;&lt;p align="justify"&gt;Microsoft ACE team has been involved in performance testing and tuning of web applications within Microsoft and externally for several years now. &lt;a href="http://www.msinfosec.com" title="Microsoft Information Security" target="_blank"&gt;Microsoft's Information Security&lt;/a&gt; - ACE Performance has been using a methodology which they have now formalized as PDL-IT (Performance Development Lifecycle for IT) which consists of a proactive approach for application performance within the SDLC.&lt;br /&gt;
&lt;br /&gt;
Irfan Chaudhry, Director of InfoSec's ACE Team, explains this methodology after being part of ACE for 8 years and having started as a Performance Analyst himself. &lt;br /&gt;
&lt;br /&gt;
If you want to learn more about PDL-IT, you can read more on the &lt;a href="http://blogs.msdn.com/ace_team/default.aspx" title="ACE Team Blog" target="_blank"&gt;ACE Team&lt;/a&gt; blog in a &lt;a href="http://blogs.msdn.com/ace_team/archive/2009/03/04/performance-development-life-cycle-for-it-part-1.aspx" title="PDL-IT Post #1" target="_blank"&gt;series of posts&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://channel9.msdn.com/463611/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/ACEs-Performance-Development-Lifecycle-for-IT-PDL-IT/</comments><link>http://channel9.msdn.com/posts/Jossie/ACEs-Performance-Development-Lifecycle-for-IT-PDL-IT/</link><pubDate>Fri, 03 Apr 2009 16:29:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.wmv</guid><evnet:views>2281</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/463611/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Microsoft ACE team has been involved in performance testing and tuning of web applications within Microsoft and externally for several years now. Microsoft's Information Security - ACE Performance has been using a methodology which they have now formalized as PDL-IT (Performance Development Lifecycle for IT) which consists of a proactive approach for application performance within the SDLC.</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.mp4" expression="full" duration="873" fileSize="86143172" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.mp3" expression="full" duration="873" fileSize="667" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.mp4" expression="full" duration="873" fileSize="86143172" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.wma" expression="full" duration="873" fileSize="14138809" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.wmv" expression="full" duration="873" fileSize="52906681" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_2MB_ch9.wmv" expression="full" duration="873" fileSize="273339205" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_Zune_ch9.wmv" expression="full" duration="873" fileSize="114746661" type="video/x-ms-wmv" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/1/6/3/6/4/PDLIT_ch9.wmv" length="52906681" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/ACEs-Performance-Development-Lifecycle-for-IT-PDL-IT/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/463611/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information security</category><category>infosec</category><category>pdl-it</category><category>performance</category></item><item><title>Application Performance Reviews: ACE Team</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_small_ch9.png" border="0" /&gt;&lt;p&gt;The Assessment Consulting &amp;amp; Engineering (ACE) team, part of the &lt;a href="http://msdn.microsoft.com/en-us/security/dd547422.aspx" title="Microsoft Information Security" target="_blank"&gt;Microsoft Information Security&lt;/a&gt; group, assesses the performance of Microsoft applications.  Principal Performance Manager, K.M. Lee, discusses his team's methodology after many years of experience on this area which keeps evolving as technology changes.  K.M. also describes how they have taken their knowledge into the field to Microsoft customers and partners as well as how they are taking the next step by creating performance review tools.&lt;/p&gt;
&lt;p&gt;For more information on the tool K.M. mentions, neXpert see: &lt;a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;amp;EventID=1032398774&amp;amp;CountryCode=US"&gt;webcast&lt;/a&gt;, &lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=5975da52-8ce6-48bd-9b3c-756a625024bb"&gt;download&lt;/a&gt;&lt;/p&gt;&lt;img src="http://channel9.msdn.com/459476/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://channel9.msdn.com/posts/Jossie/Application-Performance-Reviews-ACE-Team/</comments><link>http://channel9.msdn.com/posts/Jossie/Application-Performance-Reviews-ACE-Team/</link><pubDate>Wed, 04 Mar 2009 01:20:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.wmv</guid><evnet:views>2417</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/459476/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;The Assessment Consulting &amp;amp; Engineering (ACE) team, part of the Microsoft Information Security group, assesses the performance of Microsoft applications.  Principal Performance Manager, K.M. Lee, discusses his team's methodology after many years of experience on this area which keeps evolving as technology changes.  K.M. also describes how they have taken their knowledge into the field to Microsoft customers and partners as well as how they are taking the next step by creating performance review tools.&lt;/p&gt;</evnet:previewtext><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_large_ch9.png" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_small_ch9.png" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.mp4" expression="full" duration="714" fileSize="70573660" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.mp3" expression="full" duration="714" fileSize="5719899" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.mp4" expression="full" duration="714" fileSize="70573660" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.wma" expression="full" duration="714" fileSize="11579399" type="audio/x-ms-wma" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.wmv" expression="full" duration="714" fileSize="43097725" type="video/x-ms-wmv" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.wmv" expression="full" duration="714" fileSize="43097725" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_2MB_ch9.wmv" expression="full" duration="714" fileSize="223882243" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_Zune_ch9.wmv" expression="full" duration="714" fileSize="56473705" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.mp4" expression="full" duration="714" fileSize="70573660" type="video/mp4" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/6/7/4/9/5/4/aceperf_ch9.wmv" length="43097725" type="video/x-ms-wmv" /><dc:creator>Jossie Tirado</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://channel9.msdn.com/posts/Jossie/Application-Performance-Reviews-ACE-Team/RSS/</wfw:commentRss><trackback:ping>http://channel9.msdn.com/459476/Trackback.aspx</trackback:ping><category>ace</category><category>ace team</category><category>information</category><category>infosec</category><category>nexPert</category><category>performance</category><category>Security</category></item></channel></rss>