Posts by SealingTech
Understanding PCI DSS and the Importance of Compliance
The Payment Card Industry Data Security Standard (PCI DSS) was originally established in 2004 as a standardization of security practices for any organization that handles or uses payment collection via credit cards. This standardization is required by all major credit card carriers and is regulated by the Payment Card Security Standards Council (PCI SSC). This…
Read MoreDefensive Cyber Operations: Ground Zeroes
In an era plagued by thieves, criminals, and script kiddies, the need for securing information has increased exponentially. The market is teeming with products that are advertised to adequately secure your systems, data stores, sensitive information, etc. independently or in tandem with a bevy of other products. In the modern business world, global, interconnected networks…
Read MoreCMMI SVC Level 3 Appraisal
SealingTech recently went through a CMMI Level 3 appraisal for Services. If you’ve never heard of CMMI, it stands for Capability Maturity Model Integration and Level 3 is one of five “Maturity Levels” in the CMMI model, known as the “Defined” level. Essentially, all of our company processes and procedures were reviewed for each of…
Read MoreCloud Security (Part 1): Passive Security Monitoring in RackSpace
This is Part 1 of our “Cloud Security” series, with a goal of setting up a simple passive security monitoring capability in the cloud. Future posts will show how to enable out-of-band management, as well as setting up the monitoring services themselves. Enjoy!
Read MoreSANS 2018 Holiday Hack Challenge
Here at SealingTech we are proud to have a team of engineers who are constantly challenging themselves and each other at work and in their free time! You may recall several other challenges we have blogged about such as Kevin’s work on the IXIA Breaking Point Network Profiles challenge, or Scott and Tony’s solutions for the Cloudshark Halloween PCAP…
Read MoreTrick or Treat: Halloween PCAP Challenge from Cloudshark
TL;DR During Halloween, a company called Cloudshark released a Packet Capture challenge that involved finding hidden “pumpkins” that were hidden in packets. Two SealingTech employees, Tony Efantis and Scott Lohin, participated in the challenge and found all five pumpkins. This challenge was a lot of fun, and we thank Cloudshark for creating it for the…
Read MoreHow to Script Large Ixia Breaking Point Network Profiles
Background My team at SealingTech was tasked with testing the performance of a router that would be a tunnel endpoint for many different Site to Site VPN connections from various places. We were given requirements that it needed to support thousands of tunnels and VRFs and lots of bandwidth (upwards of 20 Gb/s). We had…
Read MoreHost Based Risk Scoring (Part 2): Calculating the Vulnerability Level of a System
This is Part 2 of the Host Based Risk Scoring series. If you haven’t checked out Part 1, check out the post at Host Based Risk Scoring (Part 1). Please note that information in these articles are taken from my personal ideas and experience. I’d love to hear your comments and thoughts on these concepts.…
Read MoreAdventures in Suricata (Part 1): Low Cost Intrusion Detection System
Welcome to the Adventures in Suricata series! Over the past couple months I have been exploring Suricata, an open source Intrusion Detection System (IDS), by standing it up in my virtualized ESXi server at home. By sharing my own experiences with you, I hope to overcome the misconception that IDS is only viable for large…
Read More