Slashdot Mirror


The Spinning Cube of Potential Doom

An anonymous reader writes "This month's Communications of the ACM (does not seem to have a link to online text) has an article about The Spinning Cube of Potential Doom, a security visualization tool that I first saw at SC2003. The cube displays data from Bro along 3 axes and creates interesting visual results (port scans, barber poles, lawnmower). This definitely makes patterns in all that 'boring log data' jump out. This is a very interesting development, the ability to monitor in real time and replay historical security related information. Definitely a step towards the new types of tools we will need to secure hosts and networks."

161 comments

  1. Security is only one possible area for innovation by CreamOfWheat · · Score: 5, Interesting

    When the eventual goal of having this data displayed in a real time setting the applications of usefulness will be startling. Data that had to be updated manually during the conference, will be available to researchers to do tci-square analysis to approximate the optimum network efficencies. Even use in the business sector and th ability to analyze huge databases will be quite amazing, although at least a half-decade down the road. Besides the primary educational aspect of the Cube, the secondary goal of the Cube will see fruition as to how investigate new techniques in visually analyzing network traffic and also to develop a tool that would potentially assist those involved with computer security. Really fascinating stuff.

  2. Too bad... by kdougherty · · Score: 4, Funny

    Too bad Cisco didn't have this a couple weeks ago when they needed it!

    --
    The best way to predict the future is to invent it. -Alan Kay
  3. dude! by eegad · · Score: 5, Funny

    I live in the spinning cube of potential doom. At least that's what my co-workers call it.

    1. Re:dude! by orthogonal · · Score: 3, Funny
      I live in the spinning cube of potential doom. At least that's what my co-workers call it.

      It sounds like something "Robert S." Rumsfeld would use to "persuade" "designated terrorists" in Abu Ghraib to talk.

      I guess the use of "potential" in the title reminds me of so-called "Rumsfled Poetry":
      "As we know,
      There are known knowns.
      There are things we know we know.
      We also know
      There are known unknowns.
      That is to say
      We know there are some things
      We do not know.
      But there are also unknown unknowns,
      The ones we don't know
      We don't know."
      --Rumsfeld, at a February 12, 2002, Department of Defense news briefing
    2. Re:dude! by tunabomber · · Score: 1

      Spinning, eh? That shouldn't be. Perhaps they should take away your swiveling chairs.

      --

      pi = 3.141592653589793helpimtrappedinauniversefactory71 ...
    3. Re:dude! by Anonymous Coward · · Score: 0

      Every time someone posts this, I'm reminded of the scene is Mystery Men:

      Capt. Amazing: I knew you couldn't change.
      Casanova Frankenstein: I knew you'd know that.
      Capt. Amazing: Oh, I know that. And I knew you'd know I'd know you knew.
      Casanova Frankenstein: But I didn't. I only knew that you'd know that I knew. Did you know that?
      Capt. Amazing: ... Of course!

    4. Re:dude! by Koatdus · · Score: 1

      I never figured out why people have such a hard time understanding what he is trying to say here.

      He is saying that there are some things we know and some we don't.

      Some of the things that we don't know, we at least know exist. Therefore, even though we don't know the details yet, we can keep a general watch on that area/group/situation and gather data.

      The dangerious ones are the ones that we are completely unaware of, have not thought of, and are not even looking for. They are the ones that will sneak up on us and cause the most damage.

      It is not that hard! Whether or not they agree with or like Rumsfeld anyone who says that they don't understand is either stupid, or doesn't want to understand it, or has an agenda and thinks that you are too stupid to understand it.

      --
      Every wrong attempt discarded is a step forward - T. Edison
    5. Re:dude! by DerekLyons · · Score: 2, Insightful
      I guess the use of "potential" in the title reminds me of so-called "Rumsfled Poetry":
      If you've ever taken a logic or philosophy class, or seriously studied science, or have been formally trained in troubleshooting real mission critical hardware/software (by that I mean the Space Shuttle, or a nuclear submarine, or a nuclear weapon, not your sales database)... Then that 'poetry' makes perfect sense.

      Matter of fact, I used to say something much like that to the techs I was training to work on nuclear tipped missiles. So did the guys who taught me ASW. So did the official documents used to learn ASW tactics... In all of these these things, failing to take care to make sure that all your unknowns are known, or at least accounted for, can kill.

      It only sounds ignorant to the ignorant.

  4. Spinning Cube of Doom? by stratjakt · · Score: 5, Funny

    Sounds like the Time Cube.

    But then, you stupid ignorant mind-traitors cant understand time cube having been manipulated by your word god.

    --
    I don't need no instructions to know how to rock!!!!
    1. Re:Spinning Cube of Doom? by Anonymous Coward · · Score: 1, Funny

      I'd rather just play GameCube.

    2. Re:Spinning Cube of Doom? by jayhawk88 · · Score: 1

      Still the greatest webpage on the Internet.

    3. Re:Spinning Cube of Doom? by pseudochaotic · · Score: 1

      Creation of 4 simultaneous 24 hour days, within a single rotation of Earth, empowers me above all 1-day gods and educated stupid scientists. I will wager $10,000.00 on it.

      Seeing that his name and address are in the whois DB, maybe we should try to figure out what he's saying and take him up on that?

      --
      And the l33t shall inherit the 34r7h.
    4. Re:Spinning Cube of Doom? by qengho · · Score: 1


      maybe we should try to figure out what he's saying and take him up on that?

      Good luck with that. I'm still not sure if he's serious or not. Either way, it's vastly entertaining. He seems to have become a lot more cranky since I last checked in, about a year ago.

    5. Re:Spinning Cube of Doom? by Anonymous Coward · · Score: 0

      I was always partial to the God is the Einstein curvature tensor pages myself.

    6. Re:Spinning Cube of Doom? by Koatdus · · Score: 1
      From the Time Cube link:

      Hey stupid - are you too dumb to know there are 4 different simultaneous 24 hour days within a single rotation of earth?


      This guy needs to re-think his rant. We divide The Earth into twenty four time zones not four so that by his own definition there are twenty four different simultaneous 24 hour days within a single rotation of earth, not four.

      --
      Every wrong attempt discarded is a step forward - T. Edison
    7. Re:Spinning Cube of Doom? by Tokerat · · Score: 1


      I thought of this too, but I thought of it become of this Bonus Stage episode called "Cube" (warning: direct Flash file link).

      I figured I could live with plugging this, as it's slightly on topic under context, and it is one of my fav. Flash toon series. (If you're interested, High Score is the website)

      --
      CAn'T CompreHend SARcaSm?
    8. Re:Spinning Cube of Doom? by Anonymous Coward · · Score: 0

      You are probably brainwashed, indoctrinated, educated stupid and cannot comprehend Nature's Harmonic Simultaneous 4-Day Perpetual Time Cube Creation. When the Sun shines upon Earth, 2 - major Time points are created on opposite sides of Earth - known as Midday and Midnight. Where the 2 major Time forces join, synergy creates 2 new minorTime points we recognize as Sunup and Sundown. The 4-equidistant Time points can be considered as Time Square imprinted upon the circle of Earth. In a single rotation of the Earth sphere, each Time corner point rotates through the other 3-corner Time points, thus creating 16 corners, 96 hours and 4-simultaneous 24 hour Days within a single rotation of Earth - equated to a Higher Order of Life Time Cube. Ignorance of the Time Cube is evil.

    9. Re:Spinning Cube of Doom? by awtbfb · · Score: 1

      Actually, it sounds more like what happens when you get too close to the the Cube when walking around the University of Michigan. It makes one wonder if the developers went to UM.

      As an aside, try to remember to stay away from the Cube when drinking in Ann Arbor. It seems your ability to estimate the danger of a large spinning mass of metal goes down when you're inebriated.

    10. Re:Spinning Cube of Doom? by Art+Tatum · · Score: 1
      I immediately thought of this site as well.

      This guy's schizophrenic. He has no idea how odd he sounds. To him, everybody else around him is just oppressing him. And the more of that he gets, the more convinced he is of a conspiracy to hide the "hidden truth" he's found. It's really kind of sad.

  5. Need new tool by nizo · · Score: 5, Funny

    Now we need tools that scan in a pattern that causes little devil faces to appear inside the cube, just to freak the sysadmin out. Words could be fun too.

    1. Re:Need new tool by garcia · · Score: 1

      just hook this thing up to the fBSD webserver when it is posted on /.

      Two birds with one stone.

  6. Disappointment... by The+Human+Cow · · Score: 5, Funny

    Man, when I heard it could display data along 3 axes I was hoping for a error message featuring a little projection of somebody saying "Help me Obi-Wan Kenobi, you're my only hope."
    Sad.

    --
    The Human Cow - bringing you scrumtrelescence since 1995
    1. Re:Disappointment... by Too+Much+Noise · · Score: 1

      Then your neighbor Ben Kenobi would smack you with a DMCA-style lawsuit for unauthorized interception and decryption of a private message. On Earth, you're better off without it ^_^

  7. Can anyone explain the data we're seeing? by Goobermunch · · Score: 2, Insightful

    Okay, so I see the pretty pictures, but what do they mean. Can anyone explain how to interpret that data?

    --AC

    1. Re:Can anyone explain the data we're seeing? by Goobermunch · · Score: 1

      Okay, I'm a tool. It helps if you click on all the links in the post, not just the pictures. I thought it was weird when I saw the cube picture twice . . . .

      --AC

    2. Re:Can anyone explain the data we're seeing? by entrager · · Score: 1

      I think this goes without saying: RTFA.

      But for the lazy. The vertical axis is port and the horizontal axis is IP. So the vertical line is a port scan, a horizontal line is a scan across all IPs for a specific open port. The "barber pole" scans show an interesting technique in which a scan increments both IP and port with each attempt, obviously in order to fool detection mechanisms. The "lawnmower scan" is a multi-IP port scan, which creates a rectangle.

    3. Re:Can anyone explain the data we're seeing? by upside · · Score: 4, Informative

      It sets three variables onto three axes to show network traffic between your network and the net:

      1) Your IP range
      2) The entire IP range
      3) Destination port

      It's useful for things like picking up semirandom port scans that you might not detect based on textual data (see "barber poles").

      Entire para:

      "The Cube takes this connection information stored in the Bro files and displays it in a graphical format which can be more readily understood by people who are unfamiliar with networking and computer security techniques. The 'X' axis of the display (shown in red) represented the SCinet address space, which ranged from 141.221.128.0 - 141.221.255.255. The 'Z' axis (shown in blue) represented all possible IP address space (0.0.0.0 - 223.255.255.255). Multicast traffic (224.0.0.0 and above) was not displayed. The 'Y' axis (shown in green) represented the port number number (0-65535). Some well known port numbers include 22 (ssh), 25 (smtp), 80 (http). "

      --
      I'm sorry if I haven't offended anyone
    4. Re:Can anyone explain the data we're seeing? by Have+Blue · · Score: 3, Insightful
      The cube displays 3 pieces of information (assuming you know how TCP works):
      • The X axis represents the local IP. Every computer on the LAN is at a unique location on this line.
      • The Z axis represents all possible IP addresses. Every computer in the *world* is a unique location on that line, so every possible connection that can be made between a SCinet computer and an external system is somewhere on the "floor" of the cube. Think of it like an old phone switchboard.
      • The Y axis represents the port number, so as two computers establish multiple TCP connections to each other they "stack" and move up towards the top of the cube.
      The upshot of all this is that all network activity on the LAN during a specific time period can be placed in this cube. And once it's here in visual form, it becomes easy for a human operator to apply our brain's pattern recognition abilities to the problem of noticing unusual activity, which is hard to do with just a text dump from a normal IDS. Normal Internet usage would be a single point, or a small vertical line, which would represent a single persistent TCP connection for a specific service (for SSH or something) or a small number of TCP connections established momentarily (for a stateless protocol like HTTP), and this can be seen in the example as a lot of random dots scattered throughout the cube.

      If there was an attack in progress, it would be some sort of procedural scan from one external system (a single Z location, or a constant depth in the example) across the LAN address space (going left to right) and/or the ports on a single LAN system (going up and down). A simple port scan would be a solid vertical line, as the attacker hit each port on a single system in sequence (Z and X constant, Y varying). I think there's one of these visible in the example, in the back; this short vertical line would be an attacker hitting all the privileged service ports between 0 and 1024. A more advanced attack pattern would attempt to randomize the ports it scanned or hit several different IPs - in a text log, this would be very hard to pick out from the "random" connections that a normal busy LAN is also handling, so the attacker could go undetected for some time. But on the Cube, this would appear as a filigree of closely packed dots all at the same depth (Z would be constant, X and Y varying), and would be immediately obvious to a human viewer.

      This isn't really meant to convey detailed information, it's just supposed to let the admin see at a glance that something suspicious may be happening, by making the data easier to examine as a whole.
    5. Re:Can anyone explain the data we're seeing? by SiliconEntity · · Score: 3, Informative

      Let me give a little commentary about what's in the sample cube pic. (BTW, does anybody have a mirror of the animation?)

      We have a 3 dimensional cube shown on a 2 dimensional display, so the image can be a little confusing. Every dot represents a connection attempt to a machine at the conference, presumably mostly laptops being used by attendees. Successful connections are shown in "white" supposedly, but on my display they look gray. The colored dots are all unsuccessful connections, connection attempts where the machine did not respond. The presumption is that the vast majority of these are attacks and scans.

      The left to right access represents the IP address of the machine at the confernece being attacked. Back to front is the IP address of the machine doing the attacking, from out on the internet. Bottom to top is the port number. To aid in viewing, the unsuccessful connections are shown in a color that represents the port, i.e. their height in the cube. That's all the color means. Red and orange are at the bottom for low numbered ports, then through yellow, green and blue in the middle ports, up to purple and back to red at the top for high number ports.

      Now let's take a look at the picture. The main feature that jumps out is that most of the dots are colored; there are a lot more attacks than successful connections. Presumably these laptops are not hosting many legitimate servers. Second, we see that most of the dots are orange, meaning that they are attempts to connect on low numbered ports. That makes sense, as most services listen on standard low numbered ports of 1024 or less, or a bit more. That's why we see so many orange dots. Those are attempts to connect to web servers, mail servers, various Windows services that are known to be vulnerable, etc.

      Another feature of the orange dots is that they are largely clustered towards the back, which would mean that the attacks are coming from Internet addresses which are relatively low in the address range. Looking closely, I make it out to be about 1/4 of the way from the back to the front, which would correspond to IP addresses of around 64.X.X.X. If we look at the first field of IPV4 addresses, ARIN (North America) has 24, then 63-70; APNIC (Asia/Pacific) has 60-61; RIPE (Europe) has 62, then 80-84, and all of them go on up from there. I'm not sure of the worldwide distribution of IP addresses but I suspect that accounts for the fact that many of the attacks and scans are coming from the 60-80 range or so, on the graph. There's another cluster of IPV4 address assignments in the 198-222 range, and that corresponds to a weak cluster of orange dots near the front of the cube, at the bottom.

      Another feature we can see is some vertical structure in the blue and cyan dots, especially to the left and the right. These represent port scans, where a particular host machine is making connection attempts to a series of port numbers on a particular target machine. Such scans show up as vertical lines. Here we don't have a full line but only aligned dots, so we may be missing some packets, or the scan may be accessing only selected ports.

      Well, that's about as far as I can go with my analysis. But you can see that if you had a real-time display of the last N minutes or seconds of activity, it would show you a visual picture of scans into your network. Probably be pretty hypnotic. Of course I'm not sure it makes sense to pay somebody to stare at it all day... you'd probably want to run a sped-up version at the end of the day and see if anything untoward leaped out.

    6. Re:Can anyone explain the data we're seeing? by Anonymous Coward · · Score: 0
      The Y axis represents the port number, so as two computers establish multiple TCP connections to each other they "stack" and move up towards the top of the cube.
      Port number != number of ports.
    7. Re:Can anyone explain the data we're seeing? by Have+Blue · · Score: 1

      I should have mentioned (and you should have known) that each TCP connection uses a different port number, and thus would be assigned a different Y value. Therefore, multiple simultaneous connections between the same IPs on different port numbers would appear arrayed along a vertical line.

  8. One of the best Cubes by Anonymous Coward · · Score: 0

    is this Cube.

    1. Re:One of the best Cubes by DrMrLordX · · Score: 1

      This is not the best Cube.

    2. Re:One of the best Cubes by ajlitt · · Score: 1

      Nah, it's this Cube.

  9. Does this have to do with by BodyCount07 · · Score: 2, Funny

    this cube of doom?

    1. Re:Does this have to do with by bSMfh · · Score: 1

      No.
      This One

    2. Re:Does this have to do with by Anonymous Coward · · Score: 0

      Not to be confused with this cube of doom.

  10. bah by mrtroy · · Score: 2, Funny

    This is old news.

    Security companies are just reacting to Swordfish...which used the opposite tool...it was spinning cubes that joined together when you successfully exploited the system.

    --
    [I can picture a world without war, without hate. I can picture us attacking that world, because they'd never expect it]
    1. Re:bah by DoctorDeath · · Score: 2, Funny

      Swordfish brought to life was my first thought. A poor graphic representation of programmers code is now a reality. What's next flip open communicators? Oh wait...

      --
      Sig temporarily out of service.
  11. I wonder.... by telstar · · Score: 4, Insightful

    Wonder if they've got one of these monitoring DOS attacks now that they've been posted on Slashdot.
    Here's the 31 meg AVI if you want to make it spin faster.

    1. Re:I wonder.... by itwerx · · Score: 2, Informative

      Here's the 31 meg AVI if you want to make it spin faster.

      Link is dead already (they yanked the file). :(

  12. If this continues... by Kirijini · · Score: 4, Interesting

    If this becomes a trend, and "Secutiry Visuallization Tools" become widespread... then people will begin to say that movies like Hackers and such were just "before their time."

    Do we really want that?

    1. Re:If this continues... by TigerNut · · Score: 4, Interesting

      It's pretty inevitable. There will always be extensions to today's technology, and likewise there will be visionaries (authors and screenwriters) who will try to imagine what that extended technology will look like and what it will feel like to use it. The visual scanning is pretty cool. What if you took a port-access logger output and assigned to each port a particular note, duration, or loudness? You'd hear white noise for the most part, but any nonrandom access would quickly be evident as a chirp, whistle or popping.

      --

      Less is more.

    2. Re:If this continues... by 0x0d0a · · Score: 1

      I remember when I used to think that people would be driven nuts by stupid, unnecessary animations all over their desktop. Well, *I* still am, but there are plenty of people that use Aqua.

      Of course, Apple didn't put in "per keystroke sounds", so maybe it isn't as bad as one would think.

      OTOH, Aqua+AIM with clicky keystroke mode enabled *is* equivalently annoying.

    3. Re:If this continues... by Anonymous Coward · · Score: 1, Informative

      a particular note, duration, or loudness

      You mean like this?

  13. Working in a cube farm is hard enough by Anonymous Coward · · Score: 2, Funny
    Now I have to figure out how to get in and out while it's spinning?

    And it's a good damn thing I've got a wireless LAN connection, so my cat5 cable won't get all twisted up.

    1. Re:Working in a cube farm is hard enough by MissTuxie · · Score: 1, Funny

      You're complaining? Try to get out of the... HYPERCUBE!!

    2. Re:Working in a cube farm is hard enough by Anonymous Coward · · Score: 0

      HELP! HELP!.. I Am all bound up in my network / Phone cables.. HELP!

      On another thought ... a spinning cube would that count the spins from drinking to much???

    3. Re:Working in a cube farm is hard enough by Anonymous Coward · · Score: 0

      Child's play. Try to get out of Gr(11,4). Now that's a challenge.

  14. Irken? by Kenshin · · Score: 1

    The Spinning Cube of Potential Doom?

    That sounds like a tool used by the Irken Armada.

    --

    Does it make you happy you're so strange?

    1. Re:Irken? by Anonymous Coward · · Score: 0

      it's zim's newest plan to get rid of dib. it has the potential to spell doom for dib if dib doesn't spin it just right.

    2. Re:Irken? by SamSim · · Score: 1

      Wouldn't that be the Spinning Cube of Impending Doom II?

    3. Re:Irken? by Exatron · · Score: 1
      At the very least, it's something Zim would think of to rain doom down upon his doomed enemies.

      I'm gonna sing the doom song now. Doom, doom doom, doom, doom, doomy doomy doom...

      --
      "I think so, Brain, but 'instant karma' always gets so lumpy." - Pinky
      "Decepticons FOREVER!!!" - Ravage
  15. I beg to differ by broothal · · Score: 5, Insightful

    "Definitely a step towards the new types of tools we will need to secure hosts and networks."

    I'm sorry, but I do not agree. While it makes it easy to visually detect intrusion attempts, it is of no use in the daily life of a BOFH. I have the responsibility of quite a number of machines. Most of the time, they don't require attention. So I don't pay them any. Then, once in a while, something extraordinary is happening, and I'm being alerted by an automatic monitoring system. That means I can use my day on all the important things (like hanging out on IRC etc). Visualizing network intrusion attempts is cool, but it's not a tool for me.

    1. Re:I beg to differ by dashersey · · Score: 1
      What about attacks that *don't* produce extraordinary behavior but might be visible in the logs with the right filter (visualizer?)

      Kind of like the shadowy figure snooping through the halls while the security guard dozes at the monitor. The alarms are only going to ring if he lobs a grenade....

      --
      You are in a maze of twisty little passages; all alike.
    2. Re:I beg to differ by Minwee · · Score: 5, Insightful

      The daily life of most admins include something called "Talking To Managers".

      Having a shiny toy with brightly coloured lights on it is a vital part of that excercise for many of us. We NEED this. We NEED it to have the Fisher-Price logo on it and play short musical bits when you push on the buttons. We NEED to be able to say "Here is a pretty picture. You like pretty pictures, don't you? The brightly coloured parts show bad people. Oooh, brightly coloured. Look at the picture. Do you like the picture? Good, now there are a few things we need to discuss about next year's budget..."

      Automated monitoring systems that handle problems for you make you (and themselves) look unnecessary. Pretty pictures with lights can be used to show everybody you work for just how important you really are.

    3. Re:I beg to differ by Anonymous Coward · · Score: 0

      This visualizer doowacky is a supliment to other network monitoring systems. you could have an old computer with a small monitor that only displays the cube. a glance at the cube could alert you to something happening. or your automatic monitoring system tells you somethings happening but you can't figure out where, so you look at the cube for a minute. I dislike the whole "here's a new thing that looks like it will replace my old tools and won't let me work thing" mentality. old + new = nolewd

    4. Re:I beg to differ by DanielMarkham · · Score: 1

      I agree that this is so much nonsense.

      Speaking as someone who just had to create a representation of multidimensional data, guess what? People want little smiley faces, not the spinning Octabhedron of Eternal Sunshine, or whatever.

      The human mind can only process so much information. I've found that once you go into 3-D, unless it represents some other, more familiar 3-D object the brain can recognize, it's just so much noise. But very pretty noise.

    5. Re:I beg to differ by joyof · · Score: 1
      The human sense/processing system includes an amazing pattern-recognition ability. A brief survey or current computational efforts in pattern recognition very quickly illustrates this. Consider face or speech recognition. These are not trivial tasks, and yet very specialized systems in our biology perform them (more or less) instantly, without conscious effort. Or consider a game of chess. Fast computers can calculate all positions five or ten moves away; humans can see sequences of as many moves along certain lines of play--based on observed patterns in the game.

      Human perception and processing systems have millions of years--stretching back into the mammalian systems we've built on--of pedigree within them. I am personally loathe to discount them in favor of automated scripts.

      I think that finding ways of presenting data in forms that capitalize on human pattern recognition is a fantastic idea, and that more work should be done in the area.

      --
      The benefits of good programming practices scale with computational power.
    6. Re:I beg to differ by Anonymous Coward · · Score: 0

      This reminds me of the story of a colonel from the Cheyenne Mountain complex taking a tour of the network center in the Pentagon. He was showed a panel of blinking, flashing lights, and was told by his guide that this panel enabled the NOC staff to quickly analyze the network data. He thought, that's interesting, and when he got back to Cheyenne he told his staff of the Pentagon's setup.

      The NOC admins at Cheyenne couldn't figure out how in the world a panel with lots of blinking lights would help them out, so they finally got permission to go to the Pentagon and look at their setup. They discovered, of course, that the panel was simply hooked up to a randomizer, its purpose was solely to dazzle management.

    7. Re:I beg to differ by Lord_Dweomer · · Score: 1
      " The daily life of most admins include something called "Talking To Managers". Having a shiny toy with brightly coloured lights on it is a vital part of that excercise for many of us. We NEED this. "

      Sounds like what you need is to learn communication skills and how to actually communicate complex ideas in terms people can understand. And yes, visualizations go a long way in this regard, but you need to be able to communicate verbally in a manner they can understand as well.

      --
      Buy Steampunk Clothing Online!
    8. Re:I beg to differ by Firefly1 · · Score: 1
      Sounds like what you need is to learn communication skills and how to actually communicate complex ideas in terms people can understand...
      Yes, this is a good point. In keeping with what I believe to be the spirit of the comment you are responding to, however, I will also suggest that a true master of persuasion does not need 'shiny toys with brightly coloured lights'...
      --
      - White Knight of the Order of Mihoshi Enthusiasts
    9. Re:I beg to differ by Anonymous Coward · · Score: 0

      If he were a true master of persuasion he would not be hanging out on /.

  16. Uuuuh, swordfish! by SoTuA · · Score: 1
    uuuh, swordfish!

    I want my n-monitor system with that funny IDE that lets you code exploits with on-screen spinning lego and gets you fine wines and a hot babe like Halle Berry.

  17. Just like in Tron! by beatleadam · · Score: 2, Funny

    The cube displays data from Bro along 3 axes and creates interesting visual results (port scans, barber poles, lawnmower).

    "So Cube...do you see anyone invading us from the 201.163.x.x range?" "YES"

    "That's Tron. He fights for the Users."

    --
    I have a theory that the truth is never told during the nine-to-five hours. -- Hunter S. Thompson
  18. virtual ICE? by dashersey · · Score: 4, Interesting
    This is evocative of william gibson's concept of ICE -- in a massively distributed computing environment with a direct-brain virtual-reality interface as primary, you interact with security systems visually.

    They appear as complex crystalline structures with no obvious holes other than the known authentication interfaces.

    Those who hack/defeat them are called "icebreakers" and they use software which has its own visual attack signature to distract or deflect(overload/DNS attack) the ice or to find hidden cracks (exploits)

    Visionary stuff (pun partially intended).

    --
    You are in a maze of twisty little passages; all alike.
    1. Re:virtual ICE? by scrytch · · Score: 3, Informative

      Give Gibson's work another read: it's just the "cowboys" who got an interface that direct, it required very expensive and specialized neurosurgery to install, and it required quite a bit of special firmware to create the visualizations, some of which would probably have been simply visual flair ala "skins", perhaps created in order to harness psycological reactions to perception (e.g. make the stuff you scan as "dangerous" look really baaaad) .

      He also mentions that ordinary people got something a good deal more pedestrian, more like the Metaverse than Gibson's Matrix (or as we might say now, more like the Matrix than the funky green overlay Neo got ... I'd stay away from using those movies for parallels tho).

      --
      I've finally had it: until slashdot gets article moderation, I am not coming back.
    2. Re:virtual ICE? by James+Lewis · · Score: 2, Insightful

      I disagree. Gibson's whole description of icebreaking was interesting science fiction, rather than something that was really attempting to make an informed guess on how future computer systems would work. For one thing, users could be killed by the security systems through their connection. It seems increadibly unlikely to me that this would ever occur, since any system connected to the internet should be able to handle disconnections, and so one could be produced on purpose the moment trouble showed up. But obviously, it made for a much more exciting plot. The same goes for the visual stuff, it's a lot more interesting than someone spending days maticulously banging away at a system. Gibson's a great author, but I think it silly to give him credit for things he obviously didn't intend in his books. By is own admission, Gibson is no techie. He writes fiction, and trying to pull deeper meaning (or predictions of the future) out of it is a waste of time.

  19. what a great name by surreal-maitland · · Score: 3, Interesting

    it looks like a great tool for ferretting out new styles of attack, even though it's use to an individual trying to protect his/her network is rather limited. the automated system that someone else mentioned sounds much more useful.

    --
    -ninjaneer
  20. protect-o by eegad · · Score: 1

    In fact, I was just talking to a coworker earlier about my new product idea. They need sanitary cube covers like those half ply protect-o toilet seat rings to protect the next victim from my blood, sweat and tears.

  21. Re:Security is only one possible area for innovati by Laxitive · · Score: 4, Funny

    Besides the primary educational aspect of the Cube, the secondary goal of the Cube will see fruition as to how investigate new techniques in visually analyzing network traffic and also to develop a tool that would potentially assist those involved with computer security.

    Yes. The Cube knows all. It will make everything all right again. The Cube has been sent to help us. We must trust the Cube.

    All hail the Cube.

    -Laxitive

    Sorry, absolutely nothing of value to add to this. I just liked the way you referred 'the Cube' using proper-noun capitalization, and spoke of it as a single entity.

  22. check out the video! by spoonyfork · · Score: 1
    --
    Speak truth to power.
    1. Re:check out the video! by upside · · Score: 1

      Like a 3D spectrum analyzer! Now we just need a sound generator that produces music from the data.

      If it's leisurely elevator music you're all hunky dory but if it escalates to 200bpm hardcore acid techno you know you're fucked.

      --
      I'm sorry if I haven't offended anyone
    2. Re:check out the video! by JebuZ · · Score: 2, Informative

      Same thing, but hosted by Akamai9 (faster).

  23. If only I had this when... by teamhasnoi · · Score: 2, Funny

    I was hacking teh Gibson, *I* would have gotten in Acid Burn's undies. :(

  24. Oh no! by Deaden · · Score: 0

    The Borg finally have the technology from The Last Starfighter! We are doomed!

  25. I wonder... by daemonc · · Score: 3, Funny

    I wonder what the 3D graph of a Slashdotting looks like...

    --
    All that we see or seem is but a dream within a dream.
    1. Re:I wonder... by aliens · · Score: 3, Funny

      Actually it's not so much a 3D graph as it is a flatline of the server's heartbeat.

      --
      -- taking over the world, we are.
    2. Re:I wonder... by tntguy · · Score: 0

      Possibly something like this.

      That's a Google Cache link for those not keeping track.

    3. Re:I wonder... by Have+Blue · · Score: 2, Insightful

      I imagine it would look like a thick, mottled square or blob drawn on a plane perpendicular to the X axis. It would represent a large number of external systems (large Z extent) connecting to a single web server (single X value) and taking up a large number of ports with HTTP transfers (large Y extent).

  26. The human mind: A better monitoring system? by zipwow · · Score: 4, Interesting

    I think the point of this interface is that the data is more easily interpreted, allowing the human-user to notice patterns that automated scripts would miss. This could be done either in real time, or as a visualization tool for historical files. The latter usage seems like it would be of interest if you're trying to determine the source of a break-in.

    For real-time monitoring, your point about mutliple systems is very valid, but what if this approach could be scaled up to allow you to visually inspect the whole system for a number of problems? Perhaps an entire array of cubes, each for a subnet or an individual system, focusing on those that pique your interest.

    This idea may be able to mesh with the glanceable objects idea (just the idea, not their chicken egg specifically). If it is informative enough, it could allow you to periodically check some aspects of your whole system for things that you either can't write scripts to do, or don't have time to write scripts for.

    -Zipwow

    --
    I don't know which is more depressing, that 2/3 didn't care enough to vote, or that 1/2 of those that did are crazy.
    1. Re:The human mind: A better monitoring system? by Danny+Rathjens · · Score: 2, Interesting
      Precisely. Using the human mind as a filter is the whole point. There is also a project called peep that does this with sound.
      Peep - Allows real-time aural monitoring of network information Peep aims to represent network information in real-time (and therefore eliminate searching through large logs of information to find problems) by using sound to represent the vast amount of available information about network status and to help identify network problems and irregularities.
      The project looks a bit stalled, but it's still a really cool idea. You could probably find some stories about it in /. archives too, ;) I thought it was neat that apparently nasa follows this philosophy with sounds for astronauts to filter/interpret on the space shuttle.
    2. Re:The human mind: A better monitoring system? by wolfbane01 · · Score: 1

      Reminds me of the movie Contact, wherein Jodie Foster's character felt that she could do better at listening to patterns in static then a whole bank of specialized machines could. Point being this is a very interesting system, but would it really be of any use to an admin who would have to sit and stare 24/7/365 at the display?

      Why not put together an audio interface to the Bro system so you could hear when there were problems? It would certainly be a heck of a lot less disruptive.

  27. Remember! by telstar · · Score: 5, Funny

    Warning: Pregnant women, the elderly and children under 10 should avoid prolonged exposure to the Spinning Cube of Potential Doom.
    Caution: the Spinning Cube of Potential Doom may suddenly accelerate to dangerous speeds.
    the Spinning Cube of Potential Doom Contains a liquid core, which, if exposed due to rupture, should not be touched, inhaled, or looked at.
    Do not use the Spinning Cube of Potential Doom on concrete.

    Discontinue use of the Spinning Cube of Potential Doom if any of the following occurs:
    Itching
    Vertigo
    Dizziness
    Tingling in extremities
    Loss of balance or coordination
    Slurred speech
    Temporary blindness
    Profuse sweating
    Heart palpitations

    If the Spinning Cube of Potential Doom begins to smoke, get away immediately. Seek shelter and cover head.
    the Spinning Cube of Potential Doom may stick to certain types of skin.

    When not in use, the Spinning Cube of Potential Doom should be returned to its special container and kept under refrigeration...

    Failure to do so relieves the makers of the Spinning Cube of Potential Doom, Wacky Products Incorporated, and its parent company Global Chemical Unlimited, of any and all liability.

    Ingredients of the Spinning Cube of Potential Doom include an unknown glowing substance which fell to Earth, presumably from outer space.

    the Spinning Cube of Potential Doom has been shipped to our troops in Saudi Arabia and is also being dropped by our warplanes on Iraq.

    Do not taunt the Spinning Cube of Potential Doom.

    the Spinning Cube of Potential Doom comes with a lifetime guarantee.

    the Spinning Cube of Potential Doom

    ACCEPT NO SUBSTITUTES!

    1. Re:Remember! by delus10n0 · · Score: 3, Informative
      --
      Not All Who Wander Are Lost
    2. Re:Remember! by telstar · · Score: 1

      Sorry ... I assumed everybody was aware of Happy Fun Ball...My Bad.

    3. Re:Remember! by radish · · Score: 1

      you forgot...

      The Spinning Cube of Potential Doom has been found to cause cancer in the state of California.

      --

      ---- Den ene knappen er powerknapp, den andre er Bender voice knapp "Bite My Shiny Metal Ass"

    4. Re:Remember! by RobertB-DC · · Score: 1

      w00t! That Wikipedia page is the first one I ever created from scratch. I saw a sig on Slashdot, did some Googling to figure it out, and having recently discovered Wikipedia, decided to try it. Seeing it come full circle is pretty cool.

      --
      Stressed? Me? Of course not. Stress is what a rubber band feels before it breaks, silly.
    5. Re:Remember! by Trumpetgod2k1 · · Score: 0

      BUT WAIT!!! There's MORE!

      Call in the next five minutes and we'll double your order for FREE!! Thats right, you get not one, but TWO Spinning Cubes of Potential Doom!

      Offer void in Hawaii and Alaska.

    6. Re:Remember! by Anonymous Coward · · Score: 0

      "is known to the State of California to cause cancer..."

    7. Re:Remember! by Lord_Dweomer · · Score: 1
      Ah...for once my .sig is actually somewhat on topic.

      --
      Buy Steampunk Clothing Online!
  28. SGI did this years ago by green+pizza · · Score: 3, Interesting

    Back in the "what possible use would anyone have for 3D?" days, Silicon Graphics made gobs of 3D utilities such as this. Many exist today as viewers for their (awesome) Performance CoPilot system for IRIX and Linux. Over time they learned that most admins perfer text most of the time. But man, fddivis on a large monitor sure does make the NOC look way more productive to the suits!!

    They even had a 3D intra-website link manager at one time!

  29. Video of the cube in action by SassyDave · · Score: 0, Redundant

    See the cube in action here.

  30. Cube... confusion by mauthbaux · · Score: 1

    From the title, I made the quick assumption that this was either talking about the borg from star trek (quite confusing) or some variation on the rubik's cube, (which has baffled people since it came out). I was quite surprised to see security software instead (which is inherently confusing for almost everyone except slashdotters)...

    --
    "Operating systems suck: you're better off using only the BIOS" --trainsaw.com
  31. And I quote: by Anonymous Coward · · Score: 0

    "Code is currently not available, sorry!. I plan on releasing the source as soon as I get a version that is more polished."

    release early and often, Im certainly not going to use something that claims to be a "security" tool if I cant view the source to see for myself just how "secure" it is. the whole point of having an open source community is so others can help you polish that code for later releases.

    "put the [code] on the floor and back away slowly, sir. we can take it from here :)"

    1. Re:And I quote: by 0x0d0a · · Score: 1

      release early and often, Im certainly not going to use something that claims to be a "security" tool if I cant view the source to see for myself just how "secure" it is.

      No, see, it's a private joke. The "Spinning Cube of Impending Doom" roots your network operations center, thus resulting in your doom.

    2. Re:And I quote: by Anonymous Coward · · Score: 0

      Boo-Hoo, not everything is immediately available and its not a security tool, its a visualization tool how secure does it need to be to read a copy of a dman log file?

  32. Gleming the cube by Orion+Blastar · · Score: 0, Offtopic

    those web sites didn't work. The urls have been Slashdotted already.

    Want to destroy a site's bandwidth, post a URL to it on Slashdot. :)

    --
    Remember, Slashdot does not have a -1 disagree moderation, and no, troll, flamebait, and overrated are not substitutes.
    1. Re:Gleming the cube by k98sven · · Score: 2, Funny

      those web sites didn't work. The urls have been Slashdotted already.

      Yup. And they're .gov top domain!
      Given the PATRIOT act, does this mean we're all terrorists now?

      I'll get the "Free Taco!" campaign started right now, just in case. We can only hope the general public will misunderstand.

      (I'm hungry, so?)

    2. Re:Gleming the cube by AbbyNormal · · Score: 1

      Yeah, its not going to be good for Taco in jail.

      Big Rough Scary Inmate: "So what do they call you?"
      Taco: "Taco....Commander Taco".

      Big Rough Scary Inmate smiles.

      --
      Sig it.
  33. Spinning cube of death by Anonymous Coward · · Score: 0

    would sound more interesting. The spinning cube
    of potential doom sounds like a Humvee on an
    icy road.

  34. Missing the point? by Hythlodaeus · · Score: 4, Funny

    Did someone just discover that data can be graphed? What is the innovation here?

    --
    For great justice.
    1. Re:Missing the point? by telstar · · Score: 1
      "Did someone just discover that data can be graphed? What is the innovation here?
      • Shhhhh! Hear that? It's the sound of the big hand hitting the 3.

    2. Re:Missing the point? by DerekLyons · · Score: 1
      Did someone just discover that data can be graphed? What is the innovation here?
      As Tufte can tell you, how the data is graphed is important. (Among other things, had certain engineers graphed the data they already had properly, then January 28th might not be a day we remember with sorrow.)
    3. Re:Missing the point? by Herkum01 · · Score: 2, Insightful

      Management: That looks good but can you use a pie chart instead? I just get whoozy looking at it...

    4. Re:Missing the point? by Krunch · · Score: 1

      > Did someone just discover that data can be graphed?
      > What is the innovation here?

      It's spinning !

      --
      No GNU has been Hurd during the making of this comment.
  35. Boon to social engineers! by stratjakt · · Score: 5, Funny

    Got some slick, nobody's fool sysadmin you need to get past?

    Well, cook up a portscan that will look like a giant, spinning Mr Goatse, or some racial slurs, etc..

    Boss walks past, geek gets fired, replaced by bosses moron nephew who is more than happy to give you the keys to the server when you call and identify yourself as the Hamburglar.

    --
    I don't need no instructions to know how to rock!!!!
  36. to the tune of yellow submarine... by eegad · · Score: 1

    We all live in a spinning cube of doom!

    (sorry, I'm infatuated with this phrase at the moment)

  37. What's the use for detecting port scans? by upside · · Score: 1

    I wonder about this sometimes. There are so many port scans and intrusion attempts they aren't worth getting you knickers in a twist about. All the non-necessary ports are blackholed anyway.

    What I do worry about are the connections that take place with actual open services. They are the ones that ought to be monitored for foul play. Log checkers and proactive HTTP request sanitizers are more use there.

    --
    I'm sorry if I haven't offended anyone
  38. The borg by British · · Score: 1

    Reminds me of the "screen display" system teh Borg had in ST:TNG. They had several external images of the starship battles arranged on a rotating cube. Fits their ship.

  39. I wonder... by jmrobinson · · Score: 0

    I bet they didn't think of the potential doom of getting posted on slashdot. What would the cube look like as they are getting slashdotted? I'm thinking implosion would be cool...

  40. No, it has to do with.. by Conspiracy_Of_Doves · · Score: 3, Funny
    1. Re:No, it has to do with.. by Performaman · · Score: 1

      That's what I thought.

      --

      I have gas, but my car uses petrol.
  41. the first rule of Spinning Cube of Potential Doom by ph4s3 · · Score: 1

    ...is don't talk about Spinning Cube of Potential Doom. You must now be punished for breaking the first rule.

  42. Old stuff, new usage by bellwould · · Score: 4, Interesting

    Visible Decisions (acquired by Visual Insights in 2000) has been doing graphical visualization for 15 years - check this out for a demo.

  43. Re:Security is only one possible area for innovati by lawngnome · · Score: 1

    Another innovation I can see is hooking this kind of tool up to network aware objects, like those little spheres that change colors.

    I can see it now...
    admin: "oh crap the ball on my desk just turned red, Ill have to call you back..."

  44. This and the orb? by novakane007 · · Score: 3, Interesting

    Remember the ambient orb?
    Thinkgeek used to sell them, but I couldn't think of something I would find it useful for. This would be perfect. Just have a globe on your desktop that changes colors based on the data provided by the cube matrix. If the orb starts turning crimson, you know that that your network is in need of administrative attention.

    --

    WURD!!
  45. It's interesting, alright - to HOLLYWOOD... by Digital+Avatar · · Score: 3, Funny

    ...I can see it now:

    I know this... this is UNIX!

    Would you like to play a game>

  46. In Rod We Trust by runlvl0 · · Score: 2


    All hail the Cube.

    from "Deep Space Homer"
    Buzz: Homer Simpson was the real hero here. He jury-rigged the door closed using this.
    Man 1: Hey, what is that?
    Man 2: It's an inanimate carbon rod!
    Everyone: Yay!

    Time magazine cover: "In Rod We Trust"

    --

    Carthago delenda est!
    1. Re:In Rod We Trust by Laxitive · · Score: 1

      Man, I knew I was getting that from _somewhere_. I just couldn't remember where.

      The Simpsons have infected my mind more than I can reasonably be comfortable with.

      -Laxitive

    2. Re:In Rod We Trust by RollingThunder · · Score: 1

      Actually, it struck me far more like a game of Paranoia than an episode of the Simpsons.

      "Trust the Computer. The Computer is your friend. Only commie mutants hate the Computer, Citizen."

  47. Data visualization using Strange Attractors by freelunch · · Score: 4, Interesting

    About 18 months ago, Slashdot posted an article The Black Ops of TCP/IP: Paketto Keiretsu 1.0 Release with a nice collection of unconventional networking tools.

    Included was a very cool tool, Phentropy, for visualizing arbitrary data using Strange Attractors. You may recall a paper on TCP/IP Sequence number analysis that highlighted the usefulness of Strange Attractors for data visualization.

    Phentropy plots an arbitrarily large data source (of arbitrary data) onto a three dimensional volumetric matrix, which may then be parsed by OpenQVIS. Data mapping is accomplished by interpreting the file as a one dimensional stream of integers and progressively mapping quads in phase space.

    OpenQVIS is a neat package and could fill a lot of arbitrary data viz needs.. But damned if I have been able to get the thing to build under Linux. The project could really use some help, and I think a lot of good could come of it. The Phd types who wrote it seem to have mostly moved on..

  48. What a pity it will not be useful for too long... by PaulBu · · Score: 4, Funny

    ... After all the $$M spent on cute visualization and PR promotion of the technology, evil authors of port-scanners just add two lines:

    pseed=urand(); iseed=urand(); /* this */
    for(port ...)
    for(ip ...){
    port ^= pseed; ip^=iseed; /* and this */
    probe(ip,port);
    }

    or use some fancier one-to-one mapping and the dots in your cube are again "random" to the naked eye.

    (On a side note, why whoever implemented that "barberwire"-producing scanner did not do this at the time, I can not understand).

    Paul B.

  49. How does it depict by Anonymous Coward · · Score: 0

    when you have been /.ed? (As it seems to be right now)

    1. Re:How does it depict by IMarvinTPA · · Score: 1

      It should be a nice line in the z-axis, basically representing all the IPs on the internet hitting the same port on the same machine.
      It should be unique, but cool.

      IMarv

  50. Someone discovered logfiles can be graphed by Anonymous Coward · · Score: 0

    And what's more, that they can be graphed in a way that leaves human-recognizable patterns. That sounds pretty innovative to me. It's like discovering that you can distinguish a Beethoven composition from a Bach because the Bach tastes more like mango.

  51. saw it as SC2003 as well... by painehope · · Score: 2, Funny

    I busted out my laptop and sat down and started port-scanning some friendly IPs in front of the screen, only to be disappointed that I'd have to wait something like 10 minutes to see my spray coming out.

    It was still pretty cool, and I'm sure half of the traffic on it was people like who kicked off port scans just to see themselves on the screen ;p

    --
    PC moderators can suck my White pierced, tattooed dick. If you think pride == hate, s/dick/Aryan meat mallet/g.
  52. Re:Security is only one possible area for innovati by Croaker-bg · · Score: 1

    Is it possible this could also be the solution to identifying the problem of auditing user groups on a system where the groups are nested? Select a file or directory and then have the magic cube display in 3 dimensions the access of a user based on amount of potential privilege with each associated group. The more privilege you have the closer to the center. This has always been such a pain as a security auditor to have to pick through spreadsheet after spreadsheet on poorly managed systems to see if a nested user has group access to something. Would be nice to do a quick find of everything and feed the cube the results. Put on your magic glass and poof ... you can now see who can touch your goodies!

  53. Mirror? by ktulu1115 · · Score: 2, Interesting

    Could someone who has downloaded the movie please post a mirror? All of the existing links posted are already 404.

    --
    # fuser -v /dev/attention | grep work
    #
  54. Re:What a pity it will not be useful for too long. by khrtt · · Score: 2, Insightful

    The time is NOT a display variable in the Cube. Your "enhanced" scanner would produce the same pattern as it would without the randomization. The order in which the scan's packets reach its target, and the dots are put on the display does not even change the resulting picture.

    Now, the "barbwire" scan tries a port on each host. This could be made less distinguishable by randomizing the port, rather than using linearly increasing port numbers for the IP range, which produces the evel-looking diagonal slashes in the picture.

  55. Hackers by sklib · · Score: 1

    And all you fools said that Hackers wasn't a realistic computer movie... Shows what you know!

    --
    -S
  56. Re:What a pity it will not be useful for too long. by PaulBu · · Score: 1

    I see it now... What is the third axis then? (TFA was already /.ed by the time I tried clicking on it, but I assumed that any Cube would be 3D, right? ;-) )

    Paul B.

  57. Re:What a pity it will not be useful for too long. by Have+Blue · · Score: 1

    You can't spoof your own IP if you expect to get any results from a port scan, so all your connections will be in the same Z plane. I expect that would show up quite well, especially if the cube was viewed from several different angles. Also, it displays a fairly large period of time simultaneously, so randomizing the connection order wouldn't be all that helpful.

  58. All Glory to the HypnoCube by Slau · · Score: 3, Interesting

    Thanks for the /. and the comments folks, although I'm not sure if the web admins are gonna talk to me anymore. :-/ I got paged about the /. while I was watching Shrek 2. What happened to Fiona's Dad? Missed that part...oh well... The Cube is still a work in progress. I originally developed it to keep wandering jaded conference attendees mesmerized by pretty moving colors. Hopefully it'll inspire people to develop new ways of educating the wormy masses that they need to take security seriously.

  59. Spinning Cube of Doom? by Anonymous Coward · · Score: 0

    I, for one, welcome our new Borg overlords!

  60. We have something similar by Isomer · · Score: 4, Interesting

    I work for a network research group ("WAND") at Waikato University in New Zealand. We have a similar visualisation which you can see various stages of evolution here, there are also some animations.

    The universities internal network IP range is mapped onto the left hand face of the cube, the rest of the world is mapped onto the right face. They are mapped so similar addresses are clustered together and addresses further apart are uh, further apart. A box represents one packet, the volume of the particle is proportional to the size of the packet, and the colour is based on port number.

    Also we "light" each end of the connection for a bit after the packet has been sent. So machines appear to be glowing in the colour of the traffic they are sending.

    We use it to show off "networks" to people who think we just sit at computers and type into stuff, however it has been very useful to detect attacks and broken machines since they provde distinctive patterns. Portscans are a series of "sparkly" packets. Network scans are a row of marching lines. Virii infected machines appear as a cone centered on the infected machine.

  61. zerg by Lord+Omlette · · Score: 1

    Am I the only one who get an error saying invalid cert? If so, maybe they should spinning cube of doom themselves!

    --
    [o]_O
  62. I'm disappointed by magefile · · Score: 1

    I thought this was going to be something cool, like that B.S. crap from Swordfish. (No, not H.B.'s boobs). Then I saw this, and it looks like B.S. crap, but not *cool* B.S. crap. Dammit! When do we, the non-gamers of the world, get some cool 3D graphics?

  63. Boss Screen by monk · · Score: 1

    I think you've missed the primary use of pretty pictures and animation. A BOFH with prominently displayed active graphs and a device that goes "ping" every so often can greatly optimize IRC/Nethack time by responding to all queries by management in the following manner.

    Manager: "Where are your TPS reports?"
    BOFH: (pointing at large, flat screen display of Cube of Potential Doom with one hand while typing jjjjjjjjjj with the left) "TPS Reports! My God can't you see we're under attack. Quick! Call facility maintenance. We need to lock down the executive suite!"

    You get the idea...

    --
    [-- Trust the Monkey --]
  64. dang straight by zogger · · Score: 1

    right on man, that would be *nice* Be able to just slide a user deeper or farther away from the center, and even add layers (jails), more spheres over spheres, on the fly.

    I like it.

  65. EEW....... by Lehk228 · · Score: 1

    NERDS X-P

    --
    Snowden and Manning are heroes.
  66. My favorite... by Nugget · · Score: 2, Interesting
    Much lower tech, but my favorite example or a conference's realtime security monitoring is this whiteboard from the 2000 Monterey BSDCon.

    It's a brutal but compelling reminder that we should all avoid unencrypted telnet/pop3/imap.

    Consider spending some time today getting STARTTLS running on your mail server. Or consider getting IMAP/SSL going. Or consider figuring out GnuPG or S/MIME email once and for all. Don't be part of the problem.

  67. The ORIGINAL spinning cube of potential doom by VernonNemitz · · Score: 1

    If I recall right (and have the spelling right), then to see it, all you need is a Star Trek Original Series episode called "The Corbomite Maneuver".

  68. Doom? by mrgsd · · Score: 1

    Anyone else quick read the title and expect this to be something about Doom III? I hope Carmack is well beyond spinning cubes at this stage of development ..

    --
    End Communication.
  69. And I already have an exploit by Tracy+Reed · · Score: 1

    I just hacked up a script that will port scan their IP space in just the right port/ip/time pattern to form the goatse guy in all of his 3-d glory rendering this security tool useless because people will refuse to look at it. If that doesn't deter them I'll hit 'em with tubgirl. They'll be able to rotate it in 3-d and see the whole stream suspended in mid-air and everything. My next task is to hit them with successive animated images so if they play it back fast enough they can see the cavern opening and closing or the cascade flowing.

  70. my idea by rush22 · · Score: 1

    when will I learn to actually make the things I think of :/. Not that graphic representation is a genius idea, though they have a cooler name, "CUBE OF DOOM", than I would have thought of. I would have called mine something like "IP & Port Grapher version 1"... or maybe "IP & Port Grafix 3000XP+"

  71. Log files appear as lincoln logs by billcopc · · Score: 1
    Port scans appear as linear lines.


    I'd really like to know how to draw a nonlinear line. Oh wait, would that be a curve ?

    Spinning cube of doom, linear lines, and lawnmower plots that really look like an old-school SVGA game that doesn't quite grok the frame buffer. It all looks amateurish to me.

    --
    -Billco, Fnarg.com
  72. This Cube of Doom is exactly what I need by Pan+T.+Hose · · Score: 1

    This Cube of Doom is exactly what I need to make my security response work seem exciting for my peers. This Cube of Doom is sexy. An xterm with Snort logs is not.

    --
    Sincerely,
    Pan Tarhei Hosé, PhD.
    "Homo sum et cogito ergo odi profanum vulgus et libido."
  73. Re:Security is only one possible area for innovati by Fjord · · Score: 1

    Only if it's a 4-corner faced natural harmonious Time Cube.

    --
    -no broken link
  74. For those who've read Dan Brown's Digital Fortress by tatonca · · Score: 1

    .. there is a section at the end where a similar technology used. I thought this was the least believable part of the story actually... that is until now...

  75. SourceFire RNA? by krinsh · · Score: 1

    I just skimmed through the site and looked at a couple of the images; and it brought to mind the imagery I've seen from the graphic presentation piece you can use with their box. http://www.sourcefire.com My slight disclaimer - we use several brands of network sensor including SourceFire and have a couple RNA boxes to play with right now.

    --
    I think with the interesting people, their lives can't possibly be wrapped up into a nice little package.