Summary / Review
The paper “Building an Early Warining System” by Securosis starts by detailing the typical situation: you can’t get ahead of the threat, security is inherent reactive. You have to use tools to be as close to the threat as possible. An Early Waning System can be one of the tools.
“A good hockey player plays where the puck is. A great hockey player plays where the puck is going to be.” – Wayne Gretzky
Nice PDF provided by SANS (including links to further information and tools for incident response):
There’s a nice article at SpiderLabs (Sniper Forensics – Part 1: A Brief History Lesson) which summarizes three interesting thesis and adopts them to modern problem solving and investigations (e.g. forensics).
Occam’s Razor / Lex Parsimoniae
(by William of Occam / Ockham)
When selecting hypothesis, the one that makes the fewest number of new assumptions is more likely to be correct.