BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//Hunter Storm - ECPv6.17.1//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Hunter Storm
X-ORIGINAL-URL:https://hunterstorm.com
X-WR-CALDESC:Events for Hunter Storm
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:America/Phoenix
BEGIN:STANDARD
TZOFFSETFROM:-0700
TZOFFSETTO:-0700
TZNAME:MST
DTSTART:20060101T000000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=America/Phoenix:20071126T183000
DTEND;TZID=America/Phoenix:20071126T203000
DTSTAMP:20260724T202211Z
CREATED:20260608T051220Z
LAST-MODIFIED:20260724T202211Z
UID:41955-1196101800-1196109000@hunterstorm.com
SUMMARY:Event: Live Presentation | University of Advancing Technology (UAT): IDS/IPS & Event Correlation: Separating Fact from Fiction
DESCRIPTION:This page documents the November 26\, 2007 Arizona Security Practitioners’ Forum session where Hunter Storm presented “IDS/IPS & Event Correlation: Separating Fact from Fiction\,” a practitioner‑level examination of detection fidelity\, false‑positive reduction\, and correlation logic in enterprise SOC environments. \n  \n\nOverview | IDS/IPS & Event Correlation: Separating Fact from Fiction\nIn this 2007 Arizona Security Practioners Forum (AZSPF) session\, Hunter Storm delivered a practitioner‑level examination of IDS/IPS tuning\, false‑positive reduction\, and event‑correlation logic from the perspective of a working SOC engineer and correlation‑tool architect. The presentation separated operational fact from vendor fiction\, clarified common misconceptions about detection fidelity\, and explored practical strategies for improving signal‑to‑noise ratios in enterprise environments. \nThe session included live practitioner participation\, reflecting the AZSPF community’s collaborative\, hands‑on approach to security engineering. \n  \n\nKey Themes\n\nIntrusion Detection — operational realities vs. vendor claims\nIntrusion Prevention — tuning for fidelity\, not noise\nEvent Correlation — logic design\, rule construction\, and context weighting\nFalse‑Positive Reduction — practical SOC‑tested strategies\nSOC Engineering — workflow\, triage\, and analyst burden\nThreat Analysis — interpreting signals in context\n\n  \n\nHistorical Significance\nThis event is a key entry in the 2007 technical‑presentations cluster\, representing Hunter Storm’s early public work in intrusion detection and prevention engineering\, event correlation modeling\, and SOC‑level operational fidelity. It complements the Hacking Humans debut event by documenting the parallel technical lineage of Storm’s security engineering career. \n  \n\nAudience & Format\nPresented to the Arizona Security Practitioners’ Forum — an organic community of InfoSec professionals — the session blended structured content with open discussion\, scenario analysis\, and practitioner‑driven Q&A. \n\n\n\n\nHunter Storm | Events and Appearances\n\nEVENT — Digital Broadcast | Public Broadcasting Service (PBS) Jobs Explained! — Interview: Cybersecurity Career Paths (2026)\nEVENT — Live Presentation | INTERFACE Phoenix Conference — Keynote Hacking Humans | The Ports and Services Model of Social Engineering (June 21\, 2013)\nEvent: Live Panel | Live for the Synthetic Swarm: The Science of Drones — Phoenix Fan Fusion (June 5\, 2026\, 7:30 PM)\nEvent: Virtual Presentation | Femme Fatale to Federal Whistleblower — ISACA Central Ohio (May 28\, 2026 12:00 PM)\nEvent: Live Panel | Career Panel: Texas A&M Department of Computer Science & Engineering (April 1\, 2025\, 2:00 PM)\nEvent: Live Presentation | The Overlooked Cyber Strategy: Protection from the New Wave of CyberThreats (Professional Attacks\, Character Assassination\, Doxing\, Impersonation\, and more) — ISSA Phoenix (June 13\, 2019\, 2:00 PM)\nEvent: Featured Speaker | IDS/IPS & Event Correlation: Separating Fact from Fiction (November 26\, 2007\, 6:30 PM)\nEvent: Featured Speaker | Spooky Security (City of Phoenix Brown Bag Series)\nEvent: Live Presentation | Social Engineering: Building a More Secure World Thru Innovative Use of the Truth (June 24\, 2026 6:30 PM) – First public presentation of Hacking Humans: The Ports and Services Model of Social Engineering\n\n  \n\n\nDiscover More from Hunter Storm\n\nAudience and Global Influence\nFemme Fatale to Federal Whistleblower — ISACA Central Ohio\nHacking Humans | The Ports and Services Model of Social Engineering\nHunter Storm Official Site\nMedia\nPlatform Visibility Review and Policy\nPresentations\nRésumé | Wells Fargo | SOC Site Lead | Black Ops Team\nSocial Engineering | Building a More Secure World Thru Innovative Use of the Truth\nThe Storm Chronology | Institutional Resilience Through Architecting Through Systemic Risk with Google Gemini\n\n\n  \n\n 
URL:https://hunterstorm.com/event/ids-ips-event-correlation-2007/
LOCATION:University of Advancing Technology (UAT)\, 2625 W Baseline Rd\, Tempe\, AZ\, 85283\, United States
CATEGORIES:Cybersecurity and Resilience,Media Appearance
ATTACH;FMTTYPE=image/jpeg:https://hunterstorm.com/wp-content/uploads/hunter-storm-smiling-professional-headshot.jpg
ORGANIZER;CN="Arizona Security Practitioner%E2%80%99s Forum (AZSFP) %E2%80%94 later known as Southwest Cybersecurity Forum (SWCF)":MAILTO:https://swcsf.org/contact/
END:VEVENT
END:VCALENDAR