Last modified:
Sun Mar 10 13:05:11 PDT 2013
General Computer Security Awareness
- Australian Defence Signals Directorate Top 35 mitigation strategies (The Top 4 remove 85% of targeted attacks)
- NSA's Sager on trends of 2011 security breaches, advanced persistent threat hype, Search Security, TechTarget, October 7, 2011
- Security Engineering - The (online) Book, by Ross Anderson, John Wiley and Sons, 2001, ISBN 0-471-38922-6
- Evans: 'People are losing data', bY Matthew Weigelt, FCW.com, November 2, 2006
- CERT/CC's Virtual Training Environment
- EDUCAUSE Security Task Force Computer Security Awareness Video Contest (These are great!)
- EDUCAUSE | Security Task Force | Data Incident Notification Toolkit
- Internet2 Effective Security Practices Guide
- Internet Threats: Spyware and Phishing Scams, The University of Missouri-Columbia Information & Access Technology Services
News items of interest
- The TJX intrusion - Largest data theft in U.S. history
- TJX agrees to reimburse banks, by Ross Kerber, The Boston Globe, December 1, 2007
- TJX e-mails tell the tale, by Donna Goodison, The Boston Herald, November 28, 2007
- Authorities hope arrest of Ukraine man leads to TJX orchestrator, by Dan Kaplan, August 21, 2007
- Report: TJX breach began in Minnesota Marshalls parking lot, by Dan Kaplan, SC Magazine, May 4, 2007
- Breach of data at TJX is called the biggest ever: Stolen numbers put at 45 .7 million, by Jenn Abelson, The Boston Globe, March 29, 2007
- Store IDs led to arrests: Data taken from TJX was used to buy gift cards, by Ross Kerber, The Boston Globe, March 29, 2007
- Russian Roulette, by Art Janke, CSOonline.com, February 2005
- A Quiet Time Bomb: The Vulnerability of U.S. Supercomputers, by Lewis Koch, Raw Story, May 11, 2004 (Many NSF sponsored supercomputer sites, major research universities, and national labs compromised by intruders over several month period.)
- Alarm growing over bot software, by Robert Lemos, CNET News.com, April 30, 2004 ("Bot nets", or "blended threats" as AusCERT refers to them, are affecting millions of PCs worldwide. Tens of thousands at a time are used for distributed denial of service attacks and extortion attempts, as well as unblockable spam delivery, theft of credit card numbers, passwords, and software product keys.)
- Worm worries grow with release of Windows hacks, by Robert Lemos, CNET News.com, April 28, 2004 (Microsoft reports 9.5 million PCs infected by MS Blaster)
Security Tools
Social Engineering
- Selling fake security "services"
- Microsoft Impersonation Scam, Snopes
- How to recognize a PC support scam, by David Harley, ESET, April 18, 2012
- Technical Support Phone Scams, Orla Cox, Symantec, June 24, 2010
- Avoid tech support phone scams, Microsoft Safety & Security Center
- Microsoft tech calling to try to sell me malware, ccleaner, superaniti spyware after installing new windows 7 os, Microsoft Answers web site, December 14, 2010
- Phone call from "Microsoft" about virus is a scam, Computer Repair Tips [Note the HUGE number of responses, indicating this is a very widespread problem.]
- Watch out for "Microsoft Tech Support" scams, by Woody Leonhard, WindowsSecrets
- Virus phone scam being run from call centres in India, Petersfield Area Neighborhood Watch Association (PANWA)
- Call from Microsoft a scam, police say, Salina Journal, February 16, 2012
- Call complaints related to this scam
- US-CERT: Social engineers target utilities with fake Microsoft support calls, by Ms. Smith, Networkworld,April 19, 2012
- Social engineering: examples and countermeasures from the real-world, by Anonymous
- Social Engineering Fundamentals, Part I: Hacker Tactics, by Sarah Granger
- The Use of Social Engineering as a Means of Violating Computer Systems, by Malcolm Allen, October 12, 2001
- Hoax email goads users into deleting harmless files by Matt Loney, May 30, 2001
- "Social Engineering" just a new twist on an old con game
- Social Engineering: Policies and Education a Must, by Rick Tims, February 16, 2001
- Social Engineering: What is it, why is so little said about it and what can be done?, by John Palumbo, July 26, 2000
- People Hacking: The Psychology of Social Engineering, text of Harl's talk at Access All Areas III, May 7, 1997
- VMYTHS: Truth about computer security hysteria
Mobile/Smartphone Security
- New Free Tools Simplify Analysis Of Android Malware, by Kelly Jackson Higgins, Dark Reading, August 31, 2011
- Android Malware Spreads Through QR Code, by Arun Sabapathy, McAfee, October 24, 2011
- Threat Update: Malicious QR Codes Pose Risk to iPhone, Android Devices, by Ericka Chickowski, Channel Insider, January 26, 2012
QR codes as attack vector
- QR Code and Near Field Communication Security Issues, Online QR Lab Blog
- Android Malware Spreads Through QR Code, by Arun Sabapathy, McAfee, October 24, 2011
- How QR Codes hide privacy, security risks, by Meg Shannon, Security News Daily, MSNBC, 2012
- QR code security risks in the car park, by Terence Eden, Sophos Security Blog, September 14, 2011
- Threat Update: Malicious QR Codes Pose Risk to iPhone, Android Devices, by Ericka Chickowski, Channel Insider, January 26, 2012
- GAO-07-65 -- INFORMATION SECURITY: Agencies Need to Develop and Implement Adequate Policies for Periodic Testing, October, 2006
- GAO-06-811 -- INFORMATION SECURITY: Coordination of Federal Cyber Security Research and Development, September, 2006
- GAO-05-231 -- INFORMATION SECURITY: Emerging Cybersecurity Issues Threaten Federal Information Systems, May 13, 2005
- GAO-05-482 -- INFORMATION SECURITY: Internal Revenue Service Needs to Remedy Serious Weaknesses over Taxpayer and Bank Secrecy Act Data, April 15, 2005
- GAO-05-567T -- Information Security: Department of Homeland Security Faces Challenges in Fulfilling Statutory Requirements, by Gregory C. Wilshusen, director, information security, before the Subcommittee on Management, Integration, and Oversight, House Committee on Homeland Security, April 14, 2005
- GAO-04-699T -- CRITICAL INFRASTRUCTURE PROTECTION: Establishing Effective Information Sharing with Infrastructure Sectors, testimony by Robert F. Dacey, Director, Information Security, before a joint hearing of the Subcommittee on Infrastructure and Border Security and the Subcommittee on Cybersecurity, Science, and Research and Development, House Select Committee on Homeland Security, April 21, 2004
- GAO-04-628T --CRITICAL INFRASTRUCTURE PROTECTION: Challenges and Efforts to Secure Control Systems, testimony by Robert F. Dacey, director, Information Security, before the Subcommittee on Technology, Information Policy, Intergovernmental Relations, and the Census, House Committee on Government Reform, March 30, 2004
- GAO-04-354 -- CRITICAL INFRASTRUCTURE PROTECTION: Challenges and Efforts to Secure Systems, March 15, 2004
- GAO-01-208t -- HOMELAND SECURITY: A Risk Management Approach Can Guide Preparedness Efforts
- GAO-04-140T -- CRITICAL INFRASTRUCTURE PROTECTION: Challenges in Securing Control Systems,October 1, 2003
- GAO-01-323 -- CRITICAL INFRASTRUCTURE PROTECTION: Significant Challenges in Developing National Capabilities, April 25, 2001
- GAO/T-AIMD-00-229 -- CRITICAL INFRASTRUCTURE PROTECTION: Comments on the Proposed Cyber Security Information Act of 2000, June 22, 2000
- GAO/T-AIMD-181 -- CRITICAL INFRASTRUCTURE PROTECTION: "ILOVEYOU" Computer Virus Highlights Need for Improved Alert and Coordination Capabilities, May 18, 2000
- GAO/T-AIMD-171 -- INFORMATION SECURITY: "ILOVEYOU" Computer Virus Emphasizes Critical Need for Agency and Governmentwide Improvements, May 10, 2000
- GAO/T-AIMD-00-7 -- CRITICAL INFRASTRUCTURE PROTECTION: Fundamental Improvements Needed to Assure Security of Federal Operations, October 6, 1999
- GAO/T-AIMD-99-223 -- INFORMATION SECURITY: Recent Attacks on Federal Web Sites Underscore Need for Stronger Information Security Management, June 24, 1999
- GAO/AIMD-99-47 -- INFORMATION SECURITY: Many NASA Mission-Critical Systems Face Serious Risk, May 1999
- GAO/AIMD-98-145 -- COMPUTER SECURITY: Pervasive, Serious Weaknesses Jeopardize State Department Operations, May 1998
- GAO/AIMD-98-155 -- AIR TRAFFIC CONTROL: Weak Computer Security Practices Jeopardize Flight Safety, May 1998
- GAO/T-AIMD-98-170 -- INFORMATION SECURITY: Serious Weaknesses Put State Department and FAA Operations at Risk, May 1998
- GAO/AIMD-98-68 -- EXECUTIVE GUIDE: Information Security Management -- Learning From Leading Organizations, May 1998
- GAO/HR-97-1 -- HIGH RISK SERIES: An Overview, February 1997
- GAO/HR-97-9 -- HIGH RISK SERIES: Information Management and Technology, February 1997
Department of Defense publications
NIST Computer Security Standards, Checklists, and Special Publications
- NIST Computer Security Resource Center home page
- Special Publication 800-88: Guidelines for Media Sanitization, September, 2006 (PDF)
- Draft NIST Special Publication 800-86: Guide to Computer and Network Data Analysis: Applying Forensic Techniques to Incident Response, August 11, 2005 (PDF)
- Special Publication 800-61: Computer Security Incident Handling Guide, January 2004 (PDF)
- Recommended Security Controls for Federal Information Systems, Revision 2, December, 2007 (PDF)
- DRAFT Special Publication 800-45 -- Guidelines on Electronic Mail Security (PDF)
- Computer Security Resource Center Practices & Checklists / Security Guides
- DRAFT Special Publication 800-40 -- Procedures for Handling Security Patches (PDF)
- Special Publication 800-30 -- Risk Management Guide for Information Technology Systems (PDF)
- The Inevitability of Failure: The Flawed Assumption of Security in Modern Computing Environments (.pdf)Peter A. Loscocco, Stephen D. Smalley, Patrick A. Muckelbauer, Ruth C. Taylor, S. Jeff Turner, John F. Farrell, National Security Agency
- NIST 800-18 -- Guide for Developing Security Plans for Information Technology Systems, December 1998
- NIST 800-10 -- Keeping Your Site Comfortably Secure: An Introduction to Internet Firewalls. [PDF format]
- NIST 800-14 -- Generally Accepted Principles and Practices for Securing Information Technology Systems, June 1996 [PDF format]
- NIST 800-12 -- An Introduction to Computer Security: The NIST Handbook, October 1995
- NIST DRAFT Special Publication Internet Security Policy: A Technical Guide
Risk Management
Security Policy/Incident Response
- Creating aa proactive enterprise security incident response program, by Marcos Christodonte II, SearchSecurity, Mar 29, 2010
- CSIRT Case Classification (Example for Enterprise CSIRT), by Dustin Schieber and Gavin Reid (Cisco Systems) and Ivo Peixinho (CAIS/RNP)
- RFPolicy 2.0 by Rain Forest Puppy
- Best Practices RFCs
- RFC2196, Site Security Handbook
- RFC2350, Expectations for Computer Security Incident Response
- RFC2504, Users' Security Handbook
- (See NIST 800-30)
- (See NIST 800-18)
- (See NIST 800-14)
- (See NIST 800-12)
- (See NIST 800-xx)
- A Framework for Incident Response, Information Security Team, DePaul University, December 13, 2002
- Harvard University's Information Security Handbook
- Handbook for Computer Security Incident Response Teams (CSIRTs), Moira J. West-Brown, Don Stikvort, and Klaus-Peter Kossakowski
- Forming an Incident Response Team, Danny Smith
Secure Email
Secure Programming
Miscellaneous Security related pages
- Microsoft Windows
- An introduction to the Internet and Internet Security.
- http://www.alw.nih.gov/Security/security-docs.html
- You can't think of any ways to make money off security holes? DigiCrime, Inc. has! ;)
- Dan Farmer's survey of (in)security of Web sites
- The National Info-Sec Technical Baseline (draft)
- UNIX Review - Security Loopholes
- Back issues of SunWorld Online's Security column
- USENIX - Security Web Sites
- Computer Security Canada, Inc.
- INFO SECURITY NEWS magazine
- CIAC-2318_IRC_On_Your_Dime.pdf
- TrustedBSD Project (Orange book B1 enhancements to FreeBSD)
- The Solaris Security FAQ at www.SunWorld.com
- Centralized System Monitoring With Swatch, by Stephen E. Hansen and E. Todd Atkins, Stanford University (LISA '93 presentation)
- SecWiz Security Guides
- Bill Wall's list of hacker incidents
- 2nd Annual Global Information Security Survey, Ernst & Young, LLP
- 2000 Computer Crime and Security Survey, Computer Security Institute (CSI)
- An Analysis Of Security Incidents On The Internet: 1989 - 1995, by John D. Howard, April 7, 1997
- The BlackHat Briefings and DEFCON
- The OpenBSD Project produces a very secure (out of the box) version of Unix
- Fred Cohen & Associates essays and articles
- Kerberos: The Network Authentication Protocol
Readings for Critical Infrastructure "Cyberterrorism" course
Password crackers and dictionaries
Back to home page