![]() |
|
|
|||||||
|
New Podcast ReleasedFour experience reports demonstrate how the CERT Resilience Management Model can be applied to manage complex and diverse operational risks.
Categories: Security
Call for Participation: HICSS-47 "Software Security for Mobile Platforms" MinitrackThis minitrack focuses on research and automation techniques that can be applied to mobile platforms to ensure that developed software on these devices is secure and does not compromise other system properties. If you would like to contribute to the minitrack, visit the HICSS-47 website or send email to hicss47-minitrack@sei.cmu.edu.
Categories: Security
New Blog Entry: The Risks of Microsoft Exchange Features that Use Oracle Outside InThis blog post describes the risks of using Microsoft Exchange features that use Oracle Outside In and what you can do about it.
Categories: Security
Technical Note on Foreign Involvement in Insider Intellectual Property Theft ReleasedThis entry in the Spotlight On series summarizes such cases and insiders and provides recommendations for mitigating these incidents.
Categories: Security
New Blog Post: Keep Calm and Deploy EMETThis blog post provides information about an effective approach to blocking exploits of CVE-2013-1347, the Internet Explorer 8 CGeneric Element object use-after-free vulnerability.
Categories: Security
New Blog Entry: Controlling the Malicious Use of USB MediaThis blog post explains the importance of protecting your organization from the theft of sensitive information using USB media.
Categories: Security
New Blog Entry: Don't Sign that Applet!This blog post describes how Oracle's new guidance for Java applets may cause more harm than good.
Categories: Security
New Blog Entry: Finding Patterns of Malicious Use in Bulk RegistrationsThis blog post describes how finding patterns in bulk registrations can help identify potentially malicious domains.
Categories: Security
GeoIP in Your SOC (Security Operations Center)This blog entry describes how to use geoIP to view data and help your network situational awareness.
Categories: Security
Call for Participation: FloCon 2014We are accepting abstracts for presentations, posters, and demonstrations for FloCon 2014, a network security conference that takes place in Charleston, South Carolina, on January 13-16, 2014.
Categories: Security
New Blog Entry: Second Level Domain Usage in 2012 for Common Top Level DomainsThis blog post looks at second level domain usage in 2012 for the most common generic Top Level Domains.
Categories: Security
New Book Released: Secure Coding in C and C++, Second EditionSecure Coding in C and C++, Second Edition identifies the root causes of today's most widespread software vulnerabilities, shows how they can be exploited, reviews the potential consequences, and presents secure alternatives.
Categories: Security
New Blog Entry: The Growth of IPv6 AnnouncementsThis blog post presents a method for assessing how popular IPv6 is on the internet.
Categories: Security
New Blog Entry: An Alternate View of Announced IPv4 SpaceThis blog post describes an alternate way to view advertised IP address space on the internet using publicly available information.
Categories: Security
Justification of a Pattern for Detecting Intellectual Property Theft by Departing Insiders ReleasedThis technical note describes an analysis of the pattern "Increased Review for Intellectual Property (IP) Theft by Departing Insiders," which helps organizations mitigate the risk of insider theft of IP.
Categories: Security
New Blog Entry: The Growth Rate of IP Addresses That Are Advertised as Usable on the InternetThis blog post describes how you can calculate the growth rate of advertised IP address space on the internet using publicly available information.
Categories: Security
New Blog Entry: How Ontologies Can Help Build a Science of CybersecurityThis blog post introduces you to work done on an ontology for malware.
Categories: Security
New Blog Entry: Watching Domains That Change DNS Servers FrequentlyThis blog entry describes the results of our three-month study of domains that change their name servers frequently.
Categories: Security
Malware Analysis Lexicon ReleasedThis technical note presents the first common vocabulary for malware analysis.
Categories: Security
|