Seven anti-phishing projects, I especially find the browser recon and countermeasures one as a trendy concept, as phishers are already taking advantage of vulnerabilities allowing them to figure out a browser's history, thus establish a more reputable communication with the victim -- adaptive phishing. . The link for this article located at Dancho Danchev is no longer available. . Explore eight cutting-edge anti-phishing initiatives aimed at improving web browser defenses and dynamic strategies.. Anti-Phishing Strategies, Browser Countermeasures, Cybersecurity Innovations, Online Safety Techniques. . LinuxSecurity.com Team
I was at CardTech/SecurTech 2006 recently and had a meeting with Cryptography Research, a company focused on securing smartcards. I spoke to Kit Rodgers, VP, and Ken Warren, Manager, about smartcard tamper resistance with differential power analysis countermeasures. Listen to the interview with Cryptography Research Listen Now. The link for this article located at InfoWorld is no longer available. . The link for this article located at InfoWorld is no longer available. . cardtech/securtech, recently, meeting, cryptography, research, company. . LinuxSecurity.com Team
Future worms could evade a network of early-warning sensors hidden across the Internet unless countermeasures are taken, according to new research. In a pair of papers presented at the Usenix Security Symposium here Thursday, computer scientists said would-be attackers can locate such sensors, which act as trip wires that detect unusual activity. That would permit nefarious activities to take place without detection. . Internet sensor networks, such as the University of Michigan's Internet Motion Sensor and the SANS Internet Storm Center, are groups of machines that monitor traffic across active networks and chunks of unused IP space. The sensor networks generate and publish statistical reports that permit an analyst to track the traffic, sniff out malicious activity and seek ways to combat it. Just as surveillance cameras are sometimes hidden, the locations of the Internet sensors are kept secret. "If the set of sensors is known, a malicious attacker could avoid the sensors entirely or could overwhelm the sensors with errant data," a team of computer scientists from the University of Wisconsin wrote in its award-winning paper titled "Mapping Internet Sensors with Probe Response Attacks." But the Wisconsin researchers discovered that the sensor maps furnish just enough information for someone to create an algorithm that can map the location of the sensors "even with reasonable constraint on bandwidth and resources," John Bethencourt, one of the paper's authors, said in his presentation.. Analysis indicates that emerging malware may bypass cybersecurity frameworks, necessitating advanced protective strategies.. Internet Sensor Networks, Evasion Techniques, Cybersecurity Research. . Brittany Day
Spyware is challenging spam and viruses for the top spot on IT worry lists. Spyware poses considerable threats and risks to enterprise networks and remediation and countermeasures are now being regarded as critical to network security. . How Spyware Threatens Enterprises Spyware is defined as covertly installed software that hijacks web browsers, invades Internet user privacy, displays unsolicited and offensive advertising, and impedes PC performance. The most commonly cited spyware issues worrying enterprise IT staff are loss of productivity and increased helpdesk costs; liability associated with privacy violations; intellectual property theft, information and premature disclosure; and loss of credibility and damage to brand. The link for this article located at Dave Piscitello is no longer available. . Malware presents a serious risk to corporate infrastructures. Discover essential strategies for safeguarding against attacks.. Spyware Protection Strategies, Enterprise Malware Defense, Network Security Practices. . Joe Shakespeare
Citing an "arms race" in the ongoing spam wars, AT&T defended its patenting of a technology to thwart antispam filters. The patent, awarded to AT&T on Nov. 4, describes a "system and method for counteracting message filtering." The patent . . . . Citing an "arms race" in the ongoing spam wars, AT&T defended its patenting of a technology to thwart antispam filters. The patent, awarded to AT&T on Nov. 4, describes a "system and method for counteracting message filtering." The patent details a way to trick filters that compare digital messages to known pieces of spam, altering each message so that no two are exactly the same. "In this way, spam countermeasures based upon duplicate detection schemes are foiled," according to the patent. AT&T's patent wins approval as spam and software patents separately preoccupy the Internet. Opponents, pointing to patent-infringement judgments like that won by Eolas Technologies at Microsoft's expense, say software patents have created a siege mentality in the industry. And the spam problem has resulted in a host of proposed solutions in the software, standards and legislative arenas. . Citing an 'arms race' in the ongoing spam wars, AT&T defended its patenting of a technology to thwar. citing, 'arms, race', ongoing, at&, defended, patenting, technology, thwar. . LinuxSecurity.com Team
I am presently working on creating a taxonomy of information assurance, based on the three aspects of: Security services Information states Security countermeasures These three aspects of Information Assurance (IA) were highlighted by John McCumber [1] as well as a team . . . . I am presently working on creating a taxonomy of information assurance, based on the three aspects of: Security services Information states Security countermeasures These three aspects of Information Assurance (IA) were highlighted by John McCumber [1] as well as a team of West Point researchers [2] as a component of works that define an integrated approach to security. Within the next 6 months, I would like to create a taxonomy that graphically depicts the relationships of these three aspects. My intent is that this taxonomy could be used by the academic community, industry, and government in improving the precision of communication used in discussing information assurance/security topics. I have searched the Internet widely for a taxonomy of IA, but I have not found anything that is sufficiently detailed for application with real world problems. I am posting my initial results here in hopes that an open collaboration process (much like the open source software movement) will yield a useful tool for the security community to use in addressing information assurance issues. The link for this article located at Abe Usher is no longer available. . I am presently working on creating a taxonomy of information assurance, based on the three aspects o. presently, working, creating, taxonomy, information, assurance, based, three, aspects. . LinuxSecurity.com Team
Buffer overflow problems always have been associated with security vulnerabilities. In the past, lots of security breaches have occurred due to buffer overflow. This article attempts to explain what buffer overflow is, how it can be exploited and what countermeasures can be taken to avoid it. . . .. Buffer overflow problems always have been associated with security vulnerabilities. In the past, lots of security breaches have occurred due to buffer overflow. This article attempts to explain what buffer overflow is, how it can be exploited and what countermeasures can be taken to avoid it. Knowledge of C or any other high level language is essential to this discussion. Basic knowledge of process memory layout is useful, but not necessary. Also, all the discussions are based on Linux running on x86 platform. The basic concepts of buffer overflow, however, are the same no matter what platform and operating system is used. The link for this article located at Linux Journal is no longer available. . Buffer overflow attacks are common security vulnerabilities that can lead to crashes, unauthorized access, or code execution by overwriting memory locations. Buffer Overflow, Attack Methods, System Security, Exploit Techniques. . LinuxSecurity.com Team
There's a war brewing in cyberspace. Make that a Netwar, so dubbed in Countering the New Terrorism, a book published last year by The RAND Corp., a Santa Monica, Calif.-based nonprofit research group formed during World War II.. . .. There's a war brewing in cyberspace. Make that a Netwar, so dubbed in Countering the New Terrorism, a book published last year by The RAND Corp., a Santa Monica, Calif.-based nonprofit research group formed during World War II. It'll be a long time before remote-controlled robots fight battles to keep intruders out of office buildings (though unconfirmed reports circulated among security newsgroups in September did claim that a company in Thailand has invented a gun-toting robot directed through a remote-controlled camera). But many players, including the government, RAND and Winn Schwartau, a security analyst in Seminole, Fla., say this information war is already upon us. And in his Internet survival book, Cybershock, Schwartau claims that some private corporations are already launching military-style counterattacks to protect their interests. The link for this article located at ComputerWorld is no longer available. . Explore the rise of digital conflict in the online realm, alongside corporate strategies designed to combat cybersecurity challenges.. Cyber Warfare, Corporate Countermeasures, Netwar Strategies, Information Warfare. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.