Computer Security

IT666 Reading List

Please be sure to read the required items (in bold) prior to the lecture. Additional readings have been provided for students that wish to gain deeper or alternative insights into specific topics. The required and additional readings can and will overlap but the student will not be held responsible for knowing any information that exists only in the additional readings.

The text .Computer Security: Principles and Practices. by Stallings & Brown, 2012 ISBN: 978-0-13-277506-9. Covers most of the topics. Applicable chapters are indicated by. Stallings: chap x.y Stallings web site

A number of the technical articles require access via the UNH library. UNH library: url

For those completely new to computer security:

    Lectures

  1. Authentication, Authorization, and Access Control (AAA)
    • Types of Authentication link
    • Introduction to Shibboleth link
    • NIST RBAC model; 2002, Sandhu, et.al., pdf
    • Death of Authentication, Gartner 2010 pdf
    • The Intersection of Mobile and Authentication, Gartner pdf
    • Application Privacy Assessments (Microsoft) link
    • Sony password analysislink
    • Password Worst Practives, (Imperva) pdf
    • Least privilege : link
    • Password Usage and Generation: NIST documents on this topic
    • Biometrics Consortium: Government-sponsored site for the research, testing, and evaluation of biometric technology
    • NIST RBAC site: Includes numerous documents, standards, and software on RBAC
    • Stallings: Chapter 3, 4
  2. Encryption
    • A flash demonstration of how Rijndael (AES) works. The zip contains a windows executable. zipped executable
    • One of the better RSA tutorials: link
    • SHA-2 link
    • A slightly dated but still valid comparison of techniques: link
    • AES Home Page: NIST's page on AES. Contains the standard plus a number of other relevant documents
    • AES Lounge: Contains a comprehensive bibliography of documents and papers on AES, with access to electronic copies.
    • Block Cipher Modes of Operation: NIST page with full information on NIST-approved modes of operation.
    • A nice online tool for comparing algorithms: online demo
    • The current US federal standards (Suite B): link
    • Educational cryptography tool: executable
    • Selecting the Advanced Encryption Standard: UNH Library
    • The First 10 years of Advanced Encryption: UNH Library
    • ECC patent: pdf
    • RSA patent: pdf
    • Generating Elliptic Curves, IEEE, Hailiza Kamarulhaili, UNH Library
    • The Cryptography FAQ: Lengthy and worthwhile FAQ covering all aspects of cryptography.
    • Bouncy Castle Crypto Package: Java implementation of cryptographic algorithms. The package is organized so that it contains a light-weight API suitable for use in any environment. The package is distributed at no charge for commercial or non-commercial use.
    • Cryptography Code: Another useful collection of software.
    • American Cryptogram Association: An association of amateur cryptographers. The Web site includes information and links to sites concerned with classical cryptography.
    • Crypto Corner: Simon Singh's Website. Lots of good information, plus interactive tools for learning about cryptography.
    • Stallings: Chapter 2, 20
  3. Keys
    • SSL Web site Basics: link
    • Sample CA/OCSP architecture: link
    • PKI Overview: pdf
    • Guide to Public Key Infrastructures (PKI): link
    • Certificate Revocation and Status Checking in Windows: link
    • What the federal government is doing: link
    • W3C XML Key Management standard: link
    • Public-Key Infrastructure Working Group: IETF group developing standards based on X.509v3.
    • NIST PKI Program: Good source of information.
    • NIST Secure Hashing Page: SHA FIPS and related documents.
    • RSA Laboratories: The research center of RSA Security, Inc., it offers an extensive collection of technical material on RSA and other topics in cryptography
    • Stallings: Chapter 21, 23
  4. Defense
    • DSD Top35 Intrusion Mitigation Strategies: The Australian Defence Signals Directorate list of top intrusion mitigation strategies.
    • Intrusion Detection and Prevention: pdf
    • BlackBox vs. WhiteBox testing: pdf
    • Immunity Analogy: pdf
    • Bayesian Classifiers: pdf
    • SNORT: Hakin9 ezine, pages (8-12): pdf
    • Open Security Foundation: Runs the
    • DataLossDB project, which compiles a wide variety of statistics, charts, graphs, and incident report.
    • Honeynet Project: A research project studying the techniques of predatory hackers and developing honeypot products
    • Honeypots: A good collection of research papers and technical articles.
    • Stallings: Chapter 9, 12
  5. Networking
    • Next Generation Firewalls for Dummies: pdf
    • Qualys SSL Labs: link
    • Proxy types: link
    • DOS attacks and defense (Section 3): pdf
    • IPsec: link
    • David Dittrichâs Distributed Denial Of Service Site: Contains lists of books, papers, and other information on DDoS attacks and tools.
    • TLS Charter: Latest RFCs and internet drafts for TLS.
    • OpenSSL Project: Project to develop open-source SSL and TLS software. Site includes documents and link.
    • NIST IPSec Project: Contains papers, presentations, and reference implementations.
    • Firewall concepts and term from Cisco: pdf
    • Firewall.com: Numerous links to firewall references and software resources.
    • Stallings: Chapter 7, 9, 22
  6. Identity
    • What they know: online demo
    • Identity types and concerns: pdf
    • NIST PII Guide: link
    • Net Anonymity: link
    • Current federal NSTIC efforts: pdf and link and link
    • Introduction to Web Beacons: link
    • Facebook wants to supply your Internet driver.s license: link
  7. Web
    • The 17 most dangerous places on the Web: link
    • SQL Injection basics: link
    • Cross site scripting basics: link
    • Web application security basics: pdf
    • HTML5 Security: pdf
    • JavaScript errors: pdf
    • Advanced SQL injection: pdf
    • Towards a Formal Foundation of Web Security, Akhawe, et.al., 2010 IEEE: UNH Library
  8. Mobility
  9. Criminals
    • Operation Aurora: pdf
    • Cybercrime survey (pages 2-7) pdf
    • Zeus Toolkit video: link
    • 2010 Data breach report: pdf
  10. Risk
    • How can a smart species be so dumb?: link
    • Microsoft Threat Model Process: link
    • Writing Effective Security Abuse Cases : pdf
    • Toward Econometric Models of the Security Risk from Remote Attack, Schechter : UNH Library
    • Data-Centric Quantitative Computer Security Risk Assessment:link
    • Separation of Duties and IT Security : link
    • 6 tips for guarding against rogue sys admins : link
    • Information Security Guide: A compendium of information providing guidance on effective approaches to the application of information security at institutions of higher education. The information is useful for any organization.
    • CSI Computer Crime and Security Survey: Details of annual surveys of computer network attacks and computer misuse trends.
    • Verizon Security Blog: and their
    • Data Breach Investigations Report provide regular updates on security issues, and their annual summary report is compiled with the assistance of the US Secret Service.
    • Stallings: Chapter 14
  11. Physical
    • Hacking cars: pdf and link and link
    • Theft control turned surveillance: link
    • Stuxnet virus and SCADA: link and link
    • Security and Privacy Vulnerabilities of In-Car Wireless Networks: A Tire Pressure Monitoring. Usenix 2010: Rouf, et.al. (pages: 323 . 338) pdf
    • Federal PIV Card Specification: pdf
    • Robot crime: pdf
    • InfraGuard: An FBI program to support infrastructure security efforts. Contains a number of useful documents and links
    • The Infrastructure Security Partnership: A public-private partnership dealing with infrastructure security issues. Contains a number of useful documents and links.
    • Federal Emergency Management Administration (FEMA): Contains a number of useful documents related to physical security for businesses and individuals.
    • NIST PIV program: Contains working documents, specifications, and links related to PIV.
    • Stallings: Chapter 16
  12. Hardware
    • Crypto Instructions: pdf
    • TPM fundamentals: pdf
    • DARPA Crash - SAFE: pdf
    • Trusted Computing Group: Vendor group involved in developing and promoting trusted computer standards. Site includes white papers, specifications, and vendor links.
    • Common Criteria Portal: Official Web site of the common criteria project.
    • Intel Initiatives: pdf
    • Stallings: Chapter 13
  13. Tools
    • Nmap download : link tutorial : link
    • Wireshark download: link tutorial : link
    • Netcat : pdf
    • Snort download : link tutorial : ppt
    • Snort: Web site for Snort, an open source network intrusion prevention and detection system.
    • Metasploit: The Metasploit Project provides useful information on shellcode exploits to people who perform penetration testing, IDS signature development, and exploit research
    • Stallings: Chapter 8, 10
  14. Usability
    • Password Policy : pdf
    • Psychological : pdf
    • Month of Twitter Bugs : link
    • Successful failure : pdf
  15. YAEP
    • Shibboleth expert demo : link
    • SAML references : link
    • Web Services Security (OASIS standard) : pdf
    • MIT Kerberos Site: Information about Kerberos, including the FAQ, papers and documents, and pointers to commercial product sites.
  16. XML
    • Digital signatures best practice : link
    • National Heath : link
    • Basic XML signature process : link
  17. OS & Open Source
  18. SDLC
    • Waterfall vs. Agile .the war and Matrix. .Getting Students to Think About How Agile Processes Can Be Made More Secure., Epstein, UNH Library
    • Open Web Application Security Project (OWASP): Dedicated to finding and fighting the causes of insecure software and providing open source tools to assist this process. Includes the
    • OWASP Secure Coding Practices Quick Reference Guide, which defines a set of general software security coding practices, in a checklist format, that can be integrated into the software development lifecycle. Implementation of these practices will mitigate most common software vulnerabilities.
    • Veracode: State of Software Security link
    • BSIMM compares your secure development efforts to others, McGraw, link
    • State-of-the-Art: Software Inspections after 25 Years, Aurum, et.al., link
    • CERT Secure Coding: Resource on CERT site of links to information on common coding vulnerabilities and secure programming practices.
    • CWE/SANS Top 25 Most Dangerous Software Errors: A list of the most common types of programming errors that were exploited in many major cyber attacks, with details on how they occur and how to avoid them.
    • David Wheeler - Secure Programming: Provides links to his book and other articles on secure programming.
    • Fuzz Testing of Application Reliability: Provides details of the security analysis of applications using random input performed by the University of Wisconsin Madison.
    • Stallings: Chapter 11
  19. Quality
    • An Attack Scenario Based Approach for Software Security Testing at Design Stage, He et.al, UNH Library
    • Comparing the Effectiveness of Penetration Testing and Static Code Analysis on the Detection of SQL Injection Vulnerabilities in Web Services, Antunes, et.al. UNH Library : UNH Library
    • Proof Carrying Code : pdf
    • Formal verification (economy of mechanisms) : pdf
    • Evaluation of SQL Injection Detection and Prevention Technique., Tajpour & Shooshtari: UNH Library
    • Static analysis success/failure: link
  20. Legal
  21. Jailbreaking
    • Let the Pirates Patch? An Economic Analysis of Software Security Patch Restrictions, August et.al., link
    • Is iOS jailbreaking an enterprise security threat? link
    • U.S. Declares iPhone Jailbreaking Legal, Over Apple.s Objections : link
    • Prosecutors Dismiss Xbox-Modding Case Mid-Trial : link
    • Apple.s stance on unauthorized modification of iOS : link
  22. Forensics
    • Zeus Botnet : pdf
    • CVSS scoring system : link
    • Russian Spy Ring Communicated Through Steganography, link
    • Steganography meets VoIP in hacker world link
    • Bitstacker: Accurately and efficiently monitoring Bittorrent traffic, Kevin Bauer et.al.,
    • Computer Security Incident Response Team: Provide security professionals with the means to report, discuss, and disseminate computer security related information to others around the world. This site provides information for reporting security incidents and information on technical resources.
    • UNH Library
    • Stallings: Chapter 17
  23. Governance
  24. Virtualization
    • Securing Elasticity in the Cloud, Owens : pdf
    • 5 Laws of Virtualization Security : pdf
    • Security in the Cloud, Anthes : pdf
    • Sandboxing : pdf and link
    • Cloud Security Alliance: Organization promoting best practices for cloud security implementation. Site contains useful documents and links.
    • Researchers to Cure Blue Pill Virtualization Attacks : link
    • Case Study: Amazon as web-scale company video: video and being DDoS immune: link
    • Stallings: Chapter 5
  25. Biometrics
    • Face recognition : link
    • Blackhat 2011: Face recognition to SSN: link
    • Eye Movements : link
    • Facebook tagging (case study) : link and link
    • Biometric Web Services : link
    • CAPTCHA : link
    • NH rejects biometrics bill : link
    • Stallings: Chapter 3, 16
  26. Zero Day
    • Empirical Estimates and Observations of 0Day Vulnerabilities, McQueen, et.al.,: UNH Library
    • Developing a Community Cyber Security Incident Response Capability, White: UNH Library
    • Paths to Compromise: pdf
    • Stuxnet dossier pdf
    • Security Patch Management: Share the Burden or Share the Damage, Cavusoglu, et.al., : UNH Library
    • Microsoft Dec.10 Patch Tuesday: link
    • Gawker response to hack : link
    • Three Lessons from the RSA Hack, from a Customer's Perspective: link
    • Vmyths: Dedicated to exposing virus hoaxes and dispelling misconceptions about real viruses.
    • SecureList: Information about viruses, hackers, and spam.
    • Symantec Internet Threat Security Report: Annual report on the Internet threat landscape by commercial antivirus software provider Symantec.
    • Symantec Security Response: Site maintained by commercial antivirus software provider Symantec, with much useful information on current malware risks.
    • Stallings: Chapter 6
  27. More readings
    • Mitre report to DoD on the state of cyber security: pdf

Last modified on August 10, 2013. Comments and questions should be directed to ken.graf@cs.unh.edu