Computer Security
IT666 Reading List
Please be sure to read the required items (in bold) prior to the lecture. Additional readings have been provided for students that wish to gain deeper or alternative insights into specific topics. The required and additional readings can and will overlap but the student will not be held responsible for knowing any information that exists only in the additional readings.
The text .Computer Security: Principles and Practices. by Stallings & Brown, 2012 ISBN: 978-0-13-277506-9. Covers most of the topics. Applicable chapters are indicated by. Stallings: chap x.y Stallings web site
A number of the technical articles require access via the UNH library. UNH library: url
For those completely new to computer security:
- Wikipedia is a great source of articles covering basic concepts with links to further detail. link
- SANS has a nice concise glossary: link
- Microsoft provides free tools, training and advice for users of Microsoft products:link
- Security Focus: A wide variety of security information, with an emphasis on vendor products and end-user concerns. Maintains the
- Bugtraq, a mailing list for the detailed discussion and announcement of computer security vulnerabilities.
- SANS Institute: Similar to Security Focus. Extensive collection of white papers. Maintains
- Internet Storm Center, which provides a warning service to Internet users and organizations concerning security threats.
- Open Web Application Security Project
- Good security blog hosted by Sophos
- Stallings: Chapter 1
- Authentication, Authorization, and Access Control (AAA)
- Types of Authentication link
- Introduction to Shibboleth link
- NIST RBAC model; 2002, Sandhu, et.al., pdf
- Death of Authentication, Gartner 2010 pdf
- The Intersection of Mobile and Authentication, Gartner pdf
- Application Privacy Assessments (Microsoft) link
- Sony password analysislink
- Password Worst Practives, (Imperva) pdf
- Least privilege : link
- Password Usage and Generation: NIST documents on this topic
- Biometrics Consortium: Government-sponsored site for the research, testing, and evaluation of biometric technology
- NIST RBAC site: Includes numerous documents, standards, and software on RBAC
- Stallings: Chapter 3, 4
- Encryption
- A flash demonstration of how Rijndael (AES) works. The zip contains a windows executable. zipped executable
- One of the better RSA tutorials: link
- SHA-2 link
- A slightly dated but still valid comparison of techniques: link
- AES Home Page: NIST's page on AES. Contains the standard plus a number of other relevant documents
- AES Lounge: Contains a comprehensive bibliography of documents and papers on AES, with access to electronic copies.
- Block Cipher Modes of Operation: NIST page with full information on NIST-approved modes of operation.
- A nice online tool for comparing algorithms: online demo
- The current US federal standards (Suite B): link
- Educational cryptography tool: executable
- Selecting the Advanced Encryption Standard: UNH Library
- The First 10 years of Advanced Encryption: UNH Library
- ECC patent: pdf
- RSA patent: pdf
- Generating Elliptic Curves, IEEE, Hailiza Kamarulhaili, UNH Library
- The Cryptography FAQ: Lengthy and worthwhile FAQ covering all aspects of cryptography.
- Bouncy Castle Crypto Package: Java implementation of cryptographic algorithms. The package is organized so that it contains a light-weight API suitable for use in any environment. The package is distributed at no charge for commercial or non-commercial use.
- Cryptography Code: Another useful collection of software.
- American Cryptogram Association: An association of amateur cryptographers. The Web site includes information and links to sites concerned with classical cryptography.
- Crypto Corner: Simon Singh's Website. Lots of good information, plus interactive tools for learning about cryptography.
- Stallings: Chapter 2, 20
- Keys
- SSL Web site Basics: link
- Sample CA/OCSP architecture: link
- PKI Overview: pdf
- Guide to Public Key Infrastructures (PKI): link
- Certificate Revocation and Status Checking in Windows: link
- What the federal government is doing: link
- W3C XML Key Management standard: link
- Public-Key Infrastructure Working Group: IETF group developing standards based on X.509v3.
- NIST PKI Program: Good source of information.
- NIST Secure Hashing Page: SHA FIPS and related documents.
- RSA Laboratories: The research center of RSA Security, Inc., it offers an extensive collection of technical material on RSA and other topics in cryptography
- Stallings: Chapter 21, 23
- Defense
- DSD Top35 Intrusion Mitigation Strategies: The Australian Defence Signals Directorate list of top intrusion mitigation strategies.
- Intrusion Detection and Prevention: pdf
- BlackBox vs. WhiteBox testing: pdf
- Immunity Analogy: pdf
- Bayesian Classifiers: pdf
- SNORT: Hakin9 ezine, pages (8-12): pdf
- Open Security Foundation: Runs the
- DataLossDB project, which compiles a wide variety of statistics, charts, graphs, and incident report.
- Honeynet Project: A research project studying the techniques of predatory hackers and developing honeypot products
- Honeypots: A good collection of research papers and technical articles.
- Stallings: Chapter 9, 12
- Networking
- Next Generation Firewalls for Dummies: pdf
- Qualys SSL Labs: link
- Proxy types: link
- DOS attacks and defense (Section 3): pdf
- IPsec: link
- David Dittrichâs Distributed Denial Of Service Site: Contains lists of books, papers, and other information on DDoS attacks and tools.
- TLS Charter: Latest RFCs and internet drafts for TLS.
- OpenSSL Project: Project to develop open-source SSL and TLS software. Site includes documents and link.
- NIST IPSec Project: Contains papers, presentations, and reference implementations.
- Firewall concepts and term from Cisco: pdf
- Firewall.com: Numerous links to firewall references and software resources.
- Stallings: Chapter 7, 9, 22
- Identity
- What they know: online demo
- Identity types and concerns: pdf
- NIST PII Guide: link
- Net Anonymity: link
- Current federal NSTIC efforts: pdf and link and link
- Introduction to Web Beacons: link
- Facebook wants to supply your Internet driver.s license: link
- Web
- The 17 most dangerous places on the Web: link
- SQL Injection basics: link
- Cross site scripting basics: link
- Web application security basics: pdf
- HTML5 Security: pdf
- JavaScript errors: pdf
- Advanced SQL injection: pdf
- Towards a Formal Foundation of Web Security, Akhawe, et.al., 2010 IEEE: UNH Library
- Mobility
- The state of WiFi Security in 2010: link
- With new GPS dating apps, its love the one you.re near link
- Mobile Virus Infection Rates: pdf
- Wireless PKI Security: UNH Library
- IEEE 802.11 Wireless LAN Working Group: Contains working group documents plus discussion archives.
- Wi-Fi Alliance: An industry group promoting the interoperabiltiy of 802.11 products with each other and with Ethernet.
- Extensible Authentication Protocol (EAP) Working Group: IETF working group responsible for EAP and related issues.
- RFCs: IETF RFC repository. Includes a complete list of all RFCs, constantly updated.
- RFC Sourcebook: Provides the relevant information on RFCs in an easy to use, easy to access format.
- Stallings: Chapter 24
- Criminals
- 2010 Data breach report: pdf
- Risk
- How can a smart species be so dumb?: link
- Microsoft Threat Model Process: link
- Writing Effective Security Abuse Cases : pdf
- Toward Econometric Models of the Security Risk from Remote Attack, Schechter : UNH Library
- Data-Centric Quantitative Computer Security Risk Assessment:link
- Separation of Duties and IT Security : link
- 6 tips for guarding against rogue sys admins : link
- Information Security Guide: A compendium of information providing guidance on effective approaches to the application of information security at institutions of higher education. The information is useful for any organization.
- CSI Computer Crime and Security Survey: Details of annual surveys of computer network attacks and computer misuse trends.
- Verizon Security Blog: and their
- Data Breach Investigations Report provide regular updates on security issues, and their annual summary report is compiled with the assistance of the US Secret Service.
- Stallings: Chapter 14
- Physical
- Hacking cars: pdf and link and link
- Theft control turned surveillance: link
- Stuxnet virus and SCADA: link and link
- Security and Privacy Vulnerabilities of In-Car Wireless Networks: A Tire Pressure Monitoring. Usenix 2010: Rouf, et.al. (pages: 323 . 338) pdf
- Federal PIV Card Specification: pdf
- Robot crime: pdf
- InfraGuard: An FBI program to support infrastructure security efforts. Contains a number of useful documents and links
- The Infrastructure Security Partnership: A public-private partnership dealing with infrastructure security issues. Contains a number of useful documents and links.
- Federal Emergency Management Administration (FEMA): Contains a number of useful documents related to physical security for businesses and individuals.
- NIST PIV program: Contains working documents, specifications, and links related to PIV.
- Stallings: Chapter 16
- Hardware
- Trusted Computing Group: Vendor group involved in developing and promoting trusted computer standards. Site includes white papers, specifications, and vendor links.
- Common Criteria Portal: Official Web site of the common criteria project.
- Intel Initiatives: pdf
- Stallings: Chapter 13
- Tools
- Nmap download : link tutorial : link
- Wireshark download: link tutorial : link
- Netcat : pdf
- Snort download : link tutorial : ppt
- Snort: Web site for Snort, an open source network intrusion prevention and detection system.
- Metasploit: The Metasploit Project provides useful information on shellcode exploits to people who perform penetration testing, IDS signature development, and exploit research
- Stallings: Chapter 8, 10
- Usability
- Month of Twitter Bugs : link
- Successful failure : pdf
- YAEP
- Shibboleth expert demo : link
- SAML references : link
- Web Services Security (OASIS standard) : pdf
- MIT Kerberos Site: Information about Kerberos, including the FAQ, papers and documents, and pointers to commercial product sites.
- XML
- Basic XML signature process : link
- OS & Open Source
- Open Source Security: Still a Myth, Viega, link
- Strengthening the Empirical Analysis of the Relationship between Linus. Law and Software Security, Meneely, et.al.: UNH Library
- Predicting Failures with Developer Networks and Social Network Analysis : UNH Library
- Increasing software security through open source or closed source development? Schryen & Rich : UNH Library
- NSA SELinux web site: Contains useful documentation on SELinux.
- Microsoft Security Central: Good collection of information about Windows and Windows Vista security
- Linux Documentation Project: manuals on Linux systems administration.
- Microsoft Security Tools & Checklists: tools and guidance to assess security on Microsoft Windows systems.
- SANS - Top Cyber Security Risks: that organizations should address.
- Stallings: Chapter 12
- SDLC
- Waterfall vs. Agile .the war and Matrix. .Getting Students to Think About How Agile Processes Can Be Made More Secure., Epstein, UNH Library
- Open Web Application Security Project (OWASP): Dedicated to finding and fighting the causes of insecure software and providing open source tools to assist this process. Includes the
- OWASP Secure Coding Practices Quick Reference Guide, which defines a set of general software security coding practices, in a checklist format, that can be integrated into the software development lifecycle. Implementation of these practices will mitigate most common software vulnerabilities.
- Veracode: State of Software Security link
- BSIMM compares your secure development efforts to others, McGraw, link
- State-of-the-Art: Software Inspections after 25 Years, Aurum, et.al., link
- CERT Secure Coding: Resource on CERT site of links to information on common coding vulnerabilities and secure programming practices.
- CWE/SANS Top 25 Most Dangerous Software Errors: A list of the most common types of programming errors that were exploited in many major cyber attacks, with details on how they occur and how to avoid them.
- David Wheeler - Secure Programming: Provides links to his book and other articles on secure programming.
- Fuzz Testing of Application Reliability: Provides details of the security analysis of applications using random input performed by the University of Wisconsin Madison.
- Stallings: Chapter 11
- Quality
- An Attack Scenario Based Approach for Software Security Testing at Design Stage, He et.al, UNH Library
- Comparing the Effectiveness of Penetration Testing and Static Code Analysis on the Detection of SQL Injection Vulnerabilities in Web Services, Antunes, et.al. UNH Library : UNH Library
- Proof Carrying Code : pdf
- Formal verification (economy of mechanisms) : pdf
- Evaluation of SQL Injection Detection and Prevention Technique., Tajpour & Shooshtari: UNH Library
- Static analysis success/failure: link
- Legal
- International Cyber Threat Task Force: An online security community of cyber security professionals collaborating to deal with all related cyber threats including all aspects of cyber crime and cyber warfare. Useful documents and other information.
- Criminal Justice Resources: CyberCrime: Excellent collection of links maintained by Michigan State University.
- International High Technology Crime Investigation Association: A collaborative effort of law enforcement and the private sector. Contains useful set of links and other resources.
- Computer Ethics Institute: Includes documents, case studies, and links.
- The Rules: Maintained by the Ad Hoc Committee on Responsible Computing.
- .FABLE: A Language for Enforcing User-defined Security Policies., Swamy et.al, UNH Library : link
- Stallings: Chapter 19
- Jailbreaking
- Let the Pirates Patch? An Economic Analysis of Software Security Patch Restrictions, August et.al., link
- Is iOS jailbreaking an enterprise security threat? link
- U.S. Declares iPhone Jailbreaking Legal, Over Apple.s Objections : link
- Prosecutors Dismiss Xbox-Modding Case Mid-Trial : link
- Apple.s stance on unauthorized modification of iOS : link
- Forensics
- Zeus Botnet : pdf CVSS scoring system : link
- Russian Spy Ring Communicated Through Steganography, link
- Steganography meets VoIP in hacker world link
- Bitstacker: Accurately and efficiently monitoring Bittorrent traffic, Kevin Bauer et.al.,
- Computer Security Incident Response Team: Provide security professionals with the means to report, discuss, and disseminate computer security related information to others around the world. This site provides information for reporting security incidents and information on technical resources. UNH Library
- Stallings: Chapter 17
- Governance
- Auditing Mechanisms, UNH Scanning : pdf
- 10 Essential Security Policies, Stewart, link
- Case Study: UNH AUP link
- HIPAA introduction: link
- Federal Agency Security Practices: A voluminous set of documents covering all aspects of organizational security policy
- ISO 27002 Community Portal: Documents, links, and other resources related to ISO 27002
- Security Issues in Network Event Logging: This IETF working group is developing standards for system logging.
- Stallings: Chapter 17, 19
- Virtualization
- Securing Elasticity in the Cloud, Owens : pdf
- 5 Laws of Virtualization Security : pdf
- Security in the Cloud, Anthes : pdf
- Sandboxing : pdf and link
- Cloud Security Alliance: Organization promoting best practices for cloud security implementation. Site contains useful documents and links.
- Researchers to Cure Blue Pill Virtualization Attacks : link
- Case Study: Amazon as web-scale company video: video and being DDoS immune: link
- Stallings: Chapter 5
- Biometrics
- Face recognition : link
- Blackhat 2011: Face recognition to SSN: link
- Eye Movements : link
- Facebook tagging (case study) : link and link
- Biometric Web Services : link
- CAPTCHA : link
- NH rejects biometrics bill : link
- Stallings: Chapter 3, 16
- Zero Day
- Empirical Estimates and Observations of 0Day Vulnerabilities, McQueen, et.al.,: UNH Library
- Developing a Community Cyber Security Incident Response Capability, White: UNH Library
- Paths to Compromise: pdf
- Stuxnet dossier pdf
- Security Patch Management: Share the Burden or Share the Damage, Cavusoglu, et.al., : UNH Library
- Microsoft Dec.10 Patch Tuesday: link
- Gawker response to hack : link
- Three Lessons from the RSA Hack, from a Customer's Perspective: link
- Vmyths: Dedicated to exposing virus hoaxes and dispelling misconceptions about real viruses.
- SecureList: Information about viruses, hackers, and spam.
- Symantec Internet Threat Security Report: Annual report on the Internet threat landscape by commercial antivirus software provider Symantec.
- Symantec Security Response: Site maintained by commercial antivirus software provider Symantec, with much useful information on current malware risks.
- Stallings: Chapter 6
- More readings
- Mitre report to DoD on the state of cyber security: pdf
Lectures
Last modified on August 10, 2013. Comments and questions should be directed to ken.graf@cs.unh.edu