- Is the Cisco MARS mission going to abort?
- First iPhone worm spreads Rick Astley wallpaper
- 10 stunning 3D buildings made with Google SketchUp
- Open source software ready for big business
- Four reasons to buy (and one reason to avoid) the Droid
Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.
Regular readers of this column know that I give a graduate seminar to my MSIA students every year in June called “INFOSEC Year in Review” or “IYIR” for short. This year the 135 graduating students and about 50 more students who will graduate in December received a 453-page book with 1,240 abstracts (including introductory material such as the list of categories) dating from Jan. 1, 2006, through May 30, 2007, classified using 280 possible categories.
The workbook is a selection I made from a total of 3,532 abstracts in that period. The full database and a complete PDF listing of the contents will be posted on my Web site later after some volunteers and I finish adding keywords to the abstracts.
I added up my time sheets on this project and it personally took me 163.5 hours from mid-May to mid-June to enter, format, and classify those abstracts; I tell you, I sure missed my research assistants this year!
For now, readers may download the 3MB PDF file freely for non-commercial uses such as teaching, research or just plain reading. Please do not post copies of the file on the Web - multiple copies are impossible to keep updated, and I do issue corrected versions of these files as I catch typos and other errors.
The IYIR course always sparks interesting discussions among the participants, and I hope that readers will be able to use the workbook fruitfully for brown-bag lunches and other stimulating meetings to discuss trends in information assurance. I doubt you will want to print this fairly hefty workbook, but you are welcome to do so if you want to as long as you don’t sell it (growl).
The workshop is broken into four sections (morning and afternoon of the two days) and the codes correspond to the parts: those beginning with 1 correspond to topics for the morning of Day 1 and so on. Some of the sections (and their codes) that I found particularly interesting this year in discussions with the graduate students were the following:
14.4 Trojans
14.5 Rootkits & back doors
14.6 Bots & botnets
16.3 Infrastructure vulnerabilities
16.5 Military perspectives on cyberwar & battlespace
18.1 Stolen equipment or media
18.2 Lost or missing equipment or media
1A7 Contests
23.7 VoIP
23.A Open-source software
24.6 Wireless
25.1 Remote control, RATs, reprogramming, auto-updates
25.2 Jamming
26.3 Keystroke loggers
26.4 Cell/mobile phones tracking, eavesdropping & cameras
29.4 Online & electronic voting
29.7 Social networks
31.1 Surveys, studies
31.2 Audits, GAO reports
31.4 New technology with potential security vulnerabilities or implications
33.2 Spam, spim, spit, splogs, phish, vish & pharms
33.5 Data-encryption policies
33.6 Outsourcing & offshoring
43.2 Biometrics
43.7 IPv6 & Internet2
49.1 U.S.-government surveillance
49.2 Non-U.S.-government surveillance
49.3 Anti-terrorist measures
49.4 Airport & Air Transport security
49.7 National ID cards/documents; REAL ID
M. E. Kabay, PhD, CISSP-ISSMP, specializes in security and operations management consulting services. CV online.
Comments (5)
Veterans Administration should be ashamed of the way it's dealing with that data breachBy Anonymous on June 12, 2007, 11:14 amIt's interesting that the letter states, in so many words, that (a) we (the VA) lost your data, and (b) the victim (recipient of the letter) whose personal data...
Reply | Read entire comment
VA Loss of DataBy Anonymous on June 13, 2007, 8:41 amI notice the letter stated that the PII was being used for research. Canada's Protection of Privacy Act requires that personal data may only be used for what it...
Reply | Read entire comment
In CanadaBy Anonymous on June 21, 2007, 2:26 pmFortunately, in Canada, the vast majority of the population (including hackers & thieves) are too stupid to understand IT security or even how to breach it (if it...
Reply | Read entire comment
As a US Army Veteran am very, very gratefulBy Brad Reese on June 21, 2007, 6:45 pmAs a US Army Veteran, I thank the US Department of Veterans Affairs every single day for the superb and excellent medical care they provide me and my fellow veterans. There...
Reply | Read entire comment
Automated harassmentBy Anonymous on June 29, 2007, 3:21 pmI was subjected to this kind of harrasement for well over a decade by Verizon in conjuction with another corporation. The only way out, for me was, to drop my landline...
Reply | Read entire comment
View all comments