Excuses for not doing the easy security


For as long as I would say that I truly understood computer security I have believed that security in depth is one of the most important elements of security. Coming from this perspective I often find it interesting how many relatively easy elements are not implemented by practitioners. Some of these are the same practitioners that will go to extraordinary lengths in other areas to secure their systems.

An Application Agnostic Review of Current Spam Filtering Techniques

This paper looks at the major spam filtering techniques in current use. In looking at methods both success rates and possible problems with each method are explored. Methods discussed include key word filtering, open relay filtering, open proxy filtering, dial-up filtering, non conforming mailing list filtering, cooperative sharing of spam samples, known spam origin filtering Bayesian filtering, Markovian discrimination, gray listing and challenge response.

 

An Application Agnostic Review of Current Spam Filtering Techniques

Network-Based Intrusion Detection Systems in the Small/Midsize Business

This paper reviews the current state of Intrusion Detection Systems (IDS) with a particular emphasis on Network-Based Intrusion Detection systems (NIDS). Many of the topic covered will be applicable for any size business, but issues specific to the Small/Medium Business (SMB) sector are emphasized. The paper covers what an IDS is followed by implementation issues that should be considered when considering an IDS solution.

This paper was originally written in November of 2005. The concepts still hold true today. This article will be a good, no marketing spin, introductory overview of IDS technologies.

 

 

Considerations in Choosing a Firewall

This paper looks at the available firewall technologies in current use. Both advantages and disadvantages for each technique are discussed. Techniques reviewed include packet filtering, proxies, stateful inspection and deep packet inspection. Also discussed are combinations of techniques and defense in depth. Along with these factors other important factors such as management interfaces, hardware choices and build verses buy are discussed.

 

Study: Workers Say Security is Not Their Problem

A recent study revealed that 73% of mobile users said they are not always aware of security threat best practices. To me this seems like a recipe for disaster. I consider security best practices akin to the rules of safe driving. I don’t think we would accept a society in which 73% of users said they are not aware of driving safety regulations.

 

Keeping Your Computer Safer on the Internet


Much like much of what is called "safe sex" would be more accurately called safer sex, I will call this safer computing.

This is in some sort of order but I will not promise order of importance because it is all important.

In Defense of Security Through Obscurity

Over the years anyone who is even vaguely familiar with the security world has had the idea of security through obscurity being worthless drilled into our heads. While I will agree that security through obscurity is exceptionally weak security there is still a place for it in a complete security plan.

After years of hearing the argument that security through obscurity is no security at all it becomes easy to assume that obscurity does not add any level of security to a security plan. As long as obscurity is a part of an overall security plan it should never hurt and will in most circumstances improve your security.

I will give a few examples where security through obscurity can and does help.

Choosing a Home or Small Office Firewall

The intention of the guide is to give a quick easy to read guide to the pros and cons of three different approached to firewalling your home or small office. This is far from a complete guide but it will get you started in the right direction to figure out exactly what you need in order to protect yourself. This particular guide comes out of my desire to provide a quick and easy comparison for a friend who had a small business and was trying to decide what to use for protection. If you are looking for specific reviews of products I recommend the Home PC Firewall Guide.

Implementing Snort IDS Using FreeBSD

This paper explores the elements involved in implementing a Snort IDS and associated software. The considerations and steps taken in building the IDS are discussed, as are the pitfalls and compromises inherent in the implementation discussed in this paper. This paper should be helpful to anyone considering setting up and IDS for the first time regardless of the final software solution that is chosen.

Vouce over IP (VoIP) in the Small and Medium Business

This paper looks at the current state of Voice over IP (VoIP) from a technology manager’s perspective. Specific attention is paid to the small and medium sized business which have up until recently been under represented in the VoIP market. In this paper, both the positive and negative effects of VoIP implementations are considered to help the SMB manager make an educated decision about the appropriateness of VoIP in their own environment.

I finished this paper in November of 2005. The VoIP landscape has changed somewhat in that time but the underlying issues there were true in 2005 still hold true today (August 2007).
Syndicate content