| Analysis Reports |
Statement for the Record of Michael A. Vatis Director of the Institute for Security Technology Studies at Dartmouth College On Cyber Terrorism: The State of U.S. Preparedness Before the House Committee on Government Reform Subcommittee on Government Efficiency, Financial Management and Intergovernmental Relations Wednesday, September 26, 2001 [PDF]
This report analyzes the possibility of cyber attacks against U.S. and allied information infrastructures in response to anticipated military strikes against terrorists and nation-state sponsors. While many have speculated about the possibility for such cyber attacks, this report provides a detailed, fact-based assessment of the situation. It examines recent trends and precedents and sets out in detail the potential types, targets, and sources of cyber attacks that we should be prepared for. It also makes concrete recommendations for protective actions. [PDF]
The Institute for Security Technology Studies (ISTS) at Dartmouth College has synthesized key reports on terrorism and homeland defense in order to provide a synopsis of the main recommendations where consensus was reached on issues of resources, substantive legislation, or research. This report is not meant to replace the work of the underlying recommendations of the experts, but rather to serve as an easy guide to those recommendations in an effort to facilitate the work of those considering immediate action to improve our counterterrorism capabilities. [PDF]
|
The Institute for Security Technology Studies (ISTS) first information monthly briefing for March 2002 focuses primarily on computer viruses/worms. In addition, it also provides an analysis of recently discovered vulnerabilities in the Simple Network Management Protocol (SNMP). [PDF]
This report examines a scenario of a Superworm release into the current Internet environment. A theoretical worm description is provided, and an examination of an actual incident of computer intrusion that indicate conditions that could facilitate the spread of the worm. Two security technologies that could potentially mitigate the spread or damage of the worm are described. The aim of this report is to identify the current model of vulnerability detection, assessment, and response to help network administrators in the development of an adaptable and comprehensive response to address these vulnerabilities.
[PDF]
There has been a clear trend toward a diversification of cyber threats and cyber attack activity in recent years. Hacking and malware techniques have been merged into potentially nasty multi-vector threat weapons that contain a variety of exploits, propagation methods and payloads. This paper examines the diversification of cyber threats in greater detail for the purpose of clarifying the actual dangers posed by these developments and analyzing the possible safeguards that could be implemented to mitigate the risk. [PDF]
This report focuses on cyber attack techniques and defense mechanisms. By giving detailed explanations of several kinds of cyber attacks, these attacks can be understood better and defended against. Covered in this report are the basic concepts of buffer overflows, memory management, Extended Unicode Directory Traversal Vulnerability in Microsoft Internet Information Server (IIS), and how data gathered from intrusion detection systems (IDS) can be analyzed more effectively through the application of Bayesian methods. [PDF]
E-Commerce is a general term for business conducted through the Internet. E-Commerce can involve online banking, selling products and making purchases through Web pages, transferring funds or any other monetary transactions conducted through electronic data interchange (EDI). E-Commerce offers consumers a convenient, fast, easy way to conduct many financial transactions. The bad news is consumers face dangers while conducting business online. A consumer could fall victim to traditional financial crime conducted through the Internet, such as fraud or theft, or consumers could become a victim of a cyber attack. The good news is that informed consumers can do a number of things to protect themselves. This paper discusses steps consumers can take to protect their personal information and assets. [PDF]
<< Main Index | Top | Back to Page 1 - Analysis Reports
