Network Security and Applications

Recent resources tagged with Network Security and Applications.

Security Task Force 2008–2009 Strategic Plan: Safeguarding Our IT Assets, Protecting Our Community’s Privacy

Added by the EDUCAUSE Librarian
Title:Security Task Force 2008–2009 Strategic Plan: Safeguarding Our IT Assets, Protecting Our Community’s Privacy (ID: CSD5494)
Origin:Contributed by the Security Task Force (09/03/2008)
Type:Plans and Guidelines
Abstract:

The EDUCAUSE/Internet2 Computer and Network Security Task Force (STF) provides a focal point for the academic community to join together to strengthen the ability of the higher education sector to respond to growing threats to information security and to protect the privacy of our community members. This strategic plan is intended to set forth a vision for the higher education community and provide a concise roadmap to guide the efforts of the STF. This roadmap emphasizes continuous and evolutionary community investment in converting our understanding of risks and issues into solutions based on effective practices, as well as the urgent need to build the national capability across the higher education sector to respond quickly and effectively as a community to new threats and vulnerabilities.

View this resource:

9 Reasons Why Campus Police and IT Should Start Talking

Added by the EDUCAUSE Librarian
Title:9 Reasons Why Campus Police and IT Should Start Talking (ID: CSD5397)
Source:Campus Safety Magazine
Origin:Contributed by Organizations or Campuses (10/26/2006)
Type:Articles, Papers, and Reports
Abstract:

When discussing video surveillance with campus police and IT departments at various schools and universities, I frequently hear an undercurrent of distrust between the two groups.

View this resource:

2008 Data Breach Investigations Report

Added by the EDUCAUSE Librarian
Title:2008 Data Breach Investigations Report (ID: CSD5395)
Author(s):Wade H. Baker (Verizon Business), C D. Hylender (Verizon Business), and J A. Valentine (Verizon Business)
Source:Verizon Business
Origin:Contributed by Organizations or Campuses (07/01/2008)
Type:Articles, Papers, and Reports
Abstract:

The 2008 Data Breach Investigations Report draws from over 500 forensic engagements handled by the Verizon Business Investigative Response team over a four-year period. Tens of thousands of data points weave together the stories and statistics from compromise victims around the world. This report seeks to answer the following questions;

  • Who is behind data breaches?
  • How do breaches occur?
  • What commonalities exist?
  • Where should mitigation efforts be focused?
View this resource:

The Data Center Within a Data Center: Building a Secure Environment for Compliance

Added by the EDUCAUSE Librarian
Title:The Data Center Within a Data Center: Building a Secure Environment for Compliance (ID: SEC08074)
Author(s):David Seidl (University of Notre Dame)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

PCI compliance can be daunting, particularly in a university network environment. Notre Dame chose a data center within a data center approach to simplify compliance and minimize integration issues. This project includes implementing the data center, a virtual network to support point-of-sale devices, and related operational procedures.

View this resource:

Software Assurance: An Overview of Current Industry Best Practices

Added by the EDUCAUSE Librarian
Title:Software Assurance: An Overview of Current Industry Best Practices (ID: CSD5389)
Source:SAFECode
Origin:Contributed by Organizations or Campuses (02/21/2008)
Type:Articles, Papers, and Reports
Abstract:

This report outlines the secure development methods and integrity controls currently used by SAFECode members to deliver high-assurance systems to government and commercial customers.

View this resource:

Community Updates

Added by the EDUCAUSE Librarian
Title:Community Updates (ID: CYB08005)
Author(s):Mine Altunay (Fermi National Accelerator Laboratory), Kenneth J. Klingenstein (University of Colorado at Boulder), James A. Marsteller (Pittsburgh Supercomputing Center), Doug Pearson (Indiana University), John J. Suess (University of Maryland, Baltimore County), and Denise Sumikawa (LLNL)
Origin:Presented at Cybersecurity Summit (05/07/2008)
Type:Presentations/Speeches
Abstract:

Community updates from EDUCAUSE/Internet2 Security Task Force, InCommon, OpenScience Grid, Research and Education Networking Information Sharing and Analysis Center (REN-ISAC), TeraGrid, and the U.S. Department of Energy Computer Incident Advisory Capability.

View this resource:

Security in Virtual Organizations

Added by the EDUCAUSE Librarian
Title:Security in Virtual Organizations (ID: CYB08018)
Author(s):James Basney (University of Illinois at Urbana-Champaign) and Margaret Murray (University of Texas at Austin)
Origin:Presented at Cybersecurity Summit (05/07/2008)
Type:Presentations/Speeches
Abstract:

Science and engineering projects are creating "virtual organizations" with participants from around the world. The rules and conventions of virtual organizations and their means of achieving success are evolving every day. In this session, we will explore the security challenges of virtual organizations. Grid security technologies and policy will be discussed to develop guidelines for strengthening security in virtual organizations.

View this resource:

Holistic Approaches to Trustworthiness, Security, and Privacy

Added by the EDUCAUSE Librarian
Title:Holistic Approaches to Trustworthiness, Security, and Privacy (ID: CYB08003)
Author(s):Peter G. Neumann (SRI International)
Origin:Presented at Cybersecurity Summit (05/07/2008)
Type:Presentations/Speeches
Abstract:

System trustworthiness is needed for security, reliability, survivability, safety, and for many application areas such as critical infrastructures, robust networking, and high-integrity elections. Trustworthiness ultimately requires many changes in the way systems are developed today. Being respectful of privacy needs requires further care. This talk considers a variety of approaches that can enhance system trustworthiness, sensible system development practices, and a system-oriented view toward achieving the desired changes.

View this resource:

Newspeak: A Paradigm for Architectural Security

Added by the EDUCAUSE Librarian
Title:Newspeak: A Paradigm for Architectural Security (ID: CYB08004)
Author(s):Steve M. Bellovin (Columbia University)
Origin:Presented at Cybersecurity Summit (05/07/2008)
Type:Presentations/Speeches
Abstract:

Most computer security problems arise from buggy code. It seems clear that writing large, bug-free programs is and will remain beyond our abilities. We propose a different goal: protecting what really matters. On e-commerce sites, the web server is primarily a front end for a database. Protecting the latter is much more important than protecting the former. Doing this properly requires a different approach to overall system architecture.

View this resource:

MPLS for the University/Enterprise Network

Added by the EDUCAUSE Librarian
Title:MPLS for the University/Enterprise Network (ID: SER08072)
Author(s):Jonathan Thyer (University of North Carolina at Greensboro)
Origin:Presented at Southeast Regional Conferences (06/02/2008)
Type:Presentations/Speeches
Abstract:

This presentation will outline the planning and implementation of an MPLS-based enterprise network at UNCG. It will cover some background, requirements and goals, and proposed and implemented network architecture. Migration strategies employed will also be addressed. Additionally, an overview of the subset of MPLS technologies that are suitable for the enterprise will be covered including MPLS VPN V4, Label Distribution Protocol (LDP), OSPF, and BGP.

View this resource: