WELCOME

Capella has been designated a National Center of Academic Excellence in Information Assurance Education (CAEIAE) by the National Security Agency and the U.S. Department of Homeland Security. Capella’s information security curriculum meets the NSA Committee on National Security Systems standards 4011, 4013, 4014.

This center provides access to resources, tools, and the latest information regarding information assurance as a way to enhance understanding in this field of study.

CNSS Certification

The NSA’s Information Assurance Courseware Evaluation (IACE) Review Committee has validated that Capella’s information security curriculum meets the Committee on National Security Systems (CNSS) National Standards 4011, 4013, (and 4014 coming). Learn what this means to a Capella learner.

ARCHIVES

Out of Band Password Administration

From Mary Brown | October 21st, 2009

Many of us who work in information security have long bemoaned the shortcomings of using passwords as an authentication factor.  One of the first alternatives to passwords in the form of two factor authentication was the token that would generate a one time password solution.  An interesting alternative to this token solution is an ‘out of band’ solution that involves pushing a password to the mobile phone of the user.

Are any of you currently using these or any of the out of band solutions to authenticate users?  Share your experiences/thoughts by posting a comment.

For more information read this white paper.  Also, check out phonefactor.com and authentify.com.



 


 

 

Tags: , , , , , ,

 

Microsoft SMB fail 2.0

From Rodney Visser | September 15th, 2009

Recently, another Windows os vulnerability has surfaced pointed at ports 139 and 445. It was initially released as a denial of service attack, but could also allow system level remote code execution. The strange thing about this particular exploit for me, is that this issue was fixed on Windows 7 build 7130, but as of today there is still no fix for Vista or Server 2008.

In the time it is taking them to address this issue there is already working exploit code in the ever popular MetaSploit framework and as an added bonus it has the ability to do reverse HTTP tunneling on port 80. This means that you could hit an exploited system and the firewall will literally mean nothing.

 

Tags: ,

 

Who to Trust?

From Mary Brown | August 20th, 2009

Brad Stone, a reporter with the New York Times, reports on the indictment of what is believed to be the largest single incident of credit card information theft.  I say believed to be, because it appears that we really do not know what is happening out on the Internet until it is publicized.  How many of you have received a new credit card in the mail without adequate explanation as to what happened to the old one that created the need for a replacement in the first place?    READ ON

Tags: , , ,

 

Invisible Firewalls?

From Rodney Visser | August 18th, 2009

 When adding a traditional hardware based firewall to a network, major network based surgery is needed a majority of the time.  The potential for configuration problems with both internal clients and the router/proxy are increased.  There is also overhead that goes into processing each packet or session for the firewall, making it difficult to come to an informed decision. 

When looking though the eyes of an attacker, only minimal investigation and enumeration is needed to identify a device that is acting as a firewall. Its rule-set or “protection” features can be realized. READ ON

Tags: , , , ,

 

Ethics of Communicating Vulnerabilities

From Mary Brown | August 17th, 2009

Kim Zetter, at wired.com, reports on the ongoing tension between RSA and an information security blogger, Scott Jarkoff, who reported on what appears to be a flaw in the security architecture in the Web site of an RSA client.  The tension has generated a renewed discussion on how vulnerabilities should be communicated when they are discovered.  

Why do you think that RSA is pushing so hard, when doing so has created more chatter and made more people aware of this vulnerability as a result of their actions?

 


Tags: , , ,

 

Distributed Security Framework

From Mary Brown | July 23rd, 2009

A 2005 paper on a distributed security framework by Susan Brenner and Leo Clarke has recently been getting a lot of attention on the blogs.  Both Bruce Schneier and Michael Kassner have recently commented on the efficacy of this approach to information security that professes to take a more proactive approach rather than the typical reactive stance that is too common in the security industry.  Included  in this paper is discussion about international cybercrime treaties, the use of police recruiting of civilians in fighting cybercrime.  The authors also suggest  the idea that it would be illegal to gain access to the Internet except through a licensed ISP.   

What do you think about this proposed framework for information security?  Why do you think it has only now gained the degree of attention that it seems to be recently experiencing? Share your thoughts.

 Check out the paper and link to Kassner blog and to Schneier blog here.

 

 

 

Tags: , , , , , , ,

 

Categories

RESOURCES

NEWS FEEDS

META

CAPELLA CONNECTION

Capella University offers several degree programs which specialize in the information assurance and security field. Visit one of the links below for more information.

To learn more about Capella, please visit http://www.capella.edu or call 1.888.CAPELLA, option 2, to speak to an enrollment counselor.

Capella University