Industry Library

Provided by: Core Competence & Mactivity, Inc
TISC2002

The Internet Security Conference 2002


Top 10 Reasons to Attend the TISC 2002 Security Conference

  Incident Response & Advisory Centers

Cert(sm) Coordination Center
CERT studies Internet security vulnerabilities, provides incident response services, publishes security alerts, researches security and survivability, and develops information to help you improve security at your site.


Center for Education and Research in Information Assurance and Integrity

CERIAS provides innovation and leadership in technology for the protection of information and information resources, and in the development and enhancement of expertise in information assurance and security.

Common Vulnerabilities & Exposures Web Page
A dictionary for vulnerabilities and other information security exposures - CVE aims to standardize the names for all publicly known vulnerabilities and security exposures. Hosted by Mitre.

Computer Incident Advisory Capability
CIAC provides computer security services to employees and contractors of the DOE, and serves as a primary resource for anyone with an interest in security issues.

COAST Homepage
COAST (Computer Operations, Audit, and Security Technology) is a multiple project, multiple investigator laboratory in computer security research in the Computer Science Department at Purdue University. COAST publishes a newsletter and hosts a calendar of security events.

Defense Information Systems Agency Center for Automated System Security Incident Support Team (ASSIST, for DoD sites)
The INFOSEC Incident Response Support to the Defense Information Infrastructure (DII) Community in Support of Information Assurance.

Federal Bureau of Investigation National Infrastructure Protection Center
NIPC's mission is to serve as the U.S. government's focal point for threat assessment, warning, investigation, and response for threats or attacks against our critical infrastructures. These include telecommunications, energy, banking and finance, water systems, government operations, and emergency services.

Federal Computer Incident Response Capability (FedCIRC)
FedCIRC offers the Federal civilian community assistance and guidance in handling computer security related incidents.

Forum of Incident Response and Security Teams (FIRST)
FIRST fosters cooperation and coordination in incident prevention among a variety of computer security incident response teams from government, commercial, and academic organizations to prompt rapid reaction to incidents, and to promote information sharing among members and the community at large.

Hacker Emergency Response Team
HERT is a pool of hackers and security consultants from many different
countries who assist individuals and organizations in locating and acquiring coders, sponsors, and funding for computer security projects.

The Information Warfare Site
The Information Warfare Site is an online resource that aims to stimulate debate about a range of subjects from information security to information operations and e-commerce. It is the aim of the site to develop a special emphasis on Europe.

The National Security Association (NSA)
The National Security Association (NSA) provides a series of Security Recommendation Guides

The WildList Organization
WildList is a premier source of information on viruses found spreading In the Wild.

Virtual Private Network Consortium VPNC
Virtual Private Network Consortium VPNC is the international trade association for manufacturers in the VPN market.

---back to top---

  Portals, Info Sites & Publications

2600 offers security related news and subscriptions to this well-known magazine.


The Beginner's Cryptography Page offers an introduction to cryptographic techniques and provides a wealth of links to other online cryptography resources.

Crypto-gram, a monthly email newsletter on cryptography from Bruce Schneier, discusses current issues in cryptography.

Fyodor's Good Reading List is an intersting and eclectic collection of security related resources.

The Hacker News Network provides daily updated information security news and commentary.

InfoSysSec is a comprehensive computer and network security resource on the Internet for Information System Security Professionals--and they maintain the news crawler at the right...

The Internet Protocol Journal, published by Cisco Systems. serves as an informational and educational resource for engineering professionals involved in the design, development, and operation of public and private internets and intranets.

InteractiveInfoSec is a very good place for novices to security. The "see a hacker", "Be a Hacker" and "Stop a Hacker" are very good instructionals for those who want to Know the Enemy (thank you, Lance Spitzner).

The Journal of Internet Security provides a DeLiberation Extranet to inform professionals and support discussions of electronic banking and commerce issues.

NewOrder, a resource for people to help avoid being hacked, security and exploiting related files and links.

Rik Farrow's Network Defense columns, from Network Magazines, are archived here.

Packet Storm claims to be the largest and most up to date library of information security information in the world. Packet Storm is a security resource that provides the mechanism for both the underground and the corporate communities to converge and direct their efforts towards sharing security information.

TechTarget's SearchSecurity.com offers a comprehensive Security specific search engine.

Phrack is an unusual, unique, and remarkable collection of security research, articles, and, well lots of kewl stuff.

SecuriTeam.com is a security news web site containing all the newest security information from various mailing lists, hacker channels and our own tools and knowledge.

Windows & .NET Magazine's Security Administrator section of discusses NT/W2K/XP security issues, tips, and new products. It's a good source for learning the latest NT security breaches and corresponding hot fixes.

SecurityPortal.com summarizes breaking security news and provides a launch point for Security Alerts, Products, Tools and other security resources. SecurityPortal also operates many informative mailgroups, including PEN-TEST and BUGTRAQ.

SecurityFocus.com is designed to facilitate discussion on security related topics, create security awareness, and to provide the Internet's largest and most comprehensive database of security knowledge and resources to the public. offersThis portal has an oustanding collection of free tools.

SecurityNews.org professes to provide Security News for Security Professionals. In addition to news stories, you'll find links to other security related material.

TALISKER'S NETWORK SECURITY TOOLS PAGE offers a plethora of security tools and software, a MUST SEE!

TechnoTronic is a hard-core security information site. Find postings of recent exploits and newly released security patches and hot fixes from all major OS and security vendors. You'll also find programs to test vulnerabilities, scan, and audit systems and networks. The ftp archives there are extensive.

The TruSecure white paper library offers a variety of technical, strategic, and non-technical papers on information security.

VPNlabs is an open community for researching, reviewing, and discussing Virtual Private Networks.

  Security (Overview, General, Opinion)


A Computer and Network Security Primer
by Fred Avolio
A Multi-Dimensional Approach to Internet Security by Fred Avolio
A Network Perimeter with Secure External Access by Fred Avolio and Marcus Ranum
Are You Prepared In The Event Of A Disaster? byMark T. Edmead
Best Practices in Network Security by Fred Avolio
Defining and Controlling Remote Access Risks by Ron Hale
Enough Already, Time to get Serious About Hacking by Marcus Ranum
Guarding the Crown Jewels - An Overview of Computer & Internet Security by Curt Wilson
Hammering Out a Secure Framework by Mike Fratto
Have a Cocktail: Computer Security Today by Marcus Ranum
Holy Intruders!: IP-Based Security Auditing Tools by Greg Shipley
Managing Electronic Records and Evidence by Jeffrey H. Matsuura
Managing security and complexity on a tight release schedule and other high-level ramblings by Marcus J. Ranum
Network Security Auditing by Joel Scambray
Social Engineering: The Threat and The Solution byChris Tobkin
Vulnerability Assessment Survey at SecurityFocus.com

_______________________________________


Information Risk Assessment: Practices of Leading Organizations United States General Accounting Office
Network 10: The next Y2K problem? by Marcus Ranum
Network Security Auditing: The Key to network security by Joel Scambray and Stuart McClure
Network Address Translation: Hiding in Plain Sight by Mike Fratto
Protecting Network Infrastructure at the Protocol Level by Curt Wilson
Security Basics Forum at SecurityFocus.com
Security on Internet Time by Marcus Ranum
Selling Security Hype by Marcus Ranum
Threats, Vulnerabilities and Real-World Responses: The Foundations of the TruSecure Process by M. E. Kabay
What I Worry About by Marcus J. Ranum

---back to top---

  Authentication, PKI, Cryptography


Acquiring PKI
by Tom Austin
Certificate Authorities: How Valuable Are They?
Conventional Public Key Infrastructure: An Artefact Ill-Fitted to the Needs of the Information Society by Roger Clarke
CRYPTO LINKS - Bibliographies at Counterpane Systems
Cryptography, an online UIC graduate course by D.J. Bernstein
Cryptography and Information Security Group Research Project: A Simple Distributed Security Infrastructure (SDSI) by Ronald L. Rivest and Butler Lampson
Cryptography & The Internet by Steve Bellovin
Deploying Crypto, What Are You Waiting For? by Fredrick M. Avolio
New Zealand Crypto Archive
Establishing Identity Without Certification Authorities by C.Ellison
Index of Cryptography Papers Available Online at Counterpane Systems
Peter Gutmann's godzilla crypto tutorial
PKI tames network security by Stuart McClure
Privacy Implications of Digital Signatures by Roger Clarke
Public-Key Infrastructure (X.509) (pkix) IETF
Risks of PKI: Electronic Commerce by C. Ellison and B. Schneier
Ten Risks of PKI: What You're Not Being Told About Public Key Infrastructure by C. Ellison and B. Schneier
The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption H. Abelson, R. Anderson, S. Bellovin, et al.
We Need a Public Key Infrastructure by Lisa Phifer

_______________________________________


Biometrics: Threat or Menace? by Stephen Kent
Bridging The Business-to-Business Authentication Gap by Christy Hudgins-Bonafield
Buyer's Guide: Biometrically Speaking by Fred Avolio
Choosing Strong Passwords by Eric Shultze
Identity Confirmed by Fred Avolio
Smart Cards and Biometrics: Your Key to PKI by D. Corcoran, D. Sims, and B. Hillhouse
The one and only you by Howard Millman
Why I Love Biometrics by Dorothy Denning
WWW Authentication by Kurt Seifried

---back to top---

  Intrusion Detection, Sniffing, & Anti-Hacking


A Taxonomy of Internet Attacks maintained by Marcus Ranum
Abnormal IP Packets by Karen Kent Frederick
Advanced Host Detection: Techniques To Validate Host-Connectivity by dethy
An Evening With Berferd, in which a Hacker is Lured, Endured, and Studied by Bill Cheswick, a classic
Automated NT Vulnerability Testing by Dave Piscitello
Benchmarking IDS by Marcus Ranum
Carnivore and Open Source Software by Steve Bellovin
Coverage in ID Systems by Marcus Ranum
FAQ: Hacking Lexicon by Robert Graham
FAQ: Network Intrusion Detection Systems by Robert Graham
Honeypots: Sweet Idea, Sticky Business by Dave Piscitello
How Web Spoofing Works by Brad Johnson
ICMP Use in Scanning by Orf Arkin
Identifying ICMP Hackery Tools Used In The Wild Today by Orf Arkin
Identifying Firewalls by David Hyams
Intrusion Detection: Challenges and Myths by Marcus J. Ranum
Implementing A Generalized Tool For Network Monitoring by Marcus J. Ranum
Internet Forensics: Common Tools by Bill Hancock
Intrusion Detection Joins Net Security Arsenal by Fred Avolio and David Piscitello
Intrusion Detection Provides A Pound Of Prevention by Mark Abene Gerald L. Kovacich, and Steven Lutz
Intrusion Detection Systems: Suspicious Finds by David Newman
Intrusion Crack Down by Ron Hale
ISS X-Force White Papers
Know Your Enemy:The Tools and Methodologies of the Script Kiddie by Lance Spitzner
Know Your Enemy: Tracking their moves by Lance Spitzner
Know Your Enemy: They Gain Root by Lance Spitzner
Know Your Enemy: A Forensic Analysis by the Honeynet Project
Know Your Enemy: Motives by the Honeynet Project
Know Your Enemy: Worms at War by the Honeynet Project
Know Your Enemy: Passive Fingerprinting by the Honeynet Project
Know Your Enemy: Honeynets by the Honeynet Project
Know Youre Enemy: Statistics by the Honeynet Project
Network Cat and Mouse Nomad Mobile Research Center
Network Forensics: Network Traffic Monitoring by Marcus J. Ranum
Network Insecurity with Switches by Aaron D. Turner
Network Intrusion Detection Signatures (Part 1) by Karen Kent Frederick
Network Intrusion Detection Signatures (Part 2) by Karen Kent Frederick
NFR eases intrusion detection by David Piscitello
Passive Fingerprinting by Lance Spitzner
Primer on Predictive Analysis by J.L. Stutzman
.RAIN.FOREST.PUPPY.
Remote OS detection via TCP/IP Stack FingerPrinting by Fyodor
Send ICMP Nasty Garbage (SING) a Source Forge project
Snort - Lightweight Intrusion Detection for Networks by Martin Roesch
Secure Strategies-Penetration Testing Exposed by George Kurtz and Chris Prosise
Sniffing (network wiretap, sniffer) FAQ by Robert Graham
Studying Normal Traffic (Part 1) by Karen Kent Frederick
Studying Normal Traffic: FTP Traffic (Part 2) by Karen Kent Frederick
Studying Normal Traffic: TCP Headers (Part 3) by Karen Kent Frederick
Tapping, Tapping On My Network Door by M. and S. Bellovin
There Be Dragons by Steve Bellovin a classic
To Build A Honeypot by Lance Spitzner
Tracking intruders by Rik Farrow
Triangulation in Attack Analysis (Part I, Part II) by J.L. Stutzman
Wiretapping the Net by Steve Bellovin
X - Remote ICMP Based OS Fingerprinting Techniques by Orf Arkin
Your First Penetration Test by Dave Piscitello
Zen and the Art of Breaking Security (Part I) by Razvan Peteanu
Zen and the Art of Breaking Security (Part II) by Razvan Peteanu

_______________________________________


A TCP/UDP Ports database in an /etc/services format by Kurt Seifried
ICMP Ports List by Kurt Seifried
Interaction InfoSec Chris Tobkin's pen-test, hacking & ID page
Ports Used by Trojans Simovitz Consulting
The Internet Ports Database
Tripwire Literature Room

---back to top---

  Virtual Private Networking, Secure Remote Access

Virtual Private Networks (Primer)
by Lee Chae
Dial VPNs: Revenue Opportunity or Headache? by Lisa Phifer
Firewalls and Virtual Private Networks by Fred Avolio
How to stay in front of VPN management by Tim Greene
Multi-Vendor VPNs: The Quest for Interoperability by Lisa Phifer
Protocols for Remote Access VPN Services by Lisa Phifer
The Core Competence VPN FAQ Page
The Two Sides Of NAT by Pete Loshin
The Trouble with NAT by Lisa Phifer
Twelve Steps to Secure Remote Access Using IPsec by Lisa Phifer & Dave Piscitello
Unlocking Virtual Private Networks by Mike Fratto
VPN Client Administration by Lisa Phifer
VPN Insider an archive of VPN articles, product reviews
VPN Services: The Real Deal on Costs by Daniel M. Gasparro
What is a VPN? by Dennis Ferguson
VPNs: Virtually Anything? by Lisa Phifer
VPNs: Low-Cost Solution For Remote Dial-Up Access by Lisa Phifer and David Piscitello

_______________________________________

SSH: From Secure Administration to Virtual Private Networking by Lisa Phifer
Sealing The Pipes by Pete Loshin

_______________________________________


A cryptographic evaluation of IPsec
by Counterpane
Explaining the Gap between Specification and Actual Performance for IPsec VPN Systems Ray Savarda and Matt Karash
IP Security and NAT: Oil and Water? by Lisa Phifer
Making IPsec Work for You by Mike Fratto
Pushing IPsec Through NAT by Lisa Phifer
Realm-Specific IP for VPNs and Beyond by Lisa Phifer
Secure Remote Access with IPsec Lisa Phifer and David Piscitello
Slipping NAT past IPsec by Lisa Phifer
Stretching 'VPN' to Fit Web-Based Intranets? by Lisa Phifer
Why can't IPsec and NAT Just Get Along? by Mike Fratto


_______________________________________


Analysis of the SSL 3.0 Protocol
by D. Wagner and Bruce Schneier
Getting started with SSH by Kimmo Suominen
Secure Sockets Layer, at Netscape
Secure Sockets Layer by Brian Lashley and Andrzej Tarski
SSL and S-HTTP (Primer) by Anita Karve
Ssh (Secure Shell) FAQ - Frequently asked questions

_______________________________________


Windows 2000: An Early Security Perspective James Michael Stewart and Ed Tittel
Windows 2000's VPN-Related Security Issues by Lisa Phifer
Windows 2000 Vulnerabilities by Phil Cox

---back to top---

  Firewalls


Access control: Beyond Firewalls by Stephen Reed
Application Gateways and Stateful Inspection by Fred Avolio
Beyond Firewalls
by Stephen Reed
Building your firewall by Carole Fennelly (3 parts)
CSI Firewall Product Search Center maintained by Rik Farrow
Distributed, Host-Resident Firewalls by Avi Fogel
Firewall Configuration Problems by Rik Farrow
Firewalling Your Personal Perimeter by David Willis
Firewalls: Common Configuration Problems by Kurt Seifried
Firewalls: Don't Get Burned by David Newman, Helen Holzbaur, and Kathleen Bishop
Firewalls Performance Measurement Project index maintained by Marcus Ranum
Firewalls Overview by Kurt Seifried
Firewalls: Evolve or Die by Kurt Seifried
Fortifying your Firewall by Peter Morrissey
How NOT to build a firewall by Richard Power (Marcus Ranum interview)
How to Perform Effective Firewall Testing by E. Eugene Schultz
How to Pick a Firewall with the Right Stuff by Rik Farrow excellent, eventual classic
How to Pick an Internet Firewall by Marcus Ranum
Internet Firewalls:Frequently Asked Questions maintained by Marcus Ranum and Matt Curtin
Interdepartmental Firewalls: Where to Put Them (and Why) by David Piscitello
NIST Guidelines on Firewalls and Firewall Policy
NT Firewalls: Tough Enough by David Newman, Helen Holzbaur, and Michael Carter
On the Topic of Firewall Testing
by Marcus Ranum
Personal Firewalls by Mandy Andress
The Internet Firewalls FAQ by Marcus Ranum
The Distributed Firewalls Web Site maintained by Network-1
The Design of a Secure Internet Gateway by W. Cheswick
The Ultimate Firewall by Marcus Ranum
Thinking About Firewalls V2.0: Beyond Perimeter Security by Marcus Ranum, a classic
How Computer Security Works: Firewalls by W. Cheswick and S. Bellovin
Implementing a Distributed Firewall by Steve Bellovin, S. Ioannidis, A. Keromytis, and J. Smith
The IETF Firewall Working Group
The ULTIMATELY Secure Firewall by Marcus Ranum
The Failure of Firewalls - A Critical Look at an Information Security Panacea by Rob Thomas
Unverified Fields - A Problem with Firewalls & Firewall Technology by Ofir Arkin

---back to top---

 

  Application Stream Hacking & Security


A Semantic Attack on URLs
by Bruce Schneier
Advanced SQL Injection by Chris Anley
Creating Arbitrary Shellcode in Unicode Expanded Strings by Chris Anley
Exploiting and Protecting Oracle by Pete Finnigan
Exploiting and Protecting Oracle (TISC Insight) by Pete Finnigan
External Operating System Commands: Backdoor or feature? Hacking with SAP R/3 by Stefan Hoelzner
HTML Form Protocol Attack by Jochen Topf
URL, URL, Little Do We Know Thee by Razvan Peteanu
Hackproofing Oracle Application Server by David Litchfield
Hackproofing Lotus Domino Web Server by david Litchfield
Improving Apache by Gary Bahadur & Mike Shema
Introduction to LDAP Security by Sacha Faust
Polymorphic Shellcodes vs. Application IDSs by Fermin Serna
Securing Oracle by Ken Ihrer (8.1.6)
Securing the Apache Web Server by Rik Farrow

---back to top---

 

  Secure Electronic Mail


Corporate.Net Secure Electronic-Mail: Return To Sender?
by David Willis
E-mail Security: Signed Sealed & Delivered by Fred Avolio and David Piscitello
E-mail Security: Why Don't We Bother? by Fred Avolio
eMailman Security pages
Encryption Essentials: A PGP Quick-Start Guide
MailGuardian Delivers Transparent Security to Users by Fred Avolio and David Piscitello
Tom McCune's page for Pretty Good Privacy
Revealing Email Headers by Rik Farrow
Tracing Electronic Mail by Fred Avolio
WSS Puts Its Stamp On E-Mail Security by Gregory Yerxa

---back to top---

  Security and the DNS


BIND news and DNS alternatives
by Jeremy Reed
DNS may be giving away your secrets by Rik Farrow
MaraDNS: Working Towards a More Secure DNS by Sam Trenholme
Secure BIND Template Version 2.1 by Rob Thomas
Securing an Internet Name Server by Cricket Liu
The DNS Security Extensions by Cricket Liu

---back to top---

 

  E-Commerce, Privacy


Electronic Commerce and Security
by Marcus Ranum
PAYMENT PROTOCOLS: CACHE ON DEMAND by Gary Kessler and N. Todd Pritsky
Privacy in the Digital Age Pages of The New York Times populace view of privacy concerns
Questions to Ask Before Going Online by Marcus Ranum
Ready, SET, wait... by Kristi Essick, Torsten Busse, and Rob Guth
The Nuts and Bolts of Business-to-Business E-Commerce by Brian Walsh
Your E-commerce Site: Build, Buy or Rent? by Brian Walsh

---back to top---

 

  Broadband Local Access & Security


CLECs Should Be Proactive In Security
by David M. Piscitello
EtherLECs and Security by David M. Piscitello
Extending the Perimeter: Protecting the Telecommuter and the Road Warrior (Part 1) by Fred Avolio
Extending the Perimeter: Protecting the Telecommuter and the Road Warrior (Part 2) by Fred Avolio
Firewalls & DSL by David M. Piscitello
Host and Network Security in the Internet Age: DSL, @Home, ISDN, etc. by David Dittrich
Residential Broadband Access and the Teleworker: Security Considerations for the IT Manager by David Piscitello
Security and xDSL, 4 part series by David Piscitello
Securing Residential Broadband Connections:The Personal Firewall Approach by Lisa Phifer
Why Metro Area EtherLECs Should (Still) Worry about DDOS Attacks
David M. Piscitello

---back to top---

 

  Client, Desktop and Stored File Security, Security Cards


2 in 1 PC keeps secure separation
by Dave Piscitello
Hostile mobile applets cause a stir by Matthew Nelson
KerbNet Takes A Bite Out Of Hackers by Dan Backman
PC Disk Encryption: A Lesson Learned and Recommendations by Fredrick M. Avolio
SecureDesktop Protects Your PC Like A Vault by Christopher Smith
Stopping Intruders at the Wall: Norton Anti-Virus for Firewalls by Lisa Phifer
Stored File Encryption: Boiled Eggs And Scrambled Data by Phil Carden

---back to top---

 

  Security & Programming


Best Practices for Secure Development
by Razvan Peteanu
Buffer Overruns and burglar alarms by Marcus Ranum
RATS (Rough Auditing Tool for Security), a security auditing utility for C, C++, Python, Perl and PHP code. RATS scans source code, finding potentially dangerous function calls.
hhp, website containing information, source code, and tutorials on exploits and programming
The Importance of Bug Testing by dethy
The Secure Programming Standards Methodology Manual by Victor A. Rodriguez
The Open Source Security Testing Methodology Manual by Pete Herzog

---back to top---

 

  Operating System Security


Another Paper on Linux Security
by Bronc Buster
Basic Steps in Forensic Analysis of Unix Systems by Dave Dittrich
Linux firewalling with ipchains by Vincent Danen
Making UNIX Servers More Secure by Rik Farrow
Secure interprocess communication by D. J. Bernstein
Security Enhanced Linux from the NSA
Tuning Solaris for FireWall-1 by Rob Thomas
Unix Computer Security Checklist

UNIX IP Stack Tuning Guide by Rob Thomas
UNIX Security by guidob

_______________________________________


A Complete List of Windows Event Identifiers
A Starting guide to armoring NT by Lance Spitzner
Hardening EFS by Roberta Bragg
NTBug Traq
NTSecurity.Net
NTToolbox.com
Microsoft Security Bulletins at Microsoft TechNet
searchNT.com
The Microsoft Security Advisor
Windows NT Passwords by Bill Wall
Windows NT/2000 Tips, Tricks, Registry Hacks and more at Microsoft TechNet
Windows 2000 Magazine Online at Microsoft TechNet
Windows 2000 Vulnerabilities by Phil Cox

---back to top---

 

  Third Party Host Scanners


FutureSoft Free External Security Scan
Hacker Whacker Free Security Scan
SecuritySpace Desktop Security Audit
SeigeSoft's Privacy Analysis of your Internet Connection
Shavlik Technologies QuickInspector for the Web
WebTrends Online Security Analyzer
Steve Gibson's Shields Up!
Steve Gibson's LeakTest
SyGate Online Security Scan
Symantec Security Check

---back to top---

 

  Denial of Service (DOS) Attacks


A stacheldraht agent scanner (C source code) by Dave Dittrich, Marcus Ranum, and others
A trinoo/TFN/stacheldraht agent scanner (C source code, BETA)
by Dave Dittrich, Marcus Ranum, George Weaver, David Brumley, and others
AntiCode
AntiOnline

Distributed Denial of Service Attacks by Rik Farrow
Distributed Denial of Service (DDoS) Attacks/tools by David Dittrich
Egress Filtering BY Mark T. Edmead
Egress Routing
Future denial of service attacks by Kurt Seifried
Hacker News Network
How to Spot Source Address Spoofing by Rik Farrow
Information on network ingress filtering, RFC 2267
Quality of Service for Denial of Service Attack Prevention
by Steve Kohalmi, Randy Charland
Network Defense Richard Power & Rik Farrow's archive of Network Magazine columns
Some TCP/IP Vulnerabilities: Weaknesses, attack tools, defenses by David Dittrich
SYN cookies by D. J. Bernstein
The "stacheldraht" distributed denial of service attack tool by David Dittrich
The "Tribe Flood Network" distributed denial of service attack tool by David Dittrich
The DoS Project's "trinoo" distributed denial of service attack tool
by David Dittrich

---back to top---

 

Copyright © 1996 - 2001 NetConnX Technologies