NIST Cybersecurity Site: A range of resources related to NIST programs and documents on cybersecurity.
NIST Computer Security Resource Center: This is an essential resource. Provides access to CSRC projects, news, huge publications library, and an extensive glossary.
Information Security Forum: Many resources, including the Standard of Good Practice. Many of these require that you be a member but there are some useful free resources.
PCI Security Standards Council: Provides free access to PCI-DSS, other standards, and supporting documents.
ITU-T Recommendations: The complete collection of Recommendations, most of which are free.
Center for Internet Security: Provides a collection of controls, best practices, and threat reports.
ISACA: Good collection of documents and other resources.
ENISA: Home page for the EU Agency for Network and Information Security. Excellent collection of documents.
Communications Security Establishment: Home page for the the Government of Canada's national cryptologic agency. A number of useful documents.
Industrial Control Systems Cyber Emergency Response Team: Web site maintained by the U.S. Department of Homeland Security. The site contains a wide range of advisories, fact sheets, and white papers, and is frequently updated..
Cyber Supply Chain Risk Management: NIST project site. A number of documents on the subject.
Cloud Standards Customer Council: NIST project site. A number of documents on the subject.
Cloud Security Alliance: Organization promoting best practices for cloud security implementation. Site contains useful documents and links.
NIST CLoud Computing Program:Useful information, links, and documents.
SABSA: Useful white papers on Enterprise Security Architecture and related topics.
Vmyths: Dedicated to exposing virus hoaxes and dispelling misconceptions about real viruses.
SecureList: Site maintained by commercial antivirus software provider. Good collection of useful information on viruses, hackers, and spam.
DDoS Attacks/Tools: Extensive list of links and documents.
Network Abuse Clearinghouse: Web sites, software, books, and other resources for dealing with spam and other network abuse.
NIST Cryptographic Module Validation Program: Validates vendor offerings using independent accredited laboratories.
CERT Coordination Center: The organization that grew from the computer emergency response team formed by the Defense Advanced Research Projects Agency. Site provides good information on Internet security threats, vulnerabilities, and attack statistics.
United States Computer Emergency Readiness Team: US-CERT is a partnership between the Department of Homeland Security and the public and private sectors, intended to coordinate the response to security threats from the Internet. The site has a good collection of technical papers, and information and alerts on current security issues, vulnerabilities and exploits.
National Council of ISACs: Central site for 20 information sharing and analysis centers. ISACs provide a central resource for gathering information on cyber threats to critical infrastructure and providing two-way sharing of information between the private and public sector.
United Nations Office for Disaster Risk Reduction: Wide range of resources for planning for and dealing with national disasters.
Natural Disaster Risk Management Series: A useful collection of publications an natural disaster risk management.
In recent years, the need for education in computer security and related topics has grown dramatically - and is essential for anyone studying Computer Science or Computer Engineering. This is the only text available to provide integrated, comprehensive, up-to-date coverage of the broad range of topics in this subject. In addition to an extensive pedagogical program, the book provides unparalleled support for both research and modeling projects, giving students a broader perspective.
The intricacies and complexities of modern system and network architecture are already difficult enough to wrap your head around even before you start trying to analyze them in terms of weaknesses and vulnerabilities.
Students studying for a degree in cybersecurity spend a lot of time immersed in the pages of textbooks trying to work these points out. Some of those textbooks prove to be indispensible in the lifelong learning that every dedicated information security professional is committed to.
Stallings has been researching network technology and information security topics since the early 1980s. In these past decades, he has uncovered a lot of information worth sharing and has been a leading thinker and contributor in the field of cybersecurity.
With a B.S. in electrical engineering from Notre Dame and a Ph.D. from M.I.T., Stallings certainly has the academic background for such works, but it is the experience from over 20 years in the I.T. industry that gives bite to his subject matter. No dry, sinecure academic, Stallings got his start working hands-on with networked information systems and continues to consult in the field today.
Many authors and texts restrict themselves to the banner topics, failing to recognize that the devil is in the details when it comes to security. Due to his background in networking architecture, Stallings never appears to fall into that trap, devoting significant room in each book to apparently peripheral topics that have a significant bearing on security operations.
The book devotes a chapter to email security, important in this day and age of spearphishing attacks, and also spends time talking about intrusion detection methodologies and systems for detecting attacks.
With computersciencestudent.com, Stallings maintains a comprehensive online resource that contains errata, additional resources, and dedicated online-only chapters. The resource website offers students the best of both worlds when it comes to computer science texts, allowing Stallings to keep information up-to-date at the breakneck pace of developments in information security, while still resting that information on the solid bedrock of the textbook itself.
The book also puts some effort into rehashing the history of cryptography to give students a solid grounding in how modern techniques evolved, and devotes an entire chapter to teaching some of the difficult mathematical concepts that underlie modern cryptographic theory.
In each of these books, Stallings provides vital information useful to cybersecurity students, even if it is not explicitly classified as security instruction. With the vulnerabilities in most systems existing primarily as exposed and overlooked flaws in otherwise solid designs, the ability to recognize the standards in the field and distinguish mistakes or exploitable holes is a valuable skill for anyone interested in a career in information security.
By bringing the power of computer science to fields such as journalism, education, robotics, and art, Northwestern University computer scientists are exponentially accelerating research and innovation. Watch our video above or learn more at the link below.
The past decade has seen an explosion in the concern for the security of information. This course introduces students to the basic principles and practices of computer and information security. Focus will be on the software, operating system and network security techniques with detailed analysis of real-world examples. Topics include cryptography, authentication, software and operating system security (e.g., buffer overflow), Internet vulnerability (DoS attacks, viruses/worms, etc.), intrusion detection systems, firewalls, VPN, Web and wireless security. Students with good performance in the class will be awarded researchship in the academic year and/or the summer. This course can help satisfy the project course requirement for undergraduates and satisfy the breadth requirement in computer systems for system Ph.D. students.
The purpose of Course F21CN Computer Network Security is to provide a solid understandingof the main issues related to security in modern networked computer systems. This covers underlying concepts and foundations of computer security, basic knowledge about security-relevant decisions in designing IT infrastructures, techniques to secure complex systems and practical skills in managinga range of systems, from personal laptop to large-scale infrastructures.The course structure is designed to provide solid foundations in the first half of the course, and discuss concrete application scenarios in the second half.
Learning Objectives:
Skills imparted:
Coursework 1 is available here (deadline see above).Resources, such as word list etc, can be downloaded following the hyperlinks in the .pdf document.This handout describes the software necessary to perform all tasks which is installed on the Linux lab machines.You can use your own laptop, if you wish. I recommend to use Linux for all pieces of coursework.OpenSSL should come with any major, recent Linux distribution. The only non-standard piece ofsoftware is \textttshed (or any other hex-editor), which you may have to download and install fromsources (that's what I did). Happy hacking!
c80f0f1006