|
|
||
|
|
Handler's Diary Provide free analysis and warning service to thousands of Internet users and organizations, and is actively working with Internet Service Providers to fight back against the most malicious attackers. |
|
|
|
Daily Top 10 Listing of ports being scanned, source IPs scanning a particular target port and recommended block list |
|
|
|
||
|
|
SecTools.Org
Voted Top 100 Network Security Tools |
|
|
|
InSecure.Org
Nmap Free Security Scanner, Tools & Hacking Resources |
|
|
|
||
|
|
K-Otik (French Security Survey) | |
|
|
||
|
|
System Backup, Bare-Metal Recovery & Migration
Symantec LiveState Recovery combines the speed and reliability of disk-based, bare-metal Windows system recovery with hardware-independent restoration and lights-out operation |
|
|
|
Continuous
Data Protection
Symantec Backup Exec 10d provides comprehensive, cost-effective, and certified backup and recovery - including continuous data protection with multiple versions |
|
|
|
||
|
|
Symantec Virus Protection Interactive Guide This guide will help you to learn more about Symantec's latest Virus Protection Solutions |
|
|
|
Cryptographic
Standards and Applications Focus is on developing cryptographic methods for protecting the integrity, confidentiality and authenticity of information resources |
|
|
|
Security Testing Focus is on working with government and industry to establish more secure systems and networks by developing, managing and promoting security assessment tools, techniques, services, and supporting programs for testing, evaluation and validation |
|
|
|
Security Research /
Emerging Technologies Focus is on research necessary to understand and enhance the security utility of new technologies while also working to identify and mitigate vulnerabilities |
|
|
|
Security
Management and Guidance Focus is on developing security management guidance, addressing such areas as: risk management, security program management, training and awareness |
|
|
|
Outreach, Awareness
and Education Focus is on activities to support wider awareness of the importance and need for IT security, promoting the understanding of IT security vulnerabilities |
|
|
|
||
|
|
Drafts
This page consists of draft NIST Publications (FIPS, Special Publications) that are either open for public review and to offer comments, or the document is waiting to be approved as a final document by the Secretary of Commerce. |
|
|
|
ITL Bulletins
ITL Bulletins are published by NIST's Information Technology Laboratory, with most bulletins written by the Computer Security Division. These bulletins are published on the average of six times a year. Each bulletin presents an in-depth discussion of a single topic of significant interest to the information systems community. Not all of ITL Bulletins that are published relate to computer / network security. Only the computer security ITL Bulletins are found here. There is a link provided on this page to get non-computer security ITL Bulletins. |
|
|
|
Federal
Information Processing Standards Publications (FIPS PUBS)
FIPS publications are issued by NIST after approval by the Secretary of Commerce pursuant to Section 5131 of the Information Technology Reform Act of 1996, Public Law 104-106, and the Computer Security Act of 1987 (Public Law 100-235). |
|
|
|
Special
Publications
Special Publications in the 800 series present documents of general interest to the computer security community. The Special Publication 800 series was established in 1990 to provide a separate identity for information technology security publications. This Special Publication 800 series reports on ITL's research, guidance, and outreach efforts in computer security, and its collaborative activities with industry, government, and academic organizations. |
|
|
|
Interagency
Reports
NIST Inteagency Reports (NISTIRs) describe research of a technical nature of interest to a specialized audience. The series includes interim or final reports on work performed by NIST for outside sponsors (both government and nongovernment). NISTIRs may also report results of NIST projects of transitory or limited interest, including those that will be published subsequently in more comprehensive form. |
|
|
|
How to order
NIST Publications
Order link - If CSRC does not have an electronic copy of the document you are looking for, this would be the page to go to get the information you need to order a copy. |
|
|
|
History of
Computer Security Project: Early Papers
This list of papers was initially distributed on CD-ROM at NISSC '98. These papers are unpublished, seminal works in computer security. They are papers every serious student of computer security should read. They are not easy to find. The goal of this collection is to make them widely available. This list was compiled by the Computer Security Laboratory of the Computer Science Department at the University of California, Davis. |
|
|
|
Other Security
Publications
This is a collection of computer security publications that the Computer Security Division received from various sources. |
|
|
|
Rainbow Series
The rainbow series is a library of about 37 documents that address specific areas of computer security. Each of the documents is a different color, which is how they became to be refereed to as the Rainbow Series. The primary document of the set is the Trusted Computer System Evaluation Criteria (5200.28-STD, Orange Book), dated December 26, 1985. This document defines the seven different levels of trust that a product can achieve under the Trusted Product Evaluation Program (TPEP) within NSA. Some of the titles include, Password Management, Audit, Discretionary Access Control, Trusted Network Interpretation, Configuration Management, Identification and Authentication, Object Reuse and Covert Channels. A new International criteria for system and product evaluation called the International Common Criteria (ICCC) has been developed for product evaluations. The TCSEC has been largely superceded by the International Common Criteria, but is still used for products that require a higher level of assurance in specific operational environments. Most of the rainbow series documents are available on-line. |
|
|
||
|
|
Scan for Security Risks (Test your computer's exposure to online
security threats and learn how to make your computer more security) -
About Scan for Security Risks |
|
|
|
Scan for Viruses (Examine your computer using Symantec's award-winning
virus detection technology to determine if it is infected by any known virus
or Trojan Horse) -
About Scan for Viruses |
|
|
|
Trace a Potential Attack (Discover information about the network from which a potential attack originated and the geographical location of the computer that was used) - About Trace a Potential Attack |
|
|
||
|
|
Symantec Security Response
(Latest virus threats, security advisories, virus definitions, updates,
virus removal tools) |
|
|
|
Distributed.net (Project in
cracking RC5, CS, & DES) |
|
|
|
ICSA Labs (A division of TruSecure
Corporation in Internet Security Assurance) |
|
|
|
OSVDB.Org
Open Source Vulnerability Database (OSVDB) is an independent and open source database created by and for the community. The goal is to provide accurate, detailed, current, and unbiased technical information. |
|
|
|
||
|
|
Gibson Research Corporation
(Free NanoProbe Technology Internet security testing for Windows users) |
|
|
|
Microsoft Baseline Security Analyzer (Tool that scan Windows-based computers for common security misconfigurations) | |
|
|
||
|
|
TruSecure Corporate (Formerly known
as National Computer Security Association, NCSA) |
|
|
|
Computer Security Institute (Provide education on practical,
cost-effective ways to protect an organization's information assets) |
|
|
|
International Computer Security Association, ICSA (Providing
security assurance services for Internet connected companies) |
|
|
|
Disaster Recovery Information Exchange (Providing information about
protecting data against disaster) |
|
|
|
Forum of Incident Response and Security Teams (Global organization
established to foster cooperation and response coordination among computer
security teams worldwide) |
|
|
|
High
Technology Crime Investigation Association (Providing information about
technology crime) |
|
|
|
Information Systems Audit and Control Association, ISACA (Worldwide
member Association dedicated to IS Audit, Control and Security
practitioners) |
|
|
|
Information Systems Security Association, ISSA (International
organization of information security professionals and practitioners) |
|
|
|
British Security Industry Association (Professional trade association for the security industry in the UK) | |