10/26/2008

European Report on internet traffic

2008 Report on European IXPs

This report has been compiled by the European Internet Exchange Association (Euro-IX) in an attempt to get a better picture of the past and current situation in regards to the number of Internet Exchange Points (IXPs) operating in Europe, the amount of traffic being exchanged at these IXPs, the number of connected parties peering there, as well as other relevant statistics and trends that are now appearing in the European IXP market.

In an effort for us to better design future reports to suit community needs we would very much appreciate if you could let us know that you have downloaded this report and of course any comments or feedback would be more than welcome.

 Download 2008 Report

22:36 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

10/22/2008

Nederlandse Crisismanagementsbrochure voor burgemeesters

Voor burgemeesters bestaat sinds kort een nieuwe handreiking Bestuurlijk handelen bij crises. Deze richt zich op de rol van de bestuurder en zijn/haar aandachtsgebieden tijdens een crisis. Van het crisismanagement in het beleidsteam en binnen het gemeentehuis, tot de rol van burgervader en boegbeeld richting lokale samenleving en media. Dus dit lijkt ook ‘verplichte kost’ voor de communicatieadviseurs en woordvoerders die met de burgemeester samenwerken

De handreiking is opgesteld door het Nederlands Genootschap van Burgemeesters (NGB). In het boekwerkje zijn de ervaringen verwerkt van crises in de afgelopen jaren. Zo krijgen de burgemeesters in totaal 94 tips en aandachtspunten. De belangrijkste lessen zijn ingedeeld volgens een aantal fasen van de crisisbeheersingsketen: preparatie-, respons- en nazorgfase, de alarmeringsfase en de omgang met de media. 

comment : niet erg praktisch, maar goed misschien bestaan die praktische documenten en guidelines ergens anders

12:32 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

10/20/2008

TCP/IP flaw Good document about security of the internet protocol

11:13 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Cyber threats 2009 report

Emerging Cyber Threats Report for 2009

Data, Mobility and Questions of Responsibility will Drive Cyber Threats in 2009 and Beyond

On October 15, 2008, the Georgia Tech Information Security Center (GTISC) hosted its annual summit on

 

and the webcast

emerging security threats and countermeasures affecting the digital world. At the conclusion of the event, GTISC released this Emerging Cyber Threats Report—outlining the top five information security threats and challenges facing both consumer and business users in 2009. This year’s summit participants include security experts from the public sector, private enterprise and academia, reinforcing GTISC’s collaborative approach to addressing information security technology and policy challenges.

 

10:34 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

10/16/2008

Internet drafts : selection of new ones 29 sept - 15th october

.draft-ietf-dhc-option-guidelines-03.txt     Guidelines for Creating New DHCP Options    14/10/2008
.draft-ietf-idnabis-defs-00.txt     Internationalized Domain Names for Applications (IDNA): Definitions and Document Framework    14/10/2008
..draft-ietf-isms-tmsm-14.txt     Transport Subsystem for the Simple Network Management Protocol (SNMP)    14/10/2008
draft-templin-autoconf-dhcp-17.txt     Virtual Enterprise Traversal (VET)    14/10/2008
.draft-krishnan-ipv6-exthdr-06.txt     An uniform format for IPv6 extension headers    14/10/2008
.draft-ietf-rohc-hcoipsec-09.txt     Integration of Robust Header Compression (ROHC) over IPsec Security Associations    14/10/2008
.draft-ietf-rohc-ikev2-extensions-hcoipsec-07.txt     IKEv2 Extensions to Support Robust Header Compression over IPsec (ROHCoIPsec)    14/10/2008
.draft-ietf-ecrit-location-hiding-req-01.txt     Location Hiding: Problem Statement and Requirements    12/10/2008
.draft-ietf-ecrit-specifying-holes-01.txt     Specifying Holes in LoST Service Boundaries    12/10/2008
.draft-ietf-isms-radius-usage-04.txt     Remote Authentication Dial-In User Service (RADIUS) Usage for Simple Network Management Protocol (SNMP) Transport Models    12/10/2008
.draft-nir-ike-qcd-03.txt     A Quick Crash Detection Method for IKE    12/10/2008
.draft-arkko-eap-aka-kdf-06.txt     Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA')    12/10/2008
.draft-ietf-krb-wg-anon-10.txt     Anonymity Support for Kerberos    10/10/2008
.draft-ietf-mext-firewall-admin-00.txt     Guidelines for firewall administrators regarding MIPv6 traffic    10/10/2008
.draft-ietf-mext-firewall-vendor-00.txt     Guidelines for firewall vendors regarding MIPv6 traffic    10/10/2008
.draft-irtf-asrg-dnsbl-07.txt     DNS Blacklists and Whitelists    10/10/2008
.draft-kucherawy-sender-auth-imap-00.txt     IMAP Annotation for Indicating Message Authentication Status    10/10/2008
.draft-brusilovsky-pak-07.txt     Password-Authenticated Diffie-Hellman Exchange (PAK)    09/10/2008
.draft-ietf-rserpool-mib-07.txt     Reliable Server Pooling: Management Information Base using SMIv2    09/10/2008
.draft-freed-sieve-ihave-03.txt     Sieve Email Filtering: Ihave Extension    09/10/2008
.draft-ietf-smime-ibearch-09.txt     Identity-based Encryption Architecture and Supporting Data Structures    09/10/2008
draft-ietf-ancp-security-threats-06.txt     Security Threats and Security Requirements for the Access Node Control Protocol (ANCP)    07/10/2008
draft-ietf-idnabis-rationale-03.txt     Internationalized Domain Names for Applications (IDNA): Definitions,Background and Rationale    07/10/2008
draft-ietf-isms-secshell-12.txt     Secure Shell Transport Model for SNMP    07/10/2008
draft-ietf-isms-transport-security-model-09.txt     Transport Security Model for SNMP    07/10/2008
draft-hajjeh-tls-identity-protection-07.txt     Credential Protection Ciphersuites for Transport Layer Security (TLS)    06/10/2008
draft-liao-smimeheaderprotect-03.txt     Header Protection for S/MIME    06/10/2008
draft-ietf-pkix-ta-format-00.txt     Trust Anchor Format    06/10/2008
draft-ietf-pkix-tamp-00.txt     Trust Anchor Management Protocol (TAMP)    06/10/2008
draft-ietf-sip-domain-certs-02.txt     Domain Certificates in the Session Initiation Protocol (SIP)    06/10/2008
draft-ietf-smime-3850bis-08.txt     Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 3.2 Certificate Handling    06/10/2008
draft-iab-ip-config-08.txt     Principles of Internet Host Configuration    04/10/2008
draft-ietf-dna-simple-03.txt     Simple procedures for Detecting Network Attachment in IPv6    03/10/2008
draft-turner-deviceowner-attribute-00.txt     Device Owner Attribute    03/10/2008
draft-hoeper-proxythreat-00.txt     Threat Model for Networks Employing AAA Proxies    03/10/2008
draft-ietf-sip-xcapevent-04.txt     An Extensible Markup Language (XML) Configuration Access Protocol (XCAP) Diff Event Package    03/10/2008
draft-ietf-mext-rfc3775bis-02.txt     Mobility Support in IPv6    01/10/2008
draft-montemurro-gsma-imei-urn-02.txt     A Uniform Resource Name Namespace For The GSM Association (GSMA) and the International Mobile station Equipment Identity(IMEI)    01/10/2008
draft-marinov-syslog-snmp-02.txt     Mapping Simple Network Management Protocol (SNMP) Notifications to SYSLOG Messages    01/10/2008
draft-sharhalakis-httptz-04.txt     Timezone Information in HTTP    01/10/2008
draft-sakane-dhc-dhcpv6-kdc-option-02.txt     Kerberos Option for DHCPv6    01/10/2008
draft-keromytis-keynote-x509-01.txt     X.509 Key and Signature Encoding for the KeyNote Trust Management System    01/10/2008
draft-endo-v6ops-dnsproxy-01.txt     Translator Friendly DNS Proxy    01/10/2008
draft-keromytis-tls-authz-keynote-01.txt     Transport Layer Security (TLS) Authorization Using KeyNote    01/10/2008
draft-elwell-sip-identity-handling-ua-00.txt     Identity Handling at a Session Initiation Protocol (SIP) User Agent    01/10/2008
draft-weaver-dnsext-fr-comprehensive-00.txt     Comprehensive DNS Resolver Defenses Against Cache Poisoning    30/09/2008
draft-weaver-dnsext-comprehensive-resolver-00.txt     Comprehensive DNS Resolver Defenses Against Cache Poisoning    30/09/2008
draft-ietf-nsis-nslp-natfw-19.txt     NAT/Firewall NSIS Signaling Layer Protocol (NSLP)    30/09/2008
draft-ietf-pcn-architecture-07.txt     Pre-Congestion Notification (PCN) Architecture    30/09/2008

Internet Drafts - Title List sorted by date

14:46 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Presentations European conference on the Internet of things (RFID) 6/7 october 08

Session 1: The Challenges of the Internet of the Future and the Internet of Things

Moderator and Speaker :

Speakers:

  • Marc Fossier, Chief Technology Officer, France Telecom Presentation
  • Dr. Gerd Wolfram, Managing Director MGI Metro Group Information Technology GmbH Presentation
  • Chris Adcock, President, EPCglobal Inc Presentation
  • George Rittenhouse, Vice President, Bell Labs Research, Alcatel Lucent Presentation
  • Serge Ferré, Corporate Vice President, Nokia Global Presentation
  • Elgar Fleisch, Director Auto-ID Lab St. Gallen, ETH Zurich / University of St. Gallen, Switzerland Presentation
  • Session 2A: Which right to privacy in the light of the Internet of Things?

    Speakers:

    Session 2B: The impact of the Internet of Things on the main industrial sectors (B2B applications & services)

    Speakers:

    Session 3A: Economic challenges & technological perspectives

    Moderator and Speaker:

    Speakers:

    Session 3B: Applications and services of the mobile Internet (B2C applications & services)

     The Challenges of International Co-operation -

    Keynote Speakers: (TBC)

  • Andrew Robinson, Chairman of the French Business Council, UK Presentation
  • Session 4A: The strategy for interoperability and the standardization of the Internet of Things

    Moderator and Speaker:

    Jørgen Friis, Deputy Director ETSI Presentation

    Speakers:

    Session 4B: Architectures and governance of the Internet of Things

    Strategies, Technologies and Services Forum


    Session A1: RFID/NFC technological issues

  • Pierre Jean Benghozi, Ecole Polytechnique et Françoise Massit-Follea, MSH Presentation Conference report of 61 pages
  • Olivier Burah, Tagsys Presentation
  • Ed Mc Donnell, HP Presentation
  • Emmanuel Faussurier, ANFR, France Presentation
  • Session A2: Architectural issues of the Internet of Things

  • Walid Dabbous, Research Director, INRIA, France Presentation
  • Prof. Alois Ferscha, Institut für Pervasive Computing Presentation
  • Mr Daniel NABET, Director Machine To Machine, Orange Business Services Présentation

    12:38 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

    SOA security : interesting working group in UK

    Because in Belgium such things seem to take some time before getting started, we look wherever can find it.

    SOA is not a disease (even if some security analysts will find it disrupts their security infrastructure the way a disease does) but stands for Service Oriented Architecture in which business services like databases would interact with each other immediately and give the customer an integrated response without the necessity of going to several databases and to integrate the responses himself. THis all looks very nice on paper but how can you promise the same user that all those databases that are communicating in real time with each other are all so secure that no hacker/crimecracker is hopping from one server to another. (go with the flow).

    There is a working group in the UK that tries to get together some guidelines and standards, norms to effectively secure this. The industry has made this job quite difficult by making different solutions with different standards and different approaches. So an independent research seems the only way forward.

    The working document is here

    The wiki about SOA security is here

    and yess they are more focused on UK law and US standards but if you are part of an international group, these will be the laws and standards you will have to follow anyway (as there is nothing legal or standard around here).

    12:16 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

    10/15/2008

    Free magazine Uninformed Nr 10

    Two articles that got our attention

    Analyzing local privilege escalations in win32k  mxatone
    This paper analyzes three vulnerabilities that were found in win32k.sys that allow kernel-mode code execution. The win32k.sys driver is a major component of the GUI subsystem in the Windows operating system. These vulnerabilities have been reported by the author and patched in MS08-025. The first vulnerability is a kernel pool overflow with an old communication mechanism called the Dynamic Data Exchange (DDE) protocol. The second vulnerability involves improper use of the ProbeForWrite function within string management functions. The third vulnerability concerns how win32k handles system menu functions. Their discovery and exploitation are covered. html | pdf | txt

    ps are all your system patched ?

    Exploiting Tomorrow's Internet Today: Penetration testing with IPv6  H D Moore
    This paper illustrates how IPv6-enabled systems with link-local and auto-configured addresses can be compromised using existing security tools. While most of the techniques described can apply to "real" IPv6 networks, the focus of this paper is to target IPv6-enabled systems on the local network. html | pdf | txt

    ps and I who thought that IPv6 would be a nightmare for hackers....

    14:21 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

    10/09/2008

    IBM US presidential transition Workbook

    The Operator's Manual (3.89 MB) is a guide to how government works and how to make it work to advance policy goals and objectives. We present, in brief and simple terms, descriptions of the most important tools and levers that executives can use to advance agency goals and the president's agenda. This Manual will help executives understand the terrain of government, become familiar with the terms and lingo used inside agencies, and know how to effectively use the tools of government. Please use Internet Explorer to access this functionality

    and more publications here

    http://www.businessofgovernment.org/transition2008/

    11:46 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

    10/06/2008

    UK publishes program to describe Information assurance

    In the UK there is a whole campaign underway to promote Information assurance.

    As part of assisting organisations' boards to progress towards the broad outcomes of the National IA Strategy, and particularly the mandatory and other measures set out in the Data Handling Review, this IAMM has been created. It is supported by the Information Assurance Assessment Framework (IAAF), which is designed to assist an independent review of progress against the IAMM within an organisation. In its turn, this review will assist organisational boards to report ongoing improvements in their Information Assurance and Information Risk Management postures in their annual reports to Cabinet Office

    Document

    15:04 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

    10/03/2008

    Free Insecure Magazine October 2008

  • Network and information security in Europe today
  • Browser security: bolt it on, then build it in
  • Passive network security analysis with NetworkMiner
  • Lynis - an introduction to UNIX system auditing
  • Windows driver vulnerabilities: the METHOD_NEITHER odyssey
  • Removing software armoring from executables
  • Insecurities in privacy protection software
  • Compliance does not equal security but it's a good start
  • Secure web application development
  • The insider threat
  • Web application security: risky business?
  • DOWNLOAD ISSUE 18 HERE (October 2008)

    14:02 | Permalink | Comments (1) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

    09/30/2008

    Download 6 chapters of Access Denied, about internetfiltering

    Today we are proud to announce that chapters one through six are now available online in PDF format; they will soon be integrated into the site as well.

    Check out the first six chapters of Access Denied:

    13:11 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

    09/25/2008

    USA EGOV best projects

    2008 Best Practices in the Use of Information Technology in State Government

    Released in conjunction with NASCIO's 2008 Best Practices in the Use of Information Technology in State Government Awards, this booklet contains summaries of innovative state government programs in the following areas: Business Continuity and Disaster Recovery ; Cross-Boundary Collaboration and Partnerships; Data, Information and Knowledge Management; Digital Government – G to B; Digital Government – G to C; Digital Government – G to G; Enterprise IT Management Initiatives; Information Communications Technology Innovations; Information Security and Privacy; and IT Project and Portfolio Management.

    http://www.nascio.org/publications/documents/NASCIO-2008A...
     

    11:09 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

    09/22/2008

    Updates on Wikileaks : Palin mail and Intel patents

    Conservative commentator Bill O'Reilly's website hacked

    Palin's e-mail problems spread
    Sarah Palin: not the Gawker Exclusive
    Sarah Palin's E-mail Hacked
    Update: Hackers claim to break into Palin's Yahoo Mail account
    VP contender Sarah Palin hacked

    Secret Counterfeiting Treaty Public Must be Made Public, Global Organizations
    Say

    Has Intel broken deliberately patents ? The document presents Intel's CSI specification, written at the "Intel Restricted Secret" level and containing 671 pages. According to the source the document reveals that Intel has violated a number of patents from other chip makers such as AMD. The original document contained numerous diagrams and tables which have been deliberately lost in the conversion to text, in-order to protect any genuine Intel discoveries while still providing enough information for those who have had their patents infringed by Intel to detect the infringement.

    Also in the UK political bloggers have been forced to retract information by legal pressure or should we say extorsion ?

    The problems of using the open source character of the Internet to do military and intelligence analysis in China

    12:37 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

    New European Actions about Cybersecurity

    Viviane Reding, Commissioner for Information Society and Media, European
    Commission announced the creation of a high-level advisory board named RISEPTIS
    (Research and Innovation for SEcurity, Privacy and Trustworthiness in the
    Information Society). The main mission of RISEPTIS will be to provide visionary
    guidance on policy and research challenges in the field of security and
    trust in the Information Society. RISEPTIS is supported by the FP7 Coordination
    Action Think-Trust.


    Brochure on ICT Security Research in FP7

    New brochure is available about ICT Security Research in FP7 containing research activities in secure and trustworthy network infrastructures; in critical information infrastructure protection; in enabling technologies for security and trustworthiness of ICT; in trustworthy and secure serviceinfrastructures; in trust, privacy and identity in the digital economy; as well as the policy links and other useful information.

    Brochure in low resolution .PDF 1,5 MB

    Brochure in high resolution .PDF 8,4 MB

    12:10 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook