<?xml version="1.0" encoding="iso-8859-1"?>
 <rss version="2.0" xmlns:ISW="http://www.infosecwriters.com/ISWModule.php">
<channel>
<title>Infosec Writers Latest Security Papers</title>
<link>http://www.infosecwriters.com/</link>
<description>Papers submitted by security professionals are published on the site and archived for readers. Categories include cryptography, E-mail security, exploitation, firewalls, forensics, honeypots, IDS, malware &amp; wireless security.</description>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>
<language>en-us</language>
<managingEditor>staticreply@yahoo.com</managingEditor>
<webMaster>reso@infosecwriters.com</webMaster>
 <lastBuildDate>Fri, 09 May 2008 00:00:08 EDT</lastBuildDate>
 <item>
<title>An Approach to Web Application Threat Modeling</title>
<link>http://www.infosecwriters.com/texts.php?op=display&amp;id=621</link>
<ISW:author>Akash Shrivastava</ISW:author>
<description>The aim of this paper, written by Akash Shrivastava, is to identify relevant threats and vulnerabilities in the Web Application and build a Security Framework to help in designing a secure Web Application.</description>
<pubDate>Fri, 09 May 2008 00:00:00 EDT</pubDate>
</item>
<item>
<title>Computer Forensics Procedures, Tools, and Digital Evidence Bags: What They Are and Who Should Use Them</title>
<link>http://www.infosecwriters.com/texts.php?op=display&amp;id=620</link>
<ISW:author>Brett Pladna</ISW:author>
<description>This paper, written by Brett Pladna, will try to demonstrate the importance of computer forensics by describing procedures, tools and differences in the use for individuals/small organizations vs. large organizations.</description>
<pubDate>Thu, 08 May 2008 00:00:00 EDT</pubDate>
</item>
<item>
<title>Security Needs in Embedded Systems</title>
<link>http://www.infosecwriters.com/texts.php?op=display&amp;id=619</link>
<ISW:author>Anoop MS</ISW:author>
<description>The paper discusses the hardware and software security requirements in an embedded device that are involved in the transfer of secure digital data. The paper gives an overview on the security processes like encryption/decryption, key agreement, digital signatures and digital certificates that are used to achieve data protection during data transfer. The paper also discusses the security requirements in the device to prevent possible physical attacks to expose the secure data such as secret keys from the device. The paper also briefs on the security enforced in a device by the use of proprietary security technology and also discusses the security measures taken during the production of the device.</description>
<pubDate>Wed, 07 May 2008 00:00:00 EDT</pubDate>
</item>
<item>
<title>A Guide E-Mail Systems and Security</title>
<link>http://www.infosecwriters.com/texts.php?op=display&amp;id=618</link>
<ISW:author>Brian Donadio</ISW:author>
<description>Brian Donadio contributes his paper which provides information on secure methods of sending and receiving E-Mail over the Internet.</description>
<pubDate>Sun, 04 May 2008 00:00:00 EDT</pubDate>
</item>
<item>
<title>A Comparison of VNC Connection Methods</title>
<link>http://www.infosecwriters.com/texts.php?op=display&amp;id=617</link>
<ISW:author>Frank Isaacs</ISW:author>
<description>This paper, written by Frank Isaacs, discusses different methods of deploying VNC with an emphasis on the security considerations of each method, and the tradeoffs associated with the convenience of each method.</description>
<pubDate>Wed, 30 Apr 2008 00:00:00 EDT</pubDate>
</item>
<item>
<title>Three Linux Security Basics</title>
<link>http://www.infosecwriters.com/texts.php?op=display&amp;id=616</link>
<ISW:author>Jeff S. Drake</ISW:author>
<description>This paper, written by Jeff Drake, outlines some basic security issues and concerns as they relate to Linux server security and tools and techniques that can be implemented to harden the system. </description>
<pubDate>Mon, 28 Apr 2008 00:00:00 EDT</pubDate>
</item>
<item>
<title>Server Virtualization and Information Security Concerns</title>
<link>http://www.infosecwriters.com/texts.php?op=display&amp;id=615</link>
<ISW:author>Daniel James</ISW:author>
<description>Daniel James and William J. Sparks discusses virtualization, the benefits, security and financial imapact.</description>
<pubDate>Tue, 08 Apr 2008 00:00:00 EDT</pubDate>
</item>
<item>
<title>Privacy?  Protecting Consumer Data in a Wireless World</title>
<link>http://www.infosecwriters.com/texts.php?op=display&amp;id=614</link>
<ISW:author>Robin Waddell Link</ISW:author>
<description>Robin Link submits this paper on the personal information vulnerable over wireless retail networks and how PCI plays a part in all of it.</description>
<pubDate>Tue, 25 Mar 2008 00:00:00 EDT</pubDate>
</item>
<item>
<title>Extensible Authentication Protocol (EAP) Security Issues</title>
<link>http://www.infosecwriters.com/texts.php?op=display&amp;id=613</link>
<ISW:author>Samuel Sotillo</ISW:author>
<description>This document, written by Samuel Sotillo, presents an overview on some security issues that affect the Extensible Authentication Protocol as defined by the IETF RFC 3748. </description>
<pubDate>Sun, 09 Mar 2008 00:00:00 EST</pubDate>
</item>
<item>
<title>Malware – What It Is and How to Avoid It</title>
<link>http://www.infosecwriters.com/texts.php?op=display&amp;id=612</link>
<ISW:author>Daniel James</ISW:author>
<description>Daniel James submits this study on the different types of malware and how to protect against them.</description>
<pubDate>Tue, 26 Feb 2008 00:00:00 EST</pubDate>
</item>
 </channel>
</rss>