GENERAL RESOURCES:
Educational Sites
CARIS - Center for Advanced Research in InfoSec at University of Illinois
CERIAS - Purdue's Center for Education & Research in Information Assurance & Security
CERT/CC - Carnegie Mellon's Coordination Center for Internet Security Expertise
C3S Center for Computer & Communications Security - also at Carnegie Mellon
Critical Infrastructure Project - joint project of George Mason & James Madison U.
CISSP Certification - online study guides available
Colleges with Courses in Digital/Computer Forensics - from E-Evidence Info Center
Complete List of College Crypto and Security Courses - for U.S. and worldwide
Dartmouth College ISTS - Institute for Security Technology Studies
George Mason University & GMU Technology & Law - an InfoSec Center & think tank
George Washington University - Off-programs related to InfoSec
Georgia Tech Information Security Center - College of Computing and Info Security Center
I3P Institute for Information Infrastructure Protection - a consortium group at Dartmouth
Indiana Univ. of PA - Center of Excellence in Information Assurance
Institute of Police Technology - popular Florida courses in computer crime investigation
ISS advICE - database on infosec and anti-hacker techniques
ITLabsOnline - helpful resources found here
John Hopkins Security Informatics Institute - an industry-academe partnership
Kennesaw State Cybercrime Institute - SCI Southeast Cybercrime Institute
MIT Lab for Computer Science & Ron Rivest's Group - InfoSec and Cryptography Pages
National Defense University - their many Centers on Information and Technology
New York University Institute for Civil Infrastructure Systems - joint project with Cornell et. al.
Oregon State Information Security Laboratory - College of Computing, Math, & Engineering
Southwestern Comm. College Cybercrime Technology Program - syllabi and lecture notes
Univ. of California Davis - Computer Security Laboratory
UNC-Charlotte IT course offerings - in security, privacy, and other topics
Univ.of New Haven - syllabi for two or three courses usually available
Univ. of Tulsa - Center for Information Security
Government Sites
CERT (Computer Emergency Readiness Team) - coordinates attacks against the nation
CIAO (Critical Infrastructure Assurance Office) - coordinates top twenty list of vulnerabilities
DISA (Defense Information Systems Agency) - Air Force, Army, & Navy IS
DOJ Cybercrime Bureau - a department of Justice website with a kid's page
EC InfoSec home page - European Commission InfoSec site
FedCIRC - great source for incident notes and intrusion detection tips
FBI - the Federal Bureau of Investigation
InterPol - their Technocrime Prevention page, with checklist
Lawrence Livermore National Laboratory - cutting edge research in energy science
Los Alamos National Laboratory - futuristic applied research
NIPC (National Infrastructure Protection Center) - Infraguard and where most incidents reported
Pacific Northwest National Laboratory - technological innovation
GAO Cyber-Security Assessments - yearly risk assessments in pdf and htm format
NIH Center for Security Information - includes advisories and other links
NIST Computer Security Division and CSRC - Department of Commerce sites
North Carolina InfraGard - our state partnership and the National Chapter
NPS CISR - Navy Postgraduate School Center for InfoSec Research
Office of Homeland Security - America's newest cabinet level agency
Sandia National Laboratory - emerging technologies that respond to national security threats
White House National Strategy to Secure Cyberspace - the official strategy of the U.S.
Industrial, Organization, or Private Sector Sites
CVE - Common Vulnerabilities and Exposures from MITRE Corp.
Computer Security Institute - a professional association that holds conferences
CyberSecurity Institute - a biz site listing core competencies in computer forensics
E-Evidence Info - big list of links in computer forensics
FIRST - a Forum of government, business, and academic incident responders
Forensics NL - big list of computer forensics and cybercrime resources
Infosyssec: The Security Portal for IT Professionals - a private think tank
Intense School - Microsoft's famous "boot camps" for IT security professionals
Jane's Information Group/Security Section - focus on terrorism and information technology
Microsoft Research - innovations in a variety of mathematically possible ways
Microsoft Technet - be sure to see the Security>Bulletins and Support>Knowledge Base
MIS Training Institute - provides courses and more in Audit and Information Security training
Mitretek Systems - a well-known think tank in criminal justice engineering
National Security Institute - provider with a lot of educational resources online
NIST List of Computer Security Organizations - professional associations and conferences
RAND Corporation - a well known think tank in public policy
SANS Institute - perhaps the premiere cyber-defense institute; intrusion detection specialists
World Research Group - holders of training workshops on computer forensics
Individual Home Pages
Computer Forensics World - a community of professionals
Dorothy Denning's home page - Georgetown InfoSec guru
Fred Cohen's home page - a consultant's tools, talks, and idea on strategic intelligence
George Smith's "Crypt" newsletter - a self-styled computer security critic
Nathan Smith's Computer Forensic Tech - another personal home page builder
Rik Farrow's Spirit.com - ports, firewalls, and web server security advice
Ron Rivest's home page - MIT's cryptography and security expert
The WWW security FAQ - longtime Internet favorite
Publisher Websites
Cipher - the IEEE Computer Security newsletter
CNet Builder Buzz: Server Insecurity - includes antihacker downloads
CyberEthics - website for the book
Digital Investigation - website for the journal with sample articles
Dr. Dobb's Journal - sophisticated tech magazine for computer professionals
Journal of Computer Security's CS database - searchable bibliographies
Lists of Computer Forensics Books reviewed - by an Amazon.com member
MSNBC Technology Front Page - Hacks, Attacks, Bugs, and Vulnerabilities
Network Magazine - sophisticated tech magazine for enterprise solutions
Security in the News - excellent, up-to-date newsletter out of Dartmouth
SC Magazine - largest circulating InfoSec magazine and its InfoSecurity News
Security Focus Magazine - tracks vulnerabilities, bugs, glitches, and flaws
Thomson Course Technology - InfoSec courseware and books
SPECIALIZED RESOURCES:
Authentication Issues
Granularity and Extensibility of Access Control - choosing a control scheme
Kerberos - the network authentication scheme explained
Facial Biometrics / Recognition - modern-day mugshots
International Biometric Group - an international focal point
The Biometric Consortium - a focal point for U.S. research and testing
The Face Recognition Home Page - tutorials and resources
Encryption Issues
Beginner's Cryptography Page - keepers of the CryptRing
Cryptography: Ron Rivest's MIT Site - pointers to other sites on the Web
Cryptography: The Study of Encryption - a comprehensive mega-site on encryption
Cryptography and Liberty - country-by-country policies on encryption
Data Encryption Techniques- an overview for beginners
International Association for Cryptologic Research - a professional association
TruSecure - an information security assurance provider
ZDNet Developer - their Backend Security section
RSA Security - a major player in the crypto field
IP Level Encryption - discussion of an emerging technology
S/MIME & PGP-a comparison of the two technologies
Hacking Issues
2600 Magazine - one of the oldest hacking news sites on the Net
AntiOnline - hackers know your weaknesses, shouldn't you?
AuditMyPC.com - free firewall tests and port scans
Computer Undergroung Digest (Cu Digest)- a popular magazine during the 90s
Digicrime - a full service criminal computer hacking organization
Fyodor's Exploit World - an archive of ALL the exploits
Hackers.Com - live hacker chats and security tips
@Stake.com -security advisories from a hacker's point of view
Nomad Mobile Research Centre - advisories, FAQs, and files
Phrack Magazine - home page for the largest IRC group of hackers
Root Shell - UNIX-based resource links
Infowarfare Issues
Al Fundaburk's Infowarfare site - he used to work at NC Wesleyan
Institute for Advanced Study of Information Warfare- as vicious-looking as it sounds
Infowar.com - a store, museum, archive, and library all rolled into one
Law and Legal isues
Berkeley Journal of Computers and the Law-your basic law school journal
Copyright and Multimedia Law - a fascinating topic and website
Crypto Law Survey - a dissertation on the law enforcement problems of cryptography
Cyberspace Law - article abstracts viewable only
Electronic Frontier Foundation - a major player on cyberspace issues
Government Crypto Policy - Center for Democracy and Technology
Harvard Journal of Law and Technology - some free stuff online
Proposals for regulating Public's right to use Databases - publicdomain.org
Stanford Technology Law Review -cyberspace speech controversies
Planning Issues
Atomic Tangerine-a vendor/portal website
Computer Security Information and FAQ - helpful page from the NIH
Netsurfer Focus on Computer & Network Security - a magazine-like website
Higher Education Security Policies-a survey
Interpol Computer Security Checklist - helpful advice from Interpol
MIT Information Security Office Web Page - sample policies to emulate
Network Engineering Mistakes - a free virtual seminar program
NIST Computer Security Resource Clearinghouse - a major website resource
SANS Model Computer Security Policies - free online tutorials
Stanford University Information Security Office - a good many policies to sample
Prevention Issues
Building Internet Firewalls Tutorial - Brent Chapman's one-day tutorial
Firewalls Mailing List - archived discussions at GNAC
IT Security Toolbox - a wealth of information and discussion groups
PresiNET - an Internet management solutions company
The Rotherwick Firewall Resource - UK site
Talisker's Intrusion Detection Systems List - UK site
Protocols and Standards Issues
Comprehensive List of Public Key and Certificate Links- the PKI Page
CGSB Independent Audit Standard - an auditing service company
Baseline Software's Security Policies - a library of policies made easy
Internet Engineering Task Force - discussion of IPSEC
International Telecommunication Union - X protocols
MD5 - MIT's working group on MD5 algorithm
MIME Security with PGP - a request for comment paper
PGP Message Exchange Formats - another request for comment paper
Point to Point Tunnelling Protocol - 3Com's tech specs
Secure Electronic Transactions- e-commerce merchandising protocols
Virus Issues
Computer Virus Myths - a beginner's guide to hoaxes and legends
AVP Virus Encyclopaedia - a sophisticated classification encyclopedia
Computer Virus Information and Resources Page - at the Univ. of N. Texas
Datafellows (F-Prot) Virus Database Page - the F-Secure virus info center
SaferSite -makers of Pest Patrol, which cleans up remnants of virii
Symantec Virus Database Page-the Symantec (IBN, Norton) virus info center
Trend Micro Antivirus Page-the Trend (PC-cillin) virus info center
Virus Bulletin -an online journal with wildlists of who found what
WildList - more up-to-date collection of wildlists
Viruslist.com-an encyclopedia/news site in Russian and English
Vulnerability Issues
CERT/CC Top Ten List of Exploits - advisories and incident notes
Common Vulnerabilities and Exposures-definitions and examples of both
Security Focus - home of Bugtraq and a library of articles
The Encyclopedia of Computer Security - more than just a glossary, tutorials too
SPECIFIC LINKS USED IN ONLINE LECTURES:
Lecture #1: Overview of Computer Security
American Society for Industrial Security
Auerbach Publications
Computer Security Institute
Computer Security Resource Center (CSRC)
Computer Security Technology Center
Federal Computer Weekly
High-Tech Crime Network
Information Security Magazine
InfoWorld's Security Audit Resource Guide
Links at the Centre for Software Reliability
Links on Software Reliability, Safety, and Metrics
Network Security Library
Security Management Magazine
Sample pages of Mission Critical
Author Ken Laudon's website
Lecture #2: Computer Security Policies
A Survey of Higher Education Computer Security Policies
Business Continuity Planning
Glendale Systems Computer Security Policy Model
Interpol IT Crime Prevention Checklist
SANS Model Computer Security Policies
SC: InfoSecurity Magazine Online
The Only Safe Computer is a Dead Computer
Sample pages of E-Policy
Author's list of web security books
Lecture #3: CyberStrategy
Selected Provisions of the USA PATRIOT Act
FEMA definition of CIP
Cyber-czar appointment in DHS
InfraGard
List of ISACS
Presidential Decision Directive 63
FedCIRC
CESA
National Strategy for the Physical Protection of Critical Infrastructures and Key Assets (pdf)
Homeland Security Presidential Directive 7
Financial Services Sector ISAC; 2003 GAO Report (pdf)
Chemical Sector ISAC; Chemical Sector Cybersecurity Forum
Continuity Sector NASCIO; 2001 GAO Report (pdf)
Electrical Sector ESISAC; North American Electric Reliability Council
Law Enforcement Sector EMR ISAC
Fire Services Sector FEMA's Fire Administration website
Food Industry Sector ISAC webpage
Health Sector CDC's Public Health Emergency Response Guide
Higher Education Sector Educause; Office of Safe & Drug-Free Schools
IT Sector ISAC; Information Technology Association of America
Insurance Sector, see Financial Services ISAC; Real Estate ISAC
Oil & Gas Sector National Petroleum Council
Transportation Sector Surface Transportation ISAC; Association of American Railroads
Water Sector ISAC; Association of Metropolitan Water Agencies
John Robb's article on design flaws in Business Model
Support Anti-terrorism by Fostering Effective Technologies Act of 2002
American Water Works Association
An Assessment (Report Card) on Homeland Security (pdf)
Commonwealth Institute Resources on Critical Infrastructure Protection
ContingencyPlanning.com
CRS Backgrounder Report on Critical Infrastructure Policy (pdf)
CRS Report on the Definition & Identification of Critical Infrastructures (pdf)
Dept. of Defense CIP Plan
DHS Organization for Infrastructure Protection
DHS Webpage for Critical Infrastructure
Executive Order on Critical Infrastructure Protection
George Mason University CIP Project
John Robb's Global Guerrillas Website
Larry Wortzel's Paper on Securing America's Critical Infrastructures
Legal Issues & Challenges of Critical Infrastructure Protection (pdf)
National Infrastructure Institute (NI2)
National Strategy for Physical Protection of Critical Infrastructure & Key Assets (pdf)
National Strategy to Secure Cyberspace (pdf)
NIST Partnerships in Specific Industry Sectors
The Infrastructure Security Partnership
USFA-FEMA Website for What CIP is About
Sample Excerpt of Reforming Infrastructure
Lecture #4: CyberCrime
Lecture on Privacy and Cyberspace Law
corporate espionage
CAIDA's map of Internet
Dictionary of Cyberpunk Slang
Lectures on Theft, fraud, and consumer fraud
CardCops
EscrowFraud.com
Director Freeh's testimony 2000
National Infrastructure Protection Center
Hacking and Industrial Espionage
Research study at Carnegie Mellon
Cybercrime, Justice, Law and Society
Cyberpunk Top 100 Sites
Cyberspace and the American Dream
Cyberterrorism: How Real is the Threat?
DHS National Infrastructure Protection Center
Federal Guidelines for Searching & Seizing Computers (1994)
Federal Guidelines for Searching & Seizing Computers (2001)
Hacking and Industrial Espionage
InfoSec and InfoWar Portal
Institute for Advanced Study of Information Warfare
MSNBC's Hacker Diaries
National Cybercrime Training Partnership
National Strategy to Secure Cyberspace
Prof. Rob Kling's Social Informatics web page
The Modus Operandi of Hacking
The Zapatista Social Netwar in Mexico
U.S. Dept. of Justice Cybercrime Section
What is CyberTerrorism?
White House National Strategy to Secure Cyberspace
Dorothy Denning's article on Activism, Hacktivism, and Cyberterrorism
EFF article on Cyberspace
Lawrence Lessig's website
Lecture #4a: CyberPredation
Free Spirits, NAMBLA, Rene Guyon Society, Childhood Sensuality Circle
Paraphilias
Lecture on Understanding Sexual Fetishes
Lecture on Serial rapists
National Center for Missing & Exploited Children
Uniform Crime Reports
NCVS
Dissociative Identity Disorders
Checklist of Child Sexual Abuse Symptoms
PROTECT
Hank Giarretto
Bridgewater
Phallometry
A Glossary of Terms Used in Treatment of Sex Offenders (pdf)
All About Pedophiles and Child Molesters
Association for the Treatment of Sexual Abusers
Center for Sex Offender Management (CSOM)
Child Molesters Who Abduct (pdf)
Deviant Desires.com
DSM-IV and the Paraphilias: An Argument for Removal
Extrafamilial Sexual Abuse, Misuse, & Exploitation (pdf)
Free Spirits: Boylove on the Internet
Incest Survivors After Effects Checklist
In Search of an Etiological Model of Pedophilia
Intrafamilial (Incest) Child Abuse Resources
National Center for Missing & Exploited Children Sexual Exploitation Page
Prevent-Abuse-Now.com
Rape, Abuse, and Incest National Network (RAINN)
Sinclair Seminars on Assessing Sex Offender Psychopathy
Stop It Now: The Campaign to Prevent Child Sexual Abuse
Survivors of Incest Anonymous
The Child Molesters by Nicholas Groth
The Pedophilia/Pedophile Education Web Site Mirror
Traits found in Potential Child Molesters
Treatment of Sexually Aggressive Behavior from a Theological Viewpoint
Voices in Action, Inc.
Dr. Drew
Lecture #4b: Cybervigilantism
Border Rescue/Ranch Rescue, USA
Franklin Zimring on the Vigilante Mindset (doc)
SPL Center's Intelligence Report/Vigilante Watch
The Crime of Cyber-Vigilantism
The Spirit of Vengeance (Excerpt from Karl Menninger)
Thoughts on Revenge and Retribution
Vigilantes and Policing in Nigeria (doc)
Vigilantism Revisited: A Legal and Economic Analysis (pdf)
Lecture #4c: Cyberterrorism
Lecture Notes from Homeland Security course
Laird v. Tatum
Patriot Debates website
Posse Comitatus Act of 1878
Gilmore Commission
www.northcom.mil
Pentagon Strategy on Homeland Defense and Civil Support (pdf)
Defense Science Board Report on DOD Roles and Missions in Homeland Security pdf
DOD Directive 5240.1-R and 5105.67
Lecture on Stuational Awareness
ORCON
DHS & FEMA
National Response Team
National Guard Bureau's J5 (IA) Unit
National Response Center
FEMA's Emergency Management Institute
Defense Production Act of 1950
PDD-63
Executive Order 12656
Mount Weather & Greenbrier Resort
FBI definition of cyberterrorism, NIPC definition & CSIS definition (pdf)
ELIGIBLE RECEIVER
Gartner Research "digital Pearl Harbor" scenario
US position on the Council of Europe's proposed Cybercrime Convention
National Security Response to Computer Intrustions (Note: Not official US. Government Policy)
Knauff v. Schaughnessy (1950) & Kwong Hai Chew v. Colding (1953)
Jay v. Boyd
McGehee v. CIA
Korematsu v. US
Hirabayashi v. U.S.
9-11 Commission: Terrorist Attacks on US
A Plague on Your City: Observations from TOPOFF (pdf)
Air War College Resources on Homeland Security
ANSER Homeland Security Institute
Center for Democracy Comment on the Defense Production Act
Citizen's Guide to Using the FOIA and Privacy Act of 1974
Cyberterrorism: How Real is the Threat?
Department of Homeland Security (DHS)
Department of Homeland Security (DHS) Role Overseas
DOD Directive 3025.15 (Military Assistance to Civil Authorities)
DOD Directive 5105.67 (Counterintelligence Field Activity)
DOD Directive 5240.1-R (Intelligence Affecting US Persons)
Gilmore Commission: Domestic Response to WMD
Homeland Security & US Civil-Military Relations
Homeland Security: The New Role for Defense
Church Commission: Improper Surveillance of American Citizens
Journal of Homeland Security
Journal of Homeland Security & Emergency Management
MegaLink's Internet Resources for Homeland Security
Myth of Posse Comitatus
National Academic Consortium for Homeland Security
National Strategy to Secure Cyberspace
Navy Postgraduate School White Paper on Cyberterror (pdf)
Northcom's Statement on the Difference between Homeland Security & Homeland Defense
Pentagon Strategy on Homeland Defense and Civil Support (pdf)
Putting Cyberterrorism in Context
RAND Corp. Homeland Security Program Homepage
RAND Report on Preparing US Army for Homeland Security
Robert T. Stafford Disaster Relief & Emergency Assistance Act
Role of National Guard in Homeland Security
The Need for a Goldwater-Nichols Act II
Thesis on Enhancement of the Civil Reserve Air Fleet
Wartime Rights, Civil Liberties, and Reparations
Wikipedia Entry on Continuity of Operations Plan
Wikipedia Entry on Korematsu v. United States
Prof. Becker's article on the Waco Incident
The National Strategy for Homeland Security
Sample excerpt of Waltz' Information Warfare
Lecture #5: Spyware
Trisys
WinWhatWhere
SpectorSoft
FTC's hotline
Cookie Central
Sample Web Bug
Web Bug Report
Adware, Spyware, and Unwanted Malware Removal
IDG.net
Internet Security Downloads
PCworld.com/
Privacy Foundation
Scumware: A New Threat
Securityfocus.com
Senator Edward's Spyware Control Act
SpyChecker
Securityfocus.com/
ZDNet What is Spyware?
Lecture #6: Malware
http://www.websense.com
http://www.surfcontrol.com
http://www.sans.org/infosecFAQ/win2000/win2000_list.htm
http://www.sans.org/infosecFAQ/win/win_list.htm
An Excerpt from George Smith's The Virus Creation Labs
Infosyssec Virus, Trojan, and Hoax Research Center
Internet Week Magazine
SANS Global Incident Response Center
Symantec AntiVirus Security Center
Lecture #7: Hacking
CERT
CVS
SANS
FBI
Prof. Marc Rogers website
Sociology of CyberSpace
Hacking Exposed
Wget
Teleport Pro
Webferret, NeoTrace and other apps
SEC Edgar database
Internic WhoIs Lookup
Sam Spade
Article on IP Scanning
TCP and UDP Ports