Showing posts with label SECURITY. Show all posts
Showing posts with label SECURITY. Show all posts

Thursday, April 26, 2012

Bluetooth Networking and its Security Architecture: Analytics of Network Concepts, Security Protocols, Vulnerabilities and Countermeasures

Bluetooth Networking and its Security Architecture: Analytics of Network Concepts, Security Protocols, Vulnerabilities and Countermeasures Review



Bluetooth wireless technology has become an essential part of our modern society. Mobile phones, game controllers, Personal Digital Assistant (PDAs), computers and various electronic gadgets have adapted Bluetooth and made it a popular technology for short range wireless communication. However, as the Bluetooth technology becomes widespread, it has shifted from short range and can now even have long range communication greater than WLANs with the help of extended antennas and so the vulnerabilities in its security protocols have also increased which can be potentially dangerous to the privacy of a user’s personal information. The security issues of Bluetooth has been an active area of research for the past few years. This book presents some vulnerabilities of this technology and proposes some countermeasures. It also provides some tips that end-users can implement immediately to become more cautious about their private information. A fairly new concept is also introduced in this book which uses a secure Bluetooth networking technology in a public environment to enable social networking between multiple users who do not have access to the internet.


Tuesday, March 6, 2012

Special Publication 800-121 Guide To Bluetooth Security

Special Publication 800-121 Guide To Bluetooth Security Review



This is a Hard copy of the NIST Special Publication 800-121, Guide To Bluetooth Security. This document discusses Bluetooth technologies and security capabilities in technical detail. This document assumes that the readers have at least some operating system, wireless networking, and security knowledge. Because of the constantly changing nature of the wireless security industry and the threats and vulnerabilities to the technologies, readers are strongly encouraged to take advantage of other resources (including those listed in this document) for more current and detailed information. The following list highlights people with differing roles and responsibilities that might use this document: Government managers (e.g., chief information officers and senior managers) who oversee the use and security of Bluetooth technologies within their organizations Systems engineers and architects who design and implement Bluetooth technologies Auditors, security consultants, and others who perform security assessments of wireless environments Researchers and analysts who are trying to understand the underlying wireless technologies. Disclaimer This hardcopy is not published by National Institute of Standards and Technology (NIST), the US Government or US Department of Commerce. The publication of this document should not in any way imply any relationship or affiliation to the above named organizations and Government.


Wednesday, January 4, 2012

Guide to Bluetooth Security: Recommendations of the National Institute of Standards and Technology (Special Publication 800-121)

Guide to Bluetooth Security: Recommendations of the National Institute of Standards and Technology (Special Publication 800-121) Review



Bluetooth is an open standard for short-range radio frequency (RF) communication. Bluetooth technology is used primarily to establish wireless personal area networks (WPAN), commonly referred to as ad hoc or peer-to-peer (P2P) networks. Bluetooth technology has been integrated into many types of business and consumer devices, including cellular phones, personal digital assistants (PDA), laptops, automobiles, printers, and headsets. This allows users to form ad hoc networks between a wide variety of devices to transfer voice and data. This document provides an overview of Bluetooth technology and discusses related security concerns. There have been several versions of Bluetooth, with the most recent being 2.0 + Enhanced Data Rate (EDR) (November 2004) and 2.1 + EDR (July 2007). While 2.0 + EDR provided faster transmission speeds than previous versions (up to 3 Mbits/second), 2.1 + EDR provides a significant security improvement for link key generation and management in the form of Secure Simple Pairing (SSP). This publication addresses the security of these versions of Bluetooth, as well as the earlier versions 1.1 and 1.2. Bluetooth technology and associated devices are susceptible to general wireless networking threats, such as denial of service attacks, eavesdropping, man-in-the-middle attacks, message modification, and resource misappropriation. They are also threatened by more specific Bluetooth-related attacks that target known vulnerabilities in Bluetooth implementations and specifications. Attacks against improperly secured Bluetooth implementations can provide attackers with unauthorized access to sensitive information and unauthorized usage of Bluetooth devices and other systems or networks to which the devices are connected. To improve the security of Bluetooth implementations, organizations should implement the following recommendations: Organizations should use the strongest Bluetooth security mode available for their Bluetooth devices. The Bluetooth specifications define four security modes, and each version of Bluetooth supports some, but not all, of these modes. The modes vary primarily by how well they protect Bluetooth communications from potential attack. Security Mode 3 is considered the strongest mode because it requires authentication and encryption to be established before the Bluetooth physical link is completely established. Security Modes 2 and 4 also use authentication and encryption, but only after the Bluetooth physical link has already been fully established and logical channels partially established. Security Mode 1 provides no security functionality. The available modes vary based on the Bluetooth specification versions of both devices, so organizations should choose the most secure mode available for each case.


Sunday, November 27, 2011

A+, Network+, Security+ Exams in a Nutshell: A Desktop Quick Reference (In a Nutshell (O'Reilly))

A+, Network+, Security+ Exams in a Nutshell: A Desktop Quick Reference (In a Nutshell (O'Reilly)) Review



If you're preparing for the new CompTIA 2006 certification in A+, or the current Network+ and Security+ certifications, you'll find this book invaluable. It provides all the information you need to get ready for these exams, including the four new A+ exams -- the required Essentials exam and three elective exams that pertain to your area of specialization.

As with other O'Reilly Nutshell books for certification exams, A+, Network+ and Security + in a Nutshell follows a proven style and approach. It reviews all of the topics needed to master each exam in a remarkably concise format, with required knowledge boiled down to the core. Instead of plowing through 500 to 700 pages to prepare for each exam, this book covers each one in approximately 150 pages. And because the objectives for the three elective A+ exams are redundant, and the book covers them in one section.

The exams covered include:

  • A+ Essentials: Required for A+ 2006 certification
  • EXAM 220-602: For the A+ IT Technician specialization
  • EXAM 220-603: For the A+ Remote Support Technician specialization
  • EXAM 220-604: For the A+ IT Depot specialization
  • EXAM N10-003: For Network+ Certification
  • EXAM SYO-101: For Security+ Certification


Each exam is covered in three parts: Exam Overview, Study Guide and Prep and Practice. Plenty of detailed tables and screen shots are included, along with study notes and practice questions. Once you have completed the exams successfully, you will find this all-in-one book to be a valuable reference to core administration and security skills.


Thursday, November 10, 2011

Security Issues in Wireless Technologies:: Bluetooth, MANET and WiMAX

Security Issues in Wireless Technologies:: Bluetooth, MANET and WiMAX Review



Due to the flexibility and mobility of wireless technologies; Bluetooth, Zig-bee, RFID, WiMAX etc. have become most commonly used medium of wireless communication. Although the demand of these technologies is rapidly increasing all over the world, very few of us are aware about the security issues related to them. A number of attacks is possible to make illegal access to our system if we do not know how to protect our system from intruders. This book focuses on security threats and countermeasures of Bluetooth, MANET and WiMAX. The readers will get to know about different types of attacks as well as preventive mechanisms. Some research questions are also identified that may be interesting to those who want to go for further study.


Saturday, November 5, 2011

Guide to Bluetooth security: recommendations of the National Institute of Standards and Technology

Guide to Bluetooth security: recommendations of the National Institute of Standards and Technology Review



Original publisher: Gaithersburg, MD : U.S. Dept. of Commerce, National Institute of Standards and Technology, [2008] OCLC Number: (OCoLC)712603834 Subject: Bluetooth technology. Excerpt: ... UIDE TO LUETOOTH ECURITY G B S 3. Bluetooth Security Features This section provides an overview of the security mechanisms included in the Bluetooth specifications to illustrate their limitations and provide a foundation for some of the security recommendations in Section 4. A high-level example of the scope of the security for the Bluetooth radio path is depicted in Figure 3-1. In this example, Bluetooth security is provided only between the mobile phone and the laptop computer, while IEEE 802.11 security protects the wireless local area network link between the laptop and the IEEE 802.11 AP. However, the communications on the wired network are not protected by Bluetooth or IEEE 802.11 security capabilities. End-to-end security is not possible without using higher-layer security solutions in addition to the security features included in the Bluetooth specification and IEEE 802.11 standards. Figure 3-1. Bluetooth Air-Interface Security The following are the three basic security services specified in the Bluetooth standard:�Authentication: verifying the identity of communicating devices. User authentication is not provided natively by Bluetooth.�Confidentiality: preventing information compromise caused by eavesdropping by ensuring that only authorized devices can access and view data.�Authorization: allowing the control of resources by ensuring that a device is authorized to use a service before permitting it to do so. The three security services offered by Bluetooth and details about the modes of security are described below. Bluetooth does not address other security services such as audit and non-repudiation; if such services are needed, they must be provided through additional means. 3-1


Wednesday, October 19, 2011

Securing the Smart Grid: Next Generation Power Grid Security

Securing the Smart Grid: Next Generation Power Grid Security Review



"The first step in securing the Smart Grid is to fully understand the threat landscape. This book provides both a timely and relevant overview of the subject - a must-read for anyone responsible for securing the grid as well as consumers looking to implement the technology!."-- Dr. Patrick Engebretson, Assistant Professor of Computer Security, Dakota State University.

"Easy to read and full of valuable information, this book provides a wide-eyed view of our future and the security challenges we will be facing in our day-to-day lives. Exploring everything from home systems to large-scale power plants, this is a must-read for everyone in our technological society."-- Thomas Wilhelm, ISSMP, CISSP, SCSECA, SCNA, SCSA, IEM, IAM

Smart Grids are the future of energy. By creating networks from power plant to home, utility companies will be able to regulate power consumption making sure that consumers are receiving the amount that is needed, no more or less. While this new use of networking technology and unique applications such as smart meters will help to conserve energy it also opens up a pipeline, that was regulated manually, into the computer world of interconnected networks. The infrastructure that is being built will need to have robust security as an attack on this network could create chaos to tens of thousands of power consumers, stop a utility company in its tracks, or be used in a cyberwar.

Securing the Smart Grid takes a look at grid security today, how it is developing and being deployed into now over 10 million households in the US alone. Direct attacks to smart meters as well as attacks via the networks will be detailed along with suggestions for defense against them. A framework for how security should be implemented throughout this growing system will be included directing security consultants, and system and network architects on how to keep the grid strong against attackers big and small.

  • Details how old and new hacking techniques can be used against the grid and how to defend against them

  • Discusses current security initiatives and how they fall short of what is needed

  • Find out how hackers can use the new infrastructure against itself

  • Saturday, October 15, 2011

    CMS Security Handbook: The Comprehensive Guide for WordPress, Joomla, Drupal, and Plone

    CMS Security Handbook: The Comprehensive Guide for WordPress, Joomla, Drupal, and Plone Review



    Learn to secure Web sites built on open source CMSs

    Web sites built on Joomla!, WordPress, Drupal, or Plone face some unique security threats. If you’re responsible for one of them, this comprehensive security guide, the first of its kind, offers detailed guidance to help you prevent attacks, develop secure CMS-site operations, and restore your site if an attack does occur. You’ll learn a strong, foundational approach to CMS operations and security from an expert in the field.

    • More and more Web sites are being built on open source CMSs, making them a popular target, thus making you vulnerable to new forms of attack
    • This is the first comprehensive guide focused on securing the most common CMS platforms: Joomla!, WordPress, Drupal, and Plone
    • Provides the tools for integrating the Web site into business operations, building a security protocol, and developing a disaster recovery plan
    • Covers hosting, installation security issues, hardening servers against attack, establishing a contingency plan, patching processes, log review, hack recovery, wireless considerations, and infosec policy

    CMS Security Handbook is an essential reference for anyone responsible for a Web site built on an open source CMS.


    Saturday, July 16, 2011

    Mobile Application Security

    Mobile Application Security Review



    Secure today's mobile devices and applications

    Implement a systematic approach to security in your mobile application development with help from this practical guide. Featuring case studies, code examples, and best practices, Mobile Application Security details how to protect against vulnerabilities in the latest smartphone and PDA platforms. Maximize isolation, lockdown internal and removable storage, work with sandboxing and signing, and encrypt sensitive user information. Safeguards against viruses, worms, malware, and buffer overflow exploits are also covered in this comprehensive resource.

    • Design highly isolated, secure, and authenticated mobile applications
    • Use the Google Android emulator, debugger, and third-party security tools
    • Configure Apple iPhone APIs to prevent overflow and SQL injection attacks
    • Employ private and public key cryptography on Windows Mobile devices
    • Enforce fine-grained security policies using the BlackBerry Enterprise Server
    • Plug holes in Java Mobile Edition, SymbianOS, and WebOS applications
    • Test for XSS, CSRF, HTTP redirects, and phishing attacks on WAP/Mobile HTML applications
    • Identify and eliminate threats from Bluetooth, SMS, and GPS services

    Himanshu Dwivedi is a co-founder of iSEC Partners (www.isecpartners.com), an information security firm specializing in application security. Chris Clark is a principal security consultant with iSEC Partners. David Thiel is a principal security consultant with iSEC Partners.


    Saturday, June 4, 2011

    COMPUTER GURU SECURITY GUIDE: How to Protect Your Computer, Your Mobile Devices & Your Information On & Off the Internet

    COMPUTER GURU SECURITY GUIDE: How to Protect Your Computer, Your Mobile Devices & Your Information On & Off the Internet Review



    COMPUTER GURU SECURITY GUIDE – available on this site in editions for a PC, Mac, Kindle, iPad, iPhone, BlackBerry or Android.

    Easy, essential (but often overlooked) security for everyone using computers, cellphones or other tech tools:

    Do you know how to protect the privacy of your emails, bank transactions and your office work while working wirelessly on your laptop in public (e.g., at a café, library, hotel or airport)?

    Do you know how to set up a simple, secure wireless network?

    Do you know how to protect yourself when using Bluetooth?

    Do you know how easy it is to backup and disaster-proof your computers?

    You can learn all this and much more for under and in just 50 pages with the COMPUTER GURU SECURITY GUIDE. This e-book shows you how to protect yourself, your computer and your mobile devices—on and off the Internet.


    Praise for the acclaimed TEACH YOUR COMPUTER TO DANCE paperback book by Don Silver and Susan Silver:

    You can pick any page at random and find yourself saying, that’s a good idea. -- Andrew Kantor, Technology Columnist, USA TODAY

    I learned something new on almost every page. -- Andrew Blackman, Reporter, The Wall Street Journal

    Great book for the computer genius or novice. It's a must-have book for people of all professions. -- Rochelle Stewart, The Boston Herald

    I like this book a lot. It’s written by people who know what they’re talking about and who are up on the latest PC and Internet technologies. --Jonathan Zittrain, Professor of Internet Governance and Regulation, Oxford University, and Co-Founder of Harvard Law School’s Berkman Center for Internet & Society

    Highly recommended for all computer users. Full of practical tips and sound advice presented in an easy-to-read format. -- Suzi Turner, Spyware Researcher and Consultant, owner of SpywareWarrior.com and writer of the Spyware Confidential blog, ZDNet.com

    Has dozens of expert tips for securing your computing experience. It also contains a ton of great advice for readers of any level. -- Roger A. Grimes, Security Adviser Columnist, InfoWorld, and author of four books on computer security

    TABLE OF CONTENTS of the COMPUTER GURU SECURITY GUIDE

    1 The Dangers Out There

    Mobile Devices Warning

    Mac Warning

    Printer and Photocopier Warning

    Privacy Warning

    Wireless Warning

    Malware

    Protecting Yourself



    2 Lowering Your Profile and Risks

    How to Lower Your Internet Profile

    Make Your Social Networking Settings More Private

    Restrict Remote Access and Control

    Do More Private Browsing on the Internet

    Set Up Your Internet Security and Privacy Levels

    More Secure Sites for Your Sensitive Data

    Be Careful How You Answer Website Security Questions

    Cookies, Flash Cookies and Beacons

    Restricting Bluetooth Broadcasting

    How Bluetooth Works

    The Dangers of Bluetooth

    19 Ways to Better Protect Yourself When Using Bluetooth Passwords

    File Sharing and Access to Information

    Security Issues with Desktop Search Programs

    Security Issues with Search Engines

    Leaving No Traces While Out

    Keep from Getting Burned at Hot Spots

    Email at Hot Spots

    Turn Your USB Drive into a Stealth Drive

    Routers

    Wireless Routers and Networks

    Make Your Wireless Router More Secure

    Encryption

    Lowering Your Risks Off the Internet



    3 Arming Your Computer

    Software Firewall

    Software Updates

    Weekly Disaster-Prevention Program

    More Disaster Prevention/Recovery Strategies

    Index