SEARCH RESULTS
 
Showing 1-10 of 117 records
 
Expand article

Detect and fix 'Manager' access control list settings in Lotus Notes Domino

2008-04-17 10:19:43 by Andy Pedisich in WhatIs: Enterprise IT tips and expert advice
 
Many Lotus Notes database access control list (ACL) settings are configured by default to "Manager" level. Learn how to detect and fix this permissions issue
 
 
 
 
 
Expand article

Key Indicators (KIs) Versus Key Performance Indicators (KPIs)

2008-01-31 08:54:15 by Tim Bass in The Complex Event Processing Blog
 
...detect both opportunities and threats in real-time with minimal coding and reusable key performance indicators (KPIs) and business models I agree with SL, but would like to suggestmy friends at SLexpandthe notion of KPIs in CEP to include the idea of KIs. In my opinion, the SL phrase shouldread, technology that is used to help companies...
 
 
 
 
 
Expand article

A breach that hits home with 2008 presidential candidates

The Article has images
2008-03-22 13:16:50 by Evan Francen in The Breach Blog
...detected by internal State Department computer checks because certain records, including those of high-profile people, are "flagged" with a computer tag that tips off supervisors when someone tries to view the records without a proper reason Evan] Excellent. It is good practice to log access attempts (successful and not) to confidential...
 
 
 
 
 
Expand article

Software Security Metrics and Commentary - Part 2

2007-10-23 20:31:00 by Security Retentive in Security Retentive
 
...detect tainted input and have a set of untrusted input functions (things that read from sockets, stdin, etc). It should be relatively straightforward to model our own application-specific output functions to detect where we're handing unchecked/unfiltered input to an output routine, potentially those across a trust boundary. If we can model...
 
 
 
 
 
Expand article

Spam Filtering: Understanding SEP and CEP

2008-04-14 04:56:52 by Greg Reemler in The Complex Event Processing Blog
 
...detecting spam was performed with rule-based systems. In fact, here is a link to one of the first papers that documented rule-based approaches in spam filtering, E-Mail Bombs and Countermeasures: Cyber Attacks on Availability and Brand Integrity published in IEEE Network Magazine, Volume 12, Issue 2, p.10-17 (1998). At the time, rule-based...
 
 
 
 
 
Expand article

Lessons learned from the massive SQL injection attacks against legacy Microsoft ASP apps

The Article has images
2008-07-08 14:32:33 by Chenxi Wang in Security & Risk Management
...detection tool to detect your vulnerabilities. You can download Scrawlr here https://download.spidynamics.com/products/scrawlr We'll be back with another edition of how important application security is to business today. Stay tuned
 
 
 
 
 
Expand article

Employee fraud at Wells Fargo Home Mortgage affects some customers

The Article has images
2008-07-08 12:58:12 by Evan Francen in The Breach Blog
...detect). Most controls are largely administrative in nature such as background checks, segregation of duties, job rotation, policy and procedure, etc. Sometimes even the best controls won't do much to prevent an attack from the enemy within We have taken appropriate action against this individual Evan] I wonder what this means We have no...
 
 
 
 
 
Expand article

The top 10 spam characteristics (#6-10)

2006-09-27 06:01:03 by Administrator in Email security & compliance blog
 
...detect spam. Remember that these spam characteristics must not be used in isolation, since some characteristics can also be present in legitimate mails. Therefore it is important to use a weighting system that provides an individual score for each spam characteristic. If a message includes several spam characteristics and reaches a spam...
 
 
 
 
 
Expand article

Microsoft Hits Back at Atsiv

2007-08-02 22:17:32 by Editor in Cheap Hack
 
...detect Atsiv, at least the current version of it. Source for Atsiv is supposedly available (although I didn't see a link for it on the Linchpin Labs site), so it should be possible to write a new version that Defender won't detect if you're looking forward to losing your own code-signing certificate. The blog also confirmsI thinkmy fear that...