SEARCH RESULTS
 
Showing 1-10 of 78 records
 
Expand article

Why Some Terrorist Attacks Succeed and Others Fail

2008-02-28 06:25:13 by schneier in Schneier on Security
 
...Failure of Terrorist Attacks: Selected Case Studies " (Homeland Security Institute, June 2007), the authors examine eight recent terrorist plots against commercial aviation and passenger rail, and come to some interesting conclusions From the "Executive Summary": The analytic results indicated that the most influential factors determining the...
 
 
 
 
 
Expand article

Real Fail-over for VMs

2008-03-31 06:38:20 by Editor in Computerworld Security News
 
Mark Hall reports on a product that promises fail-over protection for virtual servers
 
 
 
 
 
Expand article

High Availability Security In Your Virtual Environment

The Article has images
2008-03-12 21:41:15 by John Peterson in Security In The Virtual World
...failure mechanisms in them. Customers demanded "Fail Open". Fail Open to a security guy doesn't make a whole lot of sense because it basically says, if there is a problem with the metal detector at the airport, it should just "Fail Open" and let everyone into the gate area to board airplanes I'd rather block all traffic until I know it was...
 
 
 
 
 
Expand article

High Availability Security In Your Virtual Environment

The Article has images
2008-03-12 21:41:15 by John Peterson in Security In The Virtual World
...failure mechanisms in them. Customers demanded "Fail Open". Fail Open to a security guy doesn't make a whole lot of sense because it basically says, if there is a problem with the metal detector at the airport, it should just "Fail Open" and let everyone into the gate area to board airplanes I'd rather block all traffic until I know it was...
 
 
 
 
 
Expand article

Mashup of the Titans

2008-06-25 17:29:25 by Gunnar Peterson in 1 Raindrop
 
...Fail-safe defaults: Base access decisions on permission rather than exclusion. This principle, suggested by E. Glaser in 1965,8 means that the default situation is lack of access, and the protection scheme identifies conditions under which access is permitted. The alternative, in which mechanisms attempt to identify conditions under which...
 
 
 
 
 
Expand article

The Security Mindset

2008-03-25 05:27:19 by schneier in Schneier on Security
 
...fail. It involves thinking like an attacker, an adversary or a criminal. You don't have to exploit the vulnerabilities you find, but if you don't see the world that way, you'll never notice most security problems I've often speculated about how much of this is innate, and how much is teachable. In general, I think it's a particular way of...
 
 
 
 
 
Expand article

The Security Mindset

2008-03-25 05:27:19 by schneier in Schneier on Security
 
...fail. It involves thinking like an attacker, an adversary or a criminal. You don't have to exploit the vulnerabilities you find, but if you don't see the world that way, you'll never notice most security problems I've often speculated about how much of this is innate, and how much is teachable. In general, I think it's a particular way of...
 
 
 
 
 
Expand article

IPS - is it soup yet? Mike Chapple says yes and no

The Article has images
2008-05-13 20:25:13 by HASH0x84725a8 in StillSecure, After All These Years
...failure. Being smart about which rules are set and grouping attacks to trigger a minimum amount of rules is key. I have seen rule sets where one kind of attack can trigger multiple signatures. This will fire more blocks than necessary and burden your system for no reason. Don't overlap your rule sets if you are using Snort Consider using a...
 
 
 
 
 
Expand article

Clever Museum Theft

2008-06-06 05:04:38 by schneier in Schneier on Security
 
...fail during the heist and that the construction of the building's layout did not compromise security Um, isn't having stuff get stolen the very definition of security failing? And does anyone have any idea how "elaborate computer program printouts" can determine that security didn't fail? What in the world is this guy talking about A few days...
 
 
 
 
 
Expand article

Software Security Metrics and Commentary - Part 2

2007-10-23 20:31:00 by Security Retentive in Security Retentive
 
...fails catastrophically Unlike other engineering disciplines, we don't know how to get to certainty about the strength of a piece of software. I won't disagree with either of these points, but to an extent you can say this about all new technologies. We've had catastrophic failures in physical engineering before as well. Old materials fail in...