The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

Reports and Papers Archive


Browse All Papers »       Submit A Paper »

XGobi: Interactive Dynamic Data Visualization in the X Window System

D.F. Swayne,D. Cook,A. Buja
Added 2002-07-26

Designing Secure Software

P. Galvin

This month Peter turns a jaundiced eye towars the sorry state of software development. Specifically what are the flaws that cause the industry to turn out program after program with security holes. What are Companies like Sun doing to correct the problem? What should they be doing? The answer: Peter’s own Software Development Security Design Methodology.

Added 2002-07-26

UNIX Computer Security Checklist

Australian Computer Emergency Response Team
Added 2002-07-26

Aspect Oriented Programming

Xerox Corporation
Added 2002-07-26

The Changing Environment for Security Protocols

R.M. Needham
Added 2002-07-26

Blocking JAVA Applets at the Firewall

D.M. Marint Jr.,S. Rajagopalan

This paper explores the problem of protecting a site on the internet against hostile external JAVA applets while allowing trusted internal applets to run . With careful implemnetation, a site can be made resistant to current JAVA security weaknesses as well as those yet to be discovered. In addtion, we describe a new attack on certain sophisticated firewalls that is most efeectively realized as a JAVA applet.

Added 2002-07-26

Taking Computers to Task

W.W. Gibbs
Added 2002-07-26

Inventing the Internet Again

G. Gilder
Added 2002-07-26

Concept-Systems Catalogue

F. Lehmann
Added 2002-07-26

A Taxonomy for Key Escrow Encryption Systems

D.E. Denning,D.K. Branstad
Added 2002-07-26

A Taxonomy of Software Development Methods

B.I. Blum
Added 2002-07-26


Medical Devices: The Therac-25

N. Leveson
Added 2002-07-26

Rethinking the Taxonomy of Fault Detection Techniques

M. Young,R.N. Taylor

The convetional classification of software fault detection techniques as staticor dynamic analysis is inadequate as a basis for identifying useful relationships between techniques. A more useful distinction is between techniques that sample the space of possible new execuations, and techniques that fold the space. The new distinction provides better insight into the ways different techniques can interact. and is a basis for considering hybrid fault detection techniques including combinations of testing and formal verification.

Added 2002-07-26

The Case Against C

P.J. Moyan

The programming language C has been in widespread use since the early 1970s, and is it probably the language most widely used by computer science professionals. The goal of this paper is to argue that it is time to retire C in favour of a more modern language. The choice of a programming langauge is often an emotional issue which is not the subject of rational discussion. Nevertheless it is hoped to show here that there are good objective reasons why C is not a good choice for large programming projects. These reasons are related primarily to the issues of software readability and programmer productivity.

Added 2002-07-26