CERT Announcements
Technical Note on Foreign Involvement in Insider Intellectual Property Theft Released
This entry in the Spotlight On series summarizes such cases and insiders and provides recommendations for mitigating these incidents.
New Blog Post: Keep Calm and Deploy EMET
This blog post provides information about an effective approach to blocking exploits of CVE-2013-1347, the Internet Explorer 8 CGeneric Element object use-after-free vulnerability.
New Blog Entry: Controlling the Malicious Use of USB Media
This blog post explains the importance of protecting your organization from the theft of sensitive information using USB media.
New Blog Entry: Don't Sign that Applet!
This blog post describes how Oracle's new guidance for Java applets may cause more harm than good.
New Blog Entry: Finding Patterns of Malicious Use in Bulk Registrations
This blog post describes how finding patterns in bulk registrations can help identify potentially malicious domains.
GeoIP in Your SOC (Security Operations Center)
This blog entry describes how to use geoIP to view data and help your network situational awareness.
New Blog Entry: Second Level Domain Usage in 2012 for Common Top Level Domains
This blog post looks at second level domain usage in 2012 for the most common generic Top Level Domains.
New Book Released: Secure Coding in C and C++, Second Edition
This book identifies the root causes of today's most widespread software vulnerabilities, shows how they can be exploited, reviews the potential consequences, and presents secure alternatives.
New Blog Entry: The Growth of IPv6 Announcements
This blog post presents a method for assessing how popular IPv6 is on the internet.
New Blog Entry: An Alternate View of Announced IPv4 Space
This blog post describes an alternate way to view advertised IP address space on the internet using publicly available information.
Justification of a Pattern for Detecting Intellectual Property Theft by Departing Insiders Released
This technical note describes an analysis of the pattern "Increased Review for Intellectual Property (IP) Theft by Departing Insiders," which helps organizations mitigate the risk of insider theft of IP.
New Blog Entry: The Growth Rate of IP Addresses That Are Advertised as Usable on the Internet
This blog post describes how you can calculate the growth rate of advertised IP address space on the internet using publicly available information.
New Blog Entry: How Ontologies Can Help Build a Science of Cybersecurity
This blog post introduces you to work done on an ontology for malware.
New Blog Entry: Watching Domains That Change DNS Servers Frequently
This blog entry describes the results of our three-month study of domains that change their name servers frequently.
Malware Analysis Lexicon Released
This technical note presents the first common vocabulary for malware analysis.
New Blog Entry: CERT Insider Threat Events at the RSA Conference
This blog entry provides you with an opportunity to meet members of the CERT Insider Threat Center at the RSA Conference and describes events supported by these members at the conference.
New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 19 (of 19)
This last of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 19: Close the doors to unauthorized data exfiltration.
New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 18 (of 19)
This eighteenth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 18: Be especially vigilant regarding social media.
New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 17 (of 19)
This seventeenth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 17: Establish a baseline of normal network device behavior.
New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 16 (of 19)
This sixteenth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 16: Develop a formalized insider threat program.



