CERT

CERT/CC Blog


2011 Archives

Challenges in Network Monitoring above the Enterprise

Recently George Jones, Jonathan Spring, and I attended USENIX Security '11. We hosted an evening Birds of a Feather (BoF) session where we asked a question of some significance to our CERT® Network Situational Awareness (NetSA) group:

Is Large-Scale Network Security Monitoring Still Worth Effort?


Continue reading Challenges in Network Monitoring above the Enterprise

Signed Java and Cisco AnyConnect

A few years ago, I published a blog entry called Signed Java Applet Security: Worse than ActiveX? In that entry, I explained the problems that arise when a vulnerability is discovered in a signed Java applet. Let's see how the Cisco AnyConnect vulnerability is affected.


Continue reading Signed Java and Cisco AnyConnect

Effectiveness of Microsoft Office File Validation

Microsoft recently released a component for Office called Office File Validation that is supposed to help protect against attacks using malformed files. Because I recently performed file fuzzing tests on Microsoft Office, I decided to test the effectiveness of Office File Validation.


Continue reading Effectiveness of Microsoft Office File Validation

A Security Comparison: Microsoft Office vs. Oracle Openoffice

Recently, Dan Kaminsky published a blog entry that compared the fuzzing resiliency of Microsoft Office and Oracle OpenOffice. This blog entry contains the results from a similar test that I performed in November 2010. Also included are some other aspects of the Office suites that can affect the software's security.


Continue reading A Security Comparison: Microsoft Office vs. Oracle Openoffice

Announcing the CERT Basic Fuzzing Framework 2.0

Version 2.0 of the CERT Basic Fuzzing Framework (BFF) made its debut on Valentine's Day at the 2011 CERT Vendor Meeting in San Francisco. This new edition has a lot of cool features that we'll be describing in more detail in future posts, but we wanted to let you know that it's available so that you can download and try it.


Continue reading Announcing the CERT Basic Fuzzing Framework 2.0

"Network Monitoring for Web-Based Threats" released

The CERT Network Situational Awareness (NetSA) team, specifically our talented and hard-working intern Matthew Heckathorn under Sid Faber's guidance, has published an SEI Technical Report on monitoring web-based threats.


Continue reading "Network Monitoring for Web-Based Threats" released

Blog reorganization

Hi, folks. As you can see, we've changed the name of the Vulnerability Analysis Blog to the CERT/CC Blog. With this name change, we're expanding the focus of the blog to include content from other technical teams.


Continue reading Blog reorganization