Handler's Diary
Provide free analysis and warning service to thousands of Internet users and organizations, and is actively working with Internet Service Providers to fight back against the most malicious attackers.
 
 
Daily Top 10
Listing of ports being scanned, source IPs scanning a particular target port and recommended block list
 
     
   
SecTools.Org
Voted Top 100 Network Security Tools
 
 
InSecure.Org
Nmap Free Security Scanner, Tools & Hacking Resources
 
     
   
K-Otik (French Security Survey)  
     
     
System Backup, Bare-Metal Recovery & Migration
Symantec LiveState Recovery combines the speed and reliability of disk-based, bare-metal Windows system recovery with hardware-independent restoration and lights-out operation
 
 
Continuous Data Protection
Symantec Backup Exec 10d provides comprehensive, cost-effective, and certified backup and recovery - including continuous data protection with multiple versions
 
 
   
Symantec Virus Protection Interactive Guide
This guide will help you to learn more about Symantec's latest Virus Protection Solutions

 
 
Cryptographic Standards and Applications
Focus is on developing cryptographic methods for protecting the integrity, confidentiality and authenticity of information resources
 
 
Security Testing
Focus is on working with government and industry to establish more secure systems and networks by developing, managing and promoting security assessment tools, techniques, services, and supporting programs for testing, evaluation and validation
 
 
Security Research / Emerging Technologies
Focus is on research necessary to understand and enhance the security utility of new technologies while also working to identify and mitigate vulnerabilities
 
 
Security Management and Guidance
Focus is on developing security management guidance, addressing such areas as: risk management, security program management, training and awareness
 
 
Outreach, Awareness and Education
Focus is on activities to support wider awareness of the importance and need for IT security, promoting the understanding of IT security vulnerabilities
 
     
   
Drafts
This page consists of draft NIST Publications (FIPS, Special Publications) that are either open for public review and to offer comments, or the document is waiting to be approved as a final document by the Secretary of Commerce.
 
ITL Bulletins
ITL Bulletins are published by NIST's Information Technology Laboratory, with most bulletins written by the Computer Security Division. These bulletins are published on the average of six times a year. Each bulletin presents an in-depth discussion of a single topic of significant interest to the information systems community. Not all of ITL Bulletins that are published relate to computer / network security. Only the computer security ITL Bulletins are found here. There is a link provided on this page to get non-computer security ITL Bulletins.
 
Federal Information Processing Standards Publications (FIPS PUBS)
FIPS publications are issued by NIST after approval by the Secretary of Commerce pursuant to Section 5131 of the Information Technology Reform Act of 1996, Public Law 104-106, and the Computer Security Act of 1987 (Public Law 100-235).
 
Special Publications
Special Publications in the 800 series present documents of general interest to the computer security community. The Special Publication 800 series was established in 1990 to provide a separate identity for information technology security publications. This Special Publication 800 series reports on ITL's research, guidance, and outreach efforts in computer security, and its collaborative activities with industry, government, and academic organizations.
 
Interagency Reports
NIST Inteagency Reports (NISTIRs) describe research of a technical nature of interest to a specialized audience.
The series includes interim or final reports on work performed by NIST for outside sponsors (both government and nongovernment). NISTIRs may also report results of NIST projects of transitory or limited interest, including those that will be published subsequently in more comprehensive form.
 
How to order NIST Publications
Order link - If CSRC does not have an electronic copy of the document you are looking for, this would be the page to go to get the information you need to order a copy.
 
History of Computer Security Project: Early Papers
This list of papers was initially distributed on CD-ROM at NISSC '98. These papers are unpublished, seminal works in computer security. They are papers every serious student of computer security should read. They are not easy to find. The goal of this collection is to make them widely available. This list was compiled by the Computer Security Laboratory of the Computer Science Department at the University of California, Davis.
 
Other Security Publications
This is a collection of computer security publications that the Computer Security Division received from various sources.
 
Rainbow Series
The rainbow series is a library of about 37 documents that address specific areas of computer security. Each of the documents is a different color, which is how they became to be refereed to as the Rainbow Series. The primary document of the set is the Trusted Computer System Evaluation Criteria (5200.28-STD, Orange Book), dated December 26, 1985. This document defines the seven different levels of trust that a product can achieve under the Trusted Product Evaluation Program (TPEP) within NSA. Some of the titles include, Password Management, Audit, Discretionary Access Control, Trusted Network Interpretation, Configuration Management, Identification and Authentication, Object Reuse and Covert Channels. A new International criteria for system and product evaluation called the International Common Criteria (ICCC) has been developed for product evaluations. The TCSEC has been largely superceded by the International Common Criteria, but is still used for products that require a higher level of assurance in specific operational environments. Most of the rainbow series documents are available on-line.
 
   
Scan for Security Risks (Test your computer's exposure to online security threats and learn how to make your computer more security) - About Scan for Security Risks
 
 
Scan for Viruses (Examine your computer using Symantec's award-winning virus detection technology to determine if it is infected by any known virus or Trojan Horse) - About Scan for Viruses
 
 
Trace a Potential Attack (Discover information about the network from which a potential attack originated and the geographical location of the computer that was used) - About Trace a Potential Attack  
 
   
Symantec Security Response (Latest virus threats, security advisories, virus definitions, updates, virus removal tools)
 
 
Distributed.net (Project in cracking RC5, CS, & DES)
 
 
ICSA Labs (A division of TruSecure Corporation in Internet Security Assurance)
 
 
OSVDB.Org
Open Source Vulnerability Database (OSVDB) is an independent and open source database created by and for the community. The goal is to provide accurate, detailed, current, and unbiased technical information.
 
     
   
Gibson Research Corporation (Free NanoProbe Technology Internet security testing for Windows users)
 
 
Microsoft Baseline Security Analyzer (Tool that scan Windows-based computers for common security misconfigurations)  
     
   
TruSecure Corporate (Formerly known as National Computer Security Association, NCSA)
 
 
Computer Security Institute (Provide education on practical, cost-effective ways to protect an organization's information assets)
 
 
International Computer Security Association, ICSA (Providing security assurance services for Internet connected companies)
 
 
Disaster Recovery Information Exchange (Providing information about protecting data against disaster)
 
 
Forum of Incident Response and Security Teams (Global organization established to foster cooperation and response coordination among computer security teams worldwide)
 
 
High Technology Crime Investigation Association (Providing information about technology crime)
 
 
Information Systems Audit and Control Association, ISACA (Worldwide member Association dedicated to IS Audit, Control and Security practitioners)
 
 
Information Systems Security Association, ISSA (International organization of information security professionals and practitioners)
 
 
British Security Industry Association (Professional trade association for the security industry in the UK)