Profile for Ben Rothke > Reviews

Browse

Ben Rothke's Profile

Customer Reviews: 413
Top Reviewer Ranking: 2,595
Helpful Votes: 3490




Community Features
Review Discussion Boards
Top Reviewers

Guidelines: Learn more about the ins and outs of Your Profile.

Reviews Written by
Ben Rothke "Information security professional" RSS Feed (USA)
(REAL NAME)   

Show:  
Page: 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11-20
pixel
Official (ISC)2® Guide to the CCFP CBK ((ISC)2 Press)
Official (ISC)2® Guide to the CCFP CBK ((ISC)2 Press)
by Peter Stephenson
Edition: Hardcover
Price: $65.95
14 used & new from $56.88

3.0 out of 5 stars Decent CCFP preparation resource, October 22, 2014
The Certified Cyber Forensics Professional (CCFP) is the latest certification from ISC2, creators of the CISSP certification.

The CCFP, like the CISSP, is built around a common body of knowledge (CBK) that includes established forensics disciplines as well as newer challenges, such as mobile forensics, cloud forensics, anti-forensics, and more.

For those looking for reference guide, the Official (ISC) 2 Guide to the CCFP CBK is one of two guides currently available. The other being the CCFP Certified Cyber Forensics Professional All-in-One Exam Guide by Chuck Easttom.

As to the Official (ISC) 2 Guide to the CCFP CBK, the book is written by experience cast of authors and contributors. While listed at 992 pages, a number of the chapters have large fonts, more akin to a large-print edition to accommodate people who have poor vision.

Some of the material has overlap given the numerous authors. It would be helpful if the material could also be better cross-referenced. But that is the difficulty of a reference text with many authors.

The book covers in depth the six CCFP domains of the CBK, namely:

• legal and ethical principles
• investigations
• forensic science
• digital forensics
• application forensics
• hybrid and emerging technologies

For the experienced forensics professional looking to get a handle on the content for the CCFP exam, the Official (ISC) 2 Guide to the CCFP CBK is a decent study guide, at least until something better comes along.


Hate Crimes in Cyberspace
Hate Crimes in Cyberspace
by Danielle Keats Citron
Edition: Hardcover
Price: $22.41
44 used & new from $17.78

2 of 2 people found the following review helpful
5.0 out of 5 stars A book that asks if the Internet brings out the worst in us. And creates a legal framework to deal with it., October 14, 2014
It’s said that criminal lawyers see bad people at their best, and divorce lawyers see good people at their worst. At times, the Internet seems to bring out the bad in all types of people.

In Hate Crimes in Cyberspace, a fascinating book just out, author Danielle Keats Citron details many incidents where unsuspecting and ordinary people suddenly found themselves under direct attack in the form of hateful emails, threats, prank calls, online bullying and more.

The irony is that in the cases she details, the victims were not the dregs of society or criminals, rather tech bloggers, law students and the like.

Citron notes a few times that in the early days of sexual harassment in the workplace, the common wisdom was that the victim was told that they should simply deal with it and go on with their lives. The current environment doesn’t blame the victim and every firm now has policies and programs to deal with workplace sexual harassment.

She writes that to a large part, law enforcement and the media has taken the approach that today’s victims of internet trolls should use the sticks and stones may break my bones, but names will never hurt me approach. But that gives little solace to victims of internet trolls who are living their lives in fear due to the many threats against them; from malicious impersonation, proxy stalking, rape and death threats and more.

The book deals with the question of if there is something about the Internet that fuels destructive cyber mobs and individual harassers. She asks if the Internet brings out the worst in us, and why.

She writes that women are more often the victims of cyber harassment then men. This week, Xeni Jardin wrote in Yet another female game dev targeted with credible threats after speaking out on sexism, Brianna Wu, developer of sci-fi action puzzler Revolution 60, had to leave their home due to a credible threat on Twitter.

An account spammed Wu with violent threats and made it clear that it was doing so because of her outspoken support of women in tech and gaming. The last tweet publicly published Wu’s home address. In response to that, she called the police, who came to her home.

On the other side, British woman who was a troll and lead a vicious campaign of online abuse against the parents of missing girl Madeleine McCann committed suicide last week, when her identity was uncovered by the news media.

To a large part, the anonymity of the net, the ability to cloak behind a sort of shield of invisibility, reduces peoples reason, and brings out their animalistic emotions. It is the anonymity that frees people to defy social norms, in addition to their physical separation, which exacerbates the tendency to act on destructive impulses.

Citron acknowledges that anonymity’s substantial costs must be understood in lights of its great benefits. The challenge is dealing with both.

The book details where law enforcement has told victim to simply disconnect from the Internet. But in 2014, that could mean loss of professional opportunities, self-expression and the like.

The first part of the book paints the bleak picture of how pervasive cyber harassment is. In the second part, Citron comes up with ideas in which the law can be used to both prevent and punish online harassment.

The author is an attorney and knows quite well that any attempt to quash trolling or hateful speech will run head first into the First Amendment. In fact, the defense of nearly every troll, racist, hatemonger and the like has been to justify their attacks in the name of free speech.

In chapter 6, Citron creates a framework in which laws can be created and updated to deal with the threat of Internet harassers. She is savvy enough to know a legal reform agenda won’t make the problem go away, as anonymizing technologies far outpace any law, and often defeats any regulation in its midst.

In chapter 8, she shows how her cyber civil rights legal agenda can survive First Amendment challenges. She notes that civil rights and sexual harassment laws didn’t destroy expression in the workplace, and that a legal agenda against cyber harassment and cyber stalking can balance civil rights and civil liberties for the good of each.

The only flaw in this book is its title. If these were really hates crimes, they would be offenses that were easily punishable. It’s Citron goal that those who stalk, abuse, upload revenge porn and the like, will one day find their actions criminal, and not simply protected speech.

Citron’s framework, or any other, even if it were to survive the endless legal challenges, is still years, if not a decade away from becoming law. Until then, the free-for-all of the Internet, along with its many trolls will be business as usual. The downside is that there is little defense Internet users have to protect themselves. As even if they don’t take compromising pictures of themselves, there are still plenty of malevolent trolls around to make their lives miserable.

Hate Crimes in Cyberspace is a compelling and important read. It’s also equally disheartening to read myriad stories of people whose actions are sometimes criminal, and often vicious and animalistic.


Targeted Cyber Attacks: Multi-staged Attacks Driven by Exploits and Malware
Targeted Cyber Attacks: Multi-staged Attacks Driven by Exploits and Malware
by Aditya K. Sood
Edition: Paperback
Price: $21.46
29 used & new from $21.45

2 of 2 people found the following review helpful
4.0 out of 5 stars Good intro to the topic, September 21, 2014
Targeted cyber attacks are for the most part the same as an APT (advanced persistent threat). It was last year's report on APT1 from Mandiant that brought this important information security topic to the forefront.

In Targeted Cyber Attacks: Multi-staged Attacks Driven by Exploits and Malware, authors Aditya Sood and Richard Enbody write that there are a few different definitions of what a targeted cyber attack is. They use the standard definition that it's a class of dedicated attacks that aim at a specific user, company or organization, with the intent to gain access to critical data in a stealthy manner. They also note that APT's are simply variants of targeted cyber attacks.

At 158 pages, the book provides a good introduction to the topic with significant amounts of background information. It provides a mid- to high-level overview of the topic.

For those looking for a good introduction to the topic, which can then lead them to a more comprehensive reference, Targeted Cyber Attacks: Multi-staged Attacks Driven by Exploits and Malware is a good place to start.

Note that Amazon has this being mislabeled as being in published in April 2010, when it was published in April 2014.


Maimonides: Life and Thought
Maimonides: Life and Thought
by Moshe Halbertal
Edition: Hardcover
Price: $30.98
60 used & new from $26.02

2 of 3 people found the following review helpful
5.0 out of 5 stars Much more than a biography, the definitive text to understand who Maimonides was., September 14, 2014
For those that want the basic biographical facts about the life of Moses Maimonides need go no further than Wikipedia. For that, they would get ‘Maimonides: Life’.

What Professor Moshe Halbertal offers in ‘Maimonides: Life and Thought ‘, a much more than a biographical overview, he gets in the very heart of who Maimonides was, by looking at the books and monographs he authored.

Halbertal explains how a work like the Mishneh Torah, Maimonides’ magnum opus was never written before his time, and how a similar work has not been written since. It’s only a Maimonidean scholar of the first rank like Halbertal who can so deftly explain why this work was a literary act unprecedented in the history of Jewish law. It is the Mishneh Torah and the other classic works that make Maimonides not simply a great figure, but a monumental one.

Halbertal does a superb job of describing the struggles Maimonides faced, both religiously and politically.

Chapter 1 is the obligatory overview of the life of Maimonides, while in the remaining 7 chapters, Halbertal explains why each of Maimonides works was necessary, the greatness behind it, and how each of them are still completely relevant.

The Guide for the Perplexed was the most esoteric of all of the writings of Maimonides. Halbertal does a fantastic job of describing the enormity of this work, and the various readings that can be ascribed to it.

Hagiographies of great figures are a dime a dozen. Yet this is a rare work of scholarship that is everything but a hagiography or basic memoir. In ‘Maimonides: Life and Thought‘, Moshe Halbertal has done an extraordinary job of providing the reader with an understanding and appreciation of who Maimonides was.


Architecting the Cloud: Design Decisions for Cloud Computing Service Models (SaaS, PaaS, and IaaS)
Architecting the Cloud: Design Decisions for Cloud Computing Service Models (SaaS, PaaS, and IaaS)
by Michael Kavis
Edition: Hardcover
Price: $35.79
61 used & new from $31.66

5 of 5 people found the following review helpful
5.0 out of 5 stars Extremely honest and enlightening book on how to effectively use the cloud, September 8, 2014
Most books about cloud computing are either extremely high-level quasi-marketing tomes (sometimes written by cloud vendors) about the myriad benefits of the cloud without any understanding of how to practically implement the technology under discussion. The other type of cloud books are highly technical references guides, that provide technical details, but for a limited audience.

In Architecting the Cloud: Design Decisions for Cloud Computing Service Models, author Michael Kavis has written perhaps the most honest book about the cloud available to date. Make no doubt about it; Kavis is a huge fan of the cloud. But more importantly, he knows what the limits of the cloud are, and how cloud computing is not a panacea. That type of candor makes this book an invaluable guide to anyone looking to understand how to effective deploy cloud technologies.

The book is an excellent balance of the almost boundless potential of cloud computing, mixed with a high amount of caution that the potential of the cloud can only be manifest with effective requirements and formal security architecture.

One of the mistakes of using the cloud is that far too many decision makers rush in, without understanding the significant differences (and they are significant) between the 3 main cloud service models.

In chapter 1, he provides a number of enthusiastic cloud success stories to set the stage. He shows how a firm was able to build a solution entirely on the public cloud with a limited budget. He also showcases Netflix, whose infrastructure is built on Amazon Web Services (AWS).

Chapter 3 is titled cloud computing worst practices and the book would be worth purchasing for this chapter alone. The author has a number of cloud horror stories and shows the reader how they can avoid failure when moving to the cloud. While many cloud success stories showcase applications developed specifically for the cloud, the chapter details the significant challenges of migrating existing and legacy applications to the cloud. Such migrations are not easy endeavors, which he makes very clear.

In the chapter, Kavis details one of the biggest misguided perceptions of cloud computing, in that it will greatly reduce the cost of doing business. That is true for some cloud initiatives, but definitely not all, as some cloud marketing people may have you believe.

Perhaps the most important message of the chapter is that not every problem is one that needs to be solved by cloud computing. He cites a few examples where not going with a cloud solution was actually cheaper in the long run.

The book does a very good job of delineating the differences between the various types of cloud architectures and service models. He notes that one reason for leveraging IaaS over PaaS, is that when a PaaS provider has an outage, the customer can only wait for the provider to fix the issue and get the services back online. With IaaS, the customer can architect for failure and build redundant services across multiple physical or virtual data centers.

For many CIO’s, the security fears of the cloud means that they will immediately write-off any consideration of cloud computing. In chapter 9, the author notes that almost any security regulation or standard can be met in the cloud. As none of the regulations and standard dictate where the data must specifically reside.

The book notes that for security to work in the cloud, firm’s needs to apply 3 key strategies for managing security in cloud-based applications, namely centralization, standardization and automation.

In chapter 10, the book deals with creating a centralized logging strategy. Given that logging is a critical component of any cloud-based application; logging is one of the areas that many firms don’t adequate address in their move to the cloud. The book provides a number of approaches to use to create an effective logging strategy.

The only significant issue I have with the book is that while the author is a big fan of Representational state transfer (REST), many firms have struggled to obtain the benefits he describes. RESTful is an abstraction of the architecture of the web; namely an architectural style consisting of a coordinated set of architectural constraints applied to components, connectors and data elements, within a distributed hypermedia system. REST ignores the details of component implementation and protocol syntax in order to focus on the roles of components, the constraints upon their interaction with other components, and their interpretation of significant data elements.

I think the author places too much reliance on RESTful web services and doesn’t detail the challenges in making it work properly. RESTful is not always the right choice even though it is all the rage in some cloud design circle.
While the book is part of the Wiley CIO Series, cloud architects, software and security engineers, technical managers and anyone with an interest in the cloud will find this an extremely valuable resource.

Ironically, for those that are looking for ammunition why the cloud is a terrible idea, they will find plenty of evidence for it in the book. But the reasons are predominantly that those that have failed in the cloud, didn’t know why they were there in the first place, or were clueless on how to use the cloud.

For those that want to do the cloud right, the book provides a vendor neutral approach and gives the reader an extremely strong foundation on which to build their cloud architecture.

The book lists the key challenges that you will face in the migration to the cloud, and details how most of those challenges can be overcome. The author is sincere when he notes areas where the cloud won’t work.

For those that want an effective roadmap to get to the cloud, and one that provides essential information on the topic, Architecting the Cloud: Design Decisions for Cloud Computing Service Models is a book that will certainly meet their needs.


The CERT® C Coding Standard, Second Edition: 98 Rules for Developing Safe, Reliable, and Secure Systems (2nd Edition) (SEI Series in Software Engineering)
The CERT® C Coding Standard, Second Edition: 98 Rules for Developing Safe, Reliable, and Secure Systems (2nd Edition) (SEI Series in Software Engineering)
by Robert C. Seacord
Edition: Paperback
Price: $48.42
51 used & new from $42.25

4 of 4 people found the following review helpful
5.0 out of 5 stars Don’t code in C without this invaluable reference, September 1, 2014
For those interested in secure coding, Robert Seacord of CERT is one of the main sources on the topic. Some of the notable books he has authored are:

• Secure Coding in C and C++
• Java Coding Guidelines: 75 Recommendations for Reliable and Secure Programs
• Modernizing Legacy Systems: Software Technologies, Engineering Processes, and Business Practices
• The CERT Oracle Secure Coding Standard for Java

Seacord’s latest is the CERT C Coding Standard: 98 Rules for Developing Safe, Reliable, and Secure Systems.

The book covers the entire core areas that every C programmer needs to know, including areas such as:
• characters and strings
• expressions
• integers
• floating point
• arrays
• memory management
• input/output
• declarations and initialization
• error handling
• concurrency

The rules in the book can be used in parallel to ensure code is C11 (ISO/IEC 9899:2011) compliant.

Each of the rules in the book has the same format: title, description, noncompliant code examples and compliant solutions.

Programmers that implement these coding standards will find short-term gains in that the coding mistakes that leads to critical application errors such as buffer overflows are now mitigated.

This book is meant as a desktop reference for those coding in C. If you have programmers coding in C, you want to ensure that this book is on their desktop,

The goal of the book and its rules is meant to develop safe, reliable, and secure systems. Anyone who wants to do that should read definitely be reading CERT C Coding Standard: 98 Rules for Developing Safe, Reliable, and Secure Systems.


Social Engineering in IT Security: Tools, Tactics, and Techniques
Social Engineering in IT Security: Tools, Tactics, and Techniques
by Sharon Conheady
Edition: Paperback
Price: $28.52
33 used & new from $15.90

4 of 4 people found the following review helpful
5.0 out of 5 stars Effective guide on which to build a social engineering testing program, August 21, 2014
When I first got a copy of Social Engineering in IT Security Tools, Tactics, and Techniques by Sharon Conheady, my first thought was that it likely could not have much that Christopher Hadnagy didn't already detail in the definitive text on the topic: Social Engineering: The Art of Human Hacking. Obviously Hadnagy thought differently, as he wrote the foreward to the book; which he found to be a valuable resource.

While there is overlap between the two books; Hadnagy takes a somewhat more aggressive tool-based approach, while Conheady's book takes a somewhat more passive, purely social approach to the topic. There are many more software tools in Hadnagy; while Conheady doesn't reference software tools until nearly half-way through the book.

This book provides an extensive introduction to the topic and details how social engineering has evolved through the centuries. Conheady writes how the overall tactics and goals have stayed the same; while the tools and techniques have been modified to suit the times.

Coming in at about 250 pages, the book finds a good balance between high-level details and actionable tactical things to execute on. Without getting bogged down in filler.

Since the social engineering tools and techniques only get better, the advantage Conheady's book has it that it details a lot that has changed in the 4 years since Hadnagy's book came out.

Conheady writes about mumble attacks, which are telephone-based social engineering attacks that are targeted at call center agents. The social engineer will pose as a speech-impaired customer or as a person calling on behalf of the speech-impaired customer. The goal of this method is to make the victims; in this case call center agents feel awkward or embarrassed and release the desired information. Given the pressure in which most call center agents are under; this is a simple yet highly effective attack.

Like Hadnagy, this also has a detailed social engineering test methodology. Conheady details a methodology with 5 stages: planning and target identification, research and reconnaissance, scenario creation, attack execution and exit, and reporting. She notes that one does not have to be a slave to the methodology, and it can be modified depending on the project.

Social engineering can often operate on the limit of what is legal and ethical. The author goes to great lengths to write what the ethical and legal obligations are for the tester.
The book is filled with lots of practical advice as Conheady is seasoned and experienced in the topic. From advice to dealing with bathrooms as a holding location, gaining laptop connectivity and more; she writes of the many small details that can make the difference between a successful social engineering test and a failed one.

The book also details many areas where the job of the social engineer is made easy based on poor security practices at the location. Chapter 7 details how many locations have access codes on doors often don't do much to keep social engineers out. Many doors have 4-character codes, and she writes that she has seen keypads where the combination numbers have been so worn down that you can spot them straightaway.

As noted earlier, the book focuses more on the human techniques of social engineering than on software tools. She does not ignore that tools and in chapter 9 provides a list of some of the more popular tools to use, including Maltego, Cree.py and others. She also has lists of other tools to use such as recording devices, bugging devices, phone tools and more.

With all those, she still notes that the cell phone is the single most useful item you can bring with you on a social engineering test. She writes that some of the many uses a cell phone has is to discourage challengers, fake a call to look busy, use the camera and more.

While most of the book is about how to execute a social engineering test, chapter 10 details how you can defend against social engineering. She notes that it is notoriously difficult to defend against social engineering because it targets the weakest link in the security chain: the end-user. She astutely notes that a firm can't simply roll out a patch and immunize its staff against the latest social engineering attack. Even though there are vendors who make it seem like you can.

The chapter also lists a number of indicators that a firm may be experiencing a social engineering attack.

Hadnagy's Social Engineering: The Art of Human Hacking is still the gold-standard on the topic. But Social Engineering in IT Security Tools, Tactics, and Techniques certainly will give it a run for the money.

Hadnagy's approach to social engineering is quite broad and aggressive. Conheady takes more of a kinder, gentler approach to the topic.

For those that are looking for an effective guide on which to build their social engineering testing program on, this certainly provides all of the core areas and nearly everything they need to know about the fundamentals of the topic.


Carry On: Sound Advice from Schneier on Security
Carry On: Sound Advice from Schneier on Security
by Bruce Schneier
Edition: Hardcover
Price: $22.04
66 used & new from $3.27

4 of 4 people found the following review helpful
5.0 out of 5 stars Schneier writes the playbook that Washington should have been following all along, August 11, 2014
Bruce Schenier has been called an information security rock star. If that’s the case, then Carry On: Sound Advice from Schneier on Security is his greatest hits collection 2008-2013.

The roughly 175 essays in the book represent a collection of articles Schneier wrote for this Crypto-Gram newsletter, his blog and other blogs, magazines, newspapers and other periodicals.

Some of the articles, such as the 2008 piece Chinese Cyberattacks: Myth of Menace are clearly dated. A number of the other articles are somewhat redundant in that they were written on the same topic for different audiences.

But the vast majority of the essays reveal Schneier’s insight and pragmatic approach, which makes this a most important book to read. You may not agree with Schenier on every point, but every point of his is well researched and defended. Personally, I think his approach to CCTV’s and public cameras as a method for crime reduction needs to be reviewed against current data on the topic.

Many of the essays show his deep frustration with Washington and the politics of security; which has resulted in creating a security theatre dealing with movie-plot threats. Billions of dollars have been spent in this area, with almost nothing to show for it.

Another premise of the book is that most people don’t understand how to deal with risk and end up worrying about things that pose very little risk to them; of which a large number of essays are dedicated to this topic. Schenier notes the fears people have of school shootings, child abduction, mass food poisonings and the like, all of which are extremely rare. They worry about these while being oblivious do automobile deaths, DUI deaths and similar, which pose real and daily risks.

When it comes to post-9/11 security, Schneier feels most of the time, money and effort has gone to waste, protecting against imaginary threats. He notes that two things have made airplane travel safe post 9/11, namely: reinforcing the cockpit door, and convincing passengers that they need to fight back. But having tens of thousands of clueless and incompetent TSA agents seizing water bottles and patting down wheelchair-bound grannies have done absolutely nothing to increase air safety.

The book is both fascinating and frustrating. Fascinating in that the book will open your eyes to how to deal with risk and security, and ultimately how to carry on. But frustrating in that those in Washington who have been trusted to do this, have rarely done it right.

In Carry On: Sound Advice from Schneier on Security, Schneier writes the playbook that Washington should have been following all along.


Introduction to Cyber-Warfare: A Multidisciplinary Approach
Introduction to Cyber-Warfare: A Multidisciplinary Approach
by Paulo Shakarian
Edition: Paperback
Price: $28.96
55 used & new from $28.10

1 of 1 people found the following review helpful
5.0 out of 5 stars Provides a great introduction to cyberwarfare, August 4, 2014
Cyberwarfare is a most controversial topic. At the 2014 MISTI Infosec World Conference, noted security curmudgeon Marcus Ranum gave a talk on Cyberwar: Putting Civilian Infrastructure on the Front Lines, Again. Be it the topic or Marcus being Marcus, a third of the participants left within the first 15 minutes. They should have stayed, as Ranum, agree with him or not, provided some riveting insights on the topic.

While a somewhat broad term, in Wikipedia, cyberwarfare (often called information warfare) is defined as politically motivated hacking to conduct sabotage and espionage. It is a form of information warfare sometimes seen as analogous to conventional warfare.

The authors define cyber war as an extension of policy by actions taken in cyber space by state or nonstate actors that either constitute a serious threat to a nation’s security or are conducted in response to a perceived threat against a nation’s security.

As to a book on the topic, for most readers, cyberwarfare is something that they may be victims of, but will rarely be an actively part of.

In Introduction to Cyber-Warfare: A Multidisciplinary Approach, authors Paulo Shakarian, Jana Shakarian and Andrew Ruef provide an excellent overview of the topic. The book takes a holistic, or as they call it multidisciplinary, approach to the topic. It looks at the information security aspect of cyberwarfare, as well the military, sociological and other aspects of the topic.

The book is divided into 3 parts and 13 densely packed and extremely well-researched and footnoted chapters, namely:
Part I: Cyber Attack
Chapter 2: Political Cyber Attack Comes of Age in 2007
Chapter 3: How Cyber Attacks Augmented Russian Military Operations
Chapter 4: When Who Tells the Best Story Wins: Cyber and Information Operations in the Middle East
Chapter 5: Limiting Free Speech on the Internet: Cyber Attack Against Internal Dissidents in Iran and Russia
Chapter 6: Cyber Attacks by Nonstate Hacking Groups: The Case of Anonymous and Its Affiliates

Part II: Cyber Espionage and Exploitation
Chapter 7: Enter the Dragon: Why Cyber Espionage Against Militaries, Dissidents, and Nondefense Corporations Is a Key
Component of Chinese Cyber Strategy
Chapter 8: Duqu, Flame, Gauss, the Next Generation of Cyber Exploitation
Chapter 9: Losing Trust in Your Friends: Social Network Exploitation
Chapter 10: How Iraqi Insurgents Watched U.S. Predator Video—Information Theft on the Tactical Battlefield

Part III: Cyber Operations for Infrastructure Attack
Chapter 11: Cyber Warfare Against Industry
Chapter 12: Can Cyber Warfare Leave a Nation in the Dark? Cyber Attacks Against Electrical Infrastructure
Chapter 13: Attacking Iranian Nuclear Facilities: Stuxnet

The book provides numerous case studies of the largest cyberwarfare events to date. Issues around China and their use of cyberwarfare constitute a part of the book. Chapter 7 details the Chinese cyber strategy and shows how the Chinese cyber doctrine and mindset is radically different from that of those in the west.

The book compares the board games of chess (a Western game) and Go (a Chinese game) and how the outcomes and strategies of the games are manifest in each doctrine.

The chapter also shows how the Chinese government outlawed hacking, while at the same time the military identified the best and most talented hackers in China, and integrated them into Chinese security firms, consulting organizations, academia and the military.

One of the more fascinating case studies details the cyber war against the corporate world from China. The book provides a number of examples and details the methodologies they used, in addition to providing evidence of how the Chinese were involved.

For an adversary, one of the means of getting information is via social networks. This is often used in parallel by those launching some sort of cyberwarfare attack. LinkedIn is one of the favorite tools for such an effort. The authors write of the dangers of transitive trust; where user A trusts user B, and user B trusts user C. Via a transitive trust, user A will then trust user C based simply on the fact that user B does. This was most manifest in the Robin Sage exercise.

This was where Thomas Ryan created a fictitious information security professional names Robin Sage. He used her fake identity and profile to make friends with others in the information security world, both commercial, federal and military and he was able to fool even seasoned security professionals. Joan Goodchild wrote a good overview of the experiment here.

In chapter 10, the book details how Iraqi insurgents viewed Predator drones video feeds. Woody Allen said that eighty percent of success is just showing up. In this case, all the insurgents had to do was download the feed, as it was being transmitted unencrypted. Very little cyberwarfare required.

When the drone was being designed, the designers used security by obscurity in their decision not to encrypt the video feed. They felt that since the Predator video feeds were being transmitted on frequencies that were not publically known, no access control, encryption or other security mechanisms would be needed.

The downside is that once the precise frequency was determined by the insurgency, in the case of the Predator drone, the Ku-band, the use of the SkyGrabber satellite internet downloader made it possible for them to effortless view the video feeds.

The only negative about the book is a minor one. It has over 100 pictures and illustrations. Each one states: for the color version of this figure, the reader is referred to the online version of the book. Having that after every picture is a bit annoying. Also, the book never says where you can find the online version of the book.

How good is this book? In his review of it, Krypt3ia said it best when he wrote: I would love to start a kickstarter and get this book into the hands of each and every moron in Congress and the House. The reality is that this book should indeed be read by everyone in Washington, as they are making decisions on the topic, without truly understanding it.

For most readers, this will be the book that tells them everyone they need to know that their congressman should know. Most people will never be involved with any sort of warfare, and most corporate information security professional will not get involved with cyberwarfare. Nonetheless, Introduction to Cyber-Warfare: A Multidisciplinary Approach is a fascinating read about a most important topic.


Security Awareness: Applying Practical Security in Your World
Security Awareness: Applying Practical Security in Your World
by Mark D. Ciampa
Edition: Paperback
Price: $77.38
62 used & new from $45.97

1 of 1 people found the following review helpful
4.0 out of 5 stars Good resource to add to any information security awareness program, July 22, 2014
Security awareness is a vital part of information security. Just how important is it? In September, the 10-day SANS Security Awareness Summit 2014 will cover every aspect of the topic.

For those that want to get an appreciation for the topic but can’t make it to Dallas for the Summit, Security Awareness: Applying Practical Security in Your World is a good resource for the reader that wants both an understanding of the theoretical awareness issues, and how to practically address them.

Author Mark Ciampa is a computer science professor Western Kentucky University with an expansive background on the topic.

The book has an awareness focus for Windows users. The reader is expected to be somewhat technical, and relatively comfortable with using Windows tools.

For those looking for a mid-level reference on the topic, a book that’s not too basic, and also not so broad, Security Awareness: Applying Practical Security in Your World is a good resource to add to any information security awareness program.


Page: 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11-20