<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cyber.harvard.edu/cybersecurity/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=WikiSysop</id>
	<title>Cybersecurity Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://cyber.harvard.edu/cybersecurity/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=WikiSysop"/>
	<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/Special:Contributions/WikiSysop"/>
	<updated>2026-08-10T02:05:15Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Page_for_Draft_Bibliographic_Entries&amp;diff=6374</id>
		<title>Page for Draft Bibliographic Entries</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Page_for_Draft_Bibliographic_Entries&amp;diff=6374"/>
		<updated>2012-06-06T14:30:52Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Aisenberg, Nichael A.||||2010||[[The Information Technology Supply Chain]]||Journal Article||None||[http://www2.americanbar.org/sections/scitech/ST230002/PublicDocuments/INFORMATION%20SECURITY%20PRIVACY%20NEWS%20-%20volume%201%20issue%202.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Page_for_Draft_Bibliographic_Entries&amp;diff=6373</id>
		<title>Page for Draft Bibliographic Entries</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Page_for_Draft_Bibliographic_Entries&amp;diff=6373"/>
		<updated>2012-06-06T14:30:20Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Aisenberg, Nichael A.||||2010||[[The Information Technology Supply Chain]]||Journal Article||ABA Information Security Quarterly||None||[http://www2.americanbar.org/sections/scitech/ST230002/PublicDocuments/INFORMATION%20SECURITY%20PRIVACY%20NEWS%20-%20volume%201%20issue%202.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Page_for_Draft_Bibliographic_Entries&amp;diff=6372</id>
		<title>Page for Draft Bibliographic Entries</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Page_for_Draft_Bibliographic_Entries&amp;diff=6372"/>
		<updated>2012-06-06T14:29:58Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Aisenberg, Nichael A.||2010||[[The Information Technology Supply Chain]]||Journal Article||ABA Information Security Quarterly||None||[http://www2.americanbar.org/sections/scitech/ST230002/PublicDocuments/INFORMATION%20SECURITY%20PRIVACY%20NEWS%20-%20volume%201%20issue%202.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Page_for_Draft_Bibliographic_Entries&amp;diff=6371</id>
		<title>Page for Draft Bibliographic Entries</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Page_for_Draft_Bibliographic_Entries&amp;diff=6371"/>
		<updated>2012-06-06T14:28:04Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Aisenberg, Nichael A.||2010||[[The Information Technology Supply Chain]]||Journal Article||ABA||None||[http://www2.americanbar.org/sections/scitech/ST230002/PublicDocuments/INFORMATION%20SECURITY%20PRIVACY%20NEWS%20-%20volume%201%20issue%202.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Page_for_Draft_Bibliographic_Entries&amp;diff=6370</id>
		<title>Page for Draft Bibliographic Entries</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Page_for_Draft_Bibliographic_Entries&amp;diff=6370"/>
		<updated>2012-06-06T14:27:24Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Aisenberg, Nichael A.||2010||[[The Information Technology Supply Chain]]||Journal Article||None||[http://people.seas.harvard.edu/~tmoore/science-econ.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Adding_a_Reference&amp;diff=6344</id>
		<title>Adding a Reference</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Adding_a_Reference&amp;diff=6344"/>
		<updated>2011-06-29T14:38:55Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;To add a new bibliographic reference entry:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== 1. Research the Reference ===&lt;br /&gt;
Search for information on the reference including links to accessible copies online, reviews, &lt;br /&gt;
discussions and/or the web site of the author or sponsor. &lt;br /&gt;
&lt;br /&gt;
=== 2. Create a BibTex Entry for the reference ===&lt;br /&gt;
Next create the BibTeX entry for the reference.  (See [[Guidelines for adding Bibliography entries]].)&lt;br /&gt;
&lt;br /&gt;
=== 3. Create a blank Wiki page for the reference ===&lt;br /&gt;
To do this within the wiki format, you need to choose an existing page to create the link on.  Normally, you will enter the reference into the listing of all references on the [[Cybersecurity Annotated Bibliography]].  Enter a new table entry in the correct alphabetical order by first (if more than one) author&#039;s last name (see next paragraph). The initial entry does not have to be complete (since some information will not yet be available such as level of expertise), however leave blank table entries (&amp;quot;|  |&amp;quot;) for missing data.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The title of the new reference page will normally be the short version of the reference title.&#039;&#039;&#039;  For &lt;br /&gt;
example, if the title of the reference is &amp;quot;&#039;&#039;Pricing Security: Vulnerabilities as Externalities&#039;&#039;,&amp;quot; &lt;br /&gt;
the page will be named [[Pricing Security]].  The exception will be where that page already exists &lt;br /&gt;
([[Cyberwar]] for example), in which case you will need to include the subtitle (or some other distinguishing text) to create a unique page name.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Click on your newly created link.&#039;&#039;&#039; This should open a blank editing page (if it does not then you need to &lt;br /&gt;
come up with a new unique page name).  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Copy and paste&#039;&#039;&#039; the contents of the [[TemplateForSources | sample template]] &lt;br /&gt;
or some other reference page similar to the new reference into the newly created page.  You should &lt;br /&gt;
copy the &#039;&#039;source&#039;&#039; of the template (by selecting the &amp;quot;edit&amp;quot; tab) rather than the displayed page text.&lt;br /&gt;
&lt;br /&gt;
=== 4. Begin editing the template ===&lt;br /&gt;
(Note: You may find it easier to enter all the template information except for &amp;quot;Categorization&amp;quot; and &amp;quot;Keywords,&amp;quot; then go back and complete these two sections last.)&lt;br /&gt;
&lt;br /&gt;
==== 4.1 Full Title of Reference ====&lt;br /&gt;
The &amp;quot;Full Title of Reference&amp;quot; should contain both the main title and any subtitle separated by a colon.&lt;br /&gt;
&lt;br /&gt;
E.g, Even though the wiki reference page is [[Four Grand Challenges in Trustworthy Computing]], the full title would be &amp;quot;Four Grand Challenges in Trustworthy Computing: Second in a Series of Conferences on Grand Research Challenges in Computer Science and Engineering.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== 4.2 Full Citation ====&lt;br /&gt;
The full citation should consists of the bluebook formatted citation for the reference followed by a link to&lt;br /&gt;
the full text of the reference if available labeled as &#039;&#039;Web&#039;&#039; or &#039;&#039;SSRN&#039;&#039; depending on whether the link goes directly to the &lt;br /&gt;
text or to an intermediate SSRN page.  This link should appear on the same line as the citation.  If there is a second&lt;br /&gt;
source for the full text of the reference, it should follow, labled as &#039;&#039;AltWeb&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
(An example of the use of &#039;&#039;AltWeb&#039;&#039; is available at [[Why Information Security is Hard]].)&lt;br /&gt;
&lt;br /&gt;
(An example of the use of &#039;&#039;SSRN&#039;&#039; is available at [[Overcoming Impediments to Information Sharing]].)&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;Web&#039;&#039;, &#039;&#039;AltWeb&#039;&#039;, &#039;&#039;SSRN&#039;&#039;, &#039;&#039;BibTex&#039;&#039; all are italicized.&lt;br /&gt;
&lt;br /&gt;
On a separate line (place one blank line after the citation to force the Wiki to line space), put the following as applicable:&lt;br /&gt;
&lt;br /&gt;
* A link to the &#039;&#039;BibTeX&#039;&#039; entry for the reference (this should show only a single BibTeX entry in detail format - e.g. [http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=DoD:2007 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
* A link to the &#039;&#039;Google Book&#039;&#039;s entry for the reference, e.g., [http://books.google.com/books?id=ILaY4jBWXfcC&amp;amp;dq=Security+Engineering&amp;amp;ei=1NFRTNz5KJeMygTr6dDqBQ&amp;amp;cd=1 &#039;&#039;Google Books&#039;&#039;]  (This can often be found in the BibTeX entry.)&lt;br /&gt;
&lt;br /&gt;
* A link to the &#039;&#039;WorldCat&#039;&#039; entry for the reference, e.g., [http://www.worldcat.org/title/security-engineering-a-guide-to-building-dependable-distributed-systems-second-edition/oclc/639194438&amp;amp;referer=brief_results &#039;&#039;World Cat&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
* A link to &#039;&#039;Amazon&#039;&#039;.com&#039;s page for the reference (since this often contains useful reviews and other information about the work), e.g, [http://www.amazon.com/Security-Engineering-Building-Dependable-Distributed/dp/0470068523/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1280430777&amp;amp;sr=8-1 &#039;&#039;Amazon&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
(See [[Security Engineering]] for an example that contains all of these links.)&lt;br /&gt;
&lt;br /&gt;
==== 4.3 Categorization ====&lt;br /&gt;
Note: &#039;&#039;Categories refer to the major themes of the reference.&#039;&#039;  If the reference only mentions a category in passing but does not focus on it, then it need not be included.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Create links to the appropriate categories for the reference.&#039;&#039;&#039;  When you add a link to a category to the reference page, you must also place a link back to the reference page &lt;br /&gt;
into the [[Table of Contents]] page for that category and &#039;&#039;every Table of Contents page higher in the hierarchy&#039;&#039;.  So, for example, if you categorize the reference &lt;br /&gt;
under TOC-&amp;gt; Issues-&amp;gt; Economics of Cybersecurity-&amp;gt;Insurance, then links to it must appear under [[Insurance]], [[Economics of Cybersecurity]] and [[Issues]].  Links from&lt;br /&gt;
TOC Category pages back to the reference page should follow the table format shown in the TOC.  If more than two authors, abbreviate to &amp;quot;&amp;lt;first author&amp;gt; et. al&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Enter the reference in the selected category page&#039;&#039;&#039; in alphabetical order by the [first] author&#039;s last name.&lt;br /&gt;
&lt;br /&gt;
Categories should be separated by top level Table of Contents topics and in the following order (note only those top level topics in which the current reference has an applicable category need appear), i.e.:&lt;br /&gt;
&lt;br /&gt;
* Overview:&lt;br /&gt;
* Resource by Type:&lt;br /&gt;
* Treats and Actors:&lt;br /&gt;
* Issues: &lt;br /&gt;
* Approaches: &lt;br /&gt;
&lt;br /&gt;
Multiple categories within a single top level Table of Contents topic should be separated by semicolons and arranged in alphabetical order, i.e.&lt;br /&gt;
&lt;br /&gt;
* Threats and Actors: [[The Threat and Skeptics]]; [[States]]; [[Security Targets]]&lt;br /&gt;
&lt;br /&gt;
==== 4.4 Key Words ====&lt;br /&gt;
&#039;&#039;&#039;Add Relevant Keywords:&#039;&#039;&#039; Add Glossary/Keyword entries in alphabetical order separated by commas.  You can copy links from the [[List of Keyword links to copy into reference pages | Keyword Links]] page directly into the reference page.  (Switch to &amp;quot;edit&amp;quot; mode to copy the link -- be careful not to change the text on the Keyword Links page though.) &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;In the glossary, create links back to the reference page:&#039;&#039;&#039; Make sure to create links from the [[Keyword Index and Glossary of Core Ideas]] page back to the reference.  If another reference by the same author is linked under a given keyword, use &amp;quot;[2]&amp;quot;, &amp;quot;[3]&amp;quot;, etc. for succeeding entries.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;New keywords:&#039;&#039;&#039; If you decide to add a new keyword to the [[Keyword Index and Glossary of Core Ideas]], make sure to update the [[List of Keyword links to copy into reference pages | Keyword Links]] page.  It is also a good idea to email either David Abrams or Caroline Nolan of the addition.&lt;br /&gt;
&lt;br /&gt;
Note that links to Keywords are appropriate &#039;&#039;even when the item is only mentioned in passing in the reference&#039;&#039;.  The purpose of keywords are to help someone unfamiliar with the term or &lt;br /&gt;
to provide a way to find other references with the same keyword but appearing in a separate category.&lt;br /&gt;
&lt;br /&gt;
====4.5 Synopsis====&lt;br /&gt;
&#039;&#039;&#039;Add the Synopsis:&#039;&#039;&#039;  The goal is not merely to summarize the subject matter of the reference; rather, the synopsis should also summarize the author&#039;s conclusions as well.  Typically this will be equivalent to an executive summary, and that section of the reference, if available, can provide the basis of the synopsis.  Alternately, quoted opening or conclusion paragraphs from the reference may form the basis for the synopsis.  Feel free to use wiki section headings &amp;quot;===&amp;quot;, &amp;quot;====&amp;quot;, etc. to provide clarity to the synopsis.&lt;br /&gt;
&lt;br /&gt;
====4.6 Additional Notes and Highlights====&lt;br /&gt;
Finally, the &amp;quot;Additional Notes and Highlights&amp;quot; section provides a place to include information that does not fit in elsewhere.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Required:&#039;&#039;&#039; This section should begin with &amp;quot;Expertise Required: &amp;quot; followed by either &amp;quot;None&amp;quot; or one or more &amp;quot;&amp;lt;field&amp;gt; - &amp;lt;level&amp;gt;&amp;quot; pair separated by semicolons.  Level is one of &amp;quot;Low&amp;quot;, &amp;quot;Moderate&amp;quot; or &amp;quot;High&amp;quot; (although intermediate values &amp;quot;Low/Moderate&amp;quot; are allowed.  If there are multiple field/level pairs, order them from highest expertise level to lowest, e.g.,&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Economics - Moderate; Law - Low&lt;br /&gt;
&lt;br /&gt;
This is a subjective measure.  &amp;quot;None&amp;quot; means a person with a college education but no specific expertise in the subject matter of the reference would be able to understand it.  &amp;quot;High&amp;quot; suggests that a great deal of knowledge in the subject matter is required, possibly because of extensive mathematical equations or jargon-filled discussion.&lt;br /&gt;
&lt;br /&gt;
(Note that on the reference page, each expertise entry is ordered with subject matter first followed by level required; however, in the TOC, the highest level of competence is always placed first to allow the user to sort on that parameter.)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Other possible items to include in the Additional Notes and Highlights (if available) are:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* The &#039;&#039;&#039;table of contents&#039;&#039;&#039; of the reference: [[Overcoming Impediments to Information Sharing#Additional Notes and Highlights]].&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Biographic information&#039;&#039;&#039; about the author: [[Armed Attack in Cyberspace#Additional Notes and Highlights]] or about an organization [[Security Economics and the Internal Market#Additional Notes and Highlights]].&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Reviews&#039;&#039;&#039; of the reference: [[Do Data Breach Disclosure Laws Reduce Identity Theft#Additional Notes and Highlights]].&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Excerpts&#039;&#039;&#039; or chapters where the full reference is not available online: [[Cyber War#Additional Notes and Highlights]].&lt;br /&gt;
&lt;br /&gt;
* Links to &#039;&#039;&#039;the author&#039;s home page&#039;&#039;&#039;: [[Why Information Security is Hard#Additional Notes and Highlights]].&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;See also&amp;quot; information that would be useful to the reader:  [[Law and War in the Virtual Era#Additional Notes and Highlights]].&lt;br /&gt;
&lt;br /&gt;
* Information on (and possibly links to) &#039;&#039;&#039;previous versions&#039;&#039;&#039; of the reference: [[A Roadmap for Cybersecurity Research#Additional Notes and Highlights]].&lt;br /&gt;
&lt;br /&gt;
* Description of a &#039;&#039;&#039;useful appendix or glossary&#039;&#039;&#039; in the reference: [[Critical Infrastructure Threats and Terrorism#Additional Notes and Highlights]].&lt;br /&gt;
&lt;br /&gt;
===5. Check your Work===&lt;br /&gt;
&lt;br /&gt;
* Check all your links to make sure they work.&lt;br /&gt;
* Make sure that your reference is included in the [[Cybersecurity Annotated Bibliography]] list of all reference in the wiki.&lt;br /&gt;
* Make sure the reference appears in the selected categories and &#039;&#039;all the higher level categories&#039;&#039; of the selected categories.&lt;br /&gt;
* Make sure your category links not only work but properly link back to the reference.&lt;br /&gt;
* Make sure your keywords links not only work but properly link back to the reference.&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Schneier_on_Security&amp;diff=6342</id>
		<title>Schneier on Security</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Schneier_on_Security&amp;diff=6342"/>
		<updated>2010-10-08T13:16:09Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Additional Notes and Highlights */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
Schneier on Security&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
Bruce Schneier, Schneier on Security (2008). &lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=Schneier_B:2008 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
[http://books.google.com/books?id=tzyqfHr2oGAC&amp;amp;dq=Schneier+on+Security&amp;amp;ei=id1RTNXLNI2IygTxmojcCQ&amp;amp;cd=1 &#039;&#039;Google Books&#039;&#039;]&lt;br /&gt;
[http://www.worldcat.org/search?q=isbn:0470395354 &#039;&#039;World Cat&#039;&#039;]&lt;br /&gt;
[http://www.amazon.com/Schneier-Security-Bruce/dp/0470395354 &#039;&#039;Amazon&#039;&#039;]&lt;br /&gt;
[http://www.schneier.com/book-sos.html &#039;&#039;Purchase from the Author&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* [[Overview]]&lt;br /&gt;
* Resource by Type: [[Books]]&lt;br /&gt;
* Threats and Actors: [[Actors and Incentives]]; [[The Threat and Skeptics]]; [[Transportation]]&lt;br /&gt;
* Issues: [[Metrics]]; [[Risk Management and Investment]]; [[Privacy]]; [[Usability/Human Factors]]&lt;br /&gt;
* Approaches: [[Government Organizations]]; [[Regulation/Liability]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Data_Mining | Data Mining]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Department_of_Homeland_Security | Department of Homeland Security]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Disclosure_Policy | Disclosure Policy]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Identity_Fraud/Theft | Identity Fraud/Theft]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Information_Asymmetries | Information Asymmetries]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#National_Security | National Security Policy]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Phishing | Phishing]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
This collection of essays on security: on security technology, on security policy, and on how security works in the real world was previously published between June 2002 and June 2008. They offer a computer security expert&#039;s insights into a wide range of security issues, including the risk of identity theft (vastly overrated), the long-range security threat of unchecked presidential power, why computer security is fundamentally an economic problem, the industry power struggle over controlling your computer, and why national ID cards won&#039;t make us safer, only poorer. Schneier recognizes that the ultimate security risk is people and that many security paractices are, in fact, security risks. While not primarily a treatise on cybersecurity (although several of the essays address cybersecurity), Schneier&#039;s insights are applicable to any security situation where limited resources make trade-offs necessary.&lt;br /&gt;
&lt;br /&gt;
[http://www.amazon.com/gp/cdp/member-reviews/A1L5RDC8H9BB9S/ref=cm_cr_dp_auth_rev?ie=UTF8&amp;amp;sort_by=MostRecentReview Review by Ben Rothke]&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;Perhaps no one in the world gets security like author Bruce Schneier does. ... Schneier on Security is a collection of the best articles that Bruce has written from June 2002 to June 2008, mainly from his Crypto-Gram Newsletter, his blog, and other newspapers and magazine. The book is divided into 12 sections, covering nearly the entire range of security issues from terrorism, aviation, elections, economics, psychology, the business of security and much more. &amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;Two of the terms Schneier uses extensively throughout the book are intelligence and economics. From an intelligence perspective, he feels that Washington has spent far too much on hardware and other trendy security devices that create a sense of security theater. The security theater gives an aura and show of security, but in reality, has little real effect.&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;The lack of intelligence is most manifest with airports, which are a perfect example of misguided security. Schneier notes that current trends in US airport security requires that people remove their shoes, due to a one-time incident with shoe-based explosive. Such an approach completely misses the point. Also, Schneier notes that the attempt to create a no-fly list, by feeding a limited set of characteristics into a computer, which is somehow expected to divine a person&#039;s terrorist leaning, is farcical.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;Schneier therefore feels that the only way to effectively uncover terrorist plats is via intelligence and investigations, not via large-scale processing of everyone. Intelligence is an invaluable tool against terrorism, and the beauty of it is that it works regardless of what the terrorists are plotting. The bottom line according to Schneier in the book is that too much of the United State&#039;s counterterrorism security spending is not designed to protect us from the terrorists; but instead to protect public officials from criticism when another attack occurs.&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;Schneier also astutely notes that for the most part, security is not really so much of a technical issue, rather one of economics. A perfect example he gives is that of bulletproof vests. Since they are so effective, why doesn&#039;t everyone wear them all of the time? The reason people don&#039;t is that they do not think they are worth the cost. It is not worth the money or inconvenience, as the risk of being shot for most people is quite low. As a security consumer, people have made the calculation that not wearing a bulletproof vest is a good security trade-off. Schneier also notes that much of what is being proposed as national security is a bad security trade-off. It is not worth it and as consumers, the public is being ripped off.&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;Another recurring theme throughout the book is how the Bush administration has little by little eroded the Constitution, all in the name of fighting terrorism. Schneier notes that the brilliant framework the founding fathers created by creating divisions of power (executive, legislative, judicial) with checks and balances violates a basic unwritten rule, that the government should be granted only limited powers, and for limited purposes. Since there is a certainty that government powers will be abused. &amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;Schneier observes that the USA PATRIOT is a perfect example of this abuse. The Constitution was designed and carefully outlines which powers each branch may exercise. While Schneier is best-known as a cryptographer and security expert, Schneier on Security also shows him to be a defender of the Constitution. In a number of essays in the book, he shows how unchecked presidential powers is bad not only for security, but for the preservation of democracy. &amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;In chapter 8, on the topic of the economics of security, Schneier suggests a three-step program for improving computer and network security. He notes that none of them have anything to do with technology; they all have to do with businesses, economics, and people. &amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In chapter 9, on the psychology of security, Schneier writes that he tells people that if something is in the news, then they do not have to worry about it. He writes that the very definition of news is something that hardly ever happens. It&#039;s when something is not in the news, when it is so common that it is no longer news, drunk drivers killing people, domestic violence, deaths from diabetes, etc., that is when you should start worrying. And much of the terrorist threats that the Department of Homeland Security is spending tens of billions of dollars on, are those news threats, such as shoe bombers and liquid explosives that present very little real threat to the people of the US. &lt;br /&gt;
&lt;br /&gt;
A fundamental theme of the book is that security is a trade-off. And far too many people have made the security trade-off without thinking if it is truly worth it. In essay after essay, Schenier challenges those assertions. Since 9/11, much has been given up in the name of terrorism, and that has been personal privacy and security. Schenier asks, has it been worth it? &lt;br /&gt;
&lt;br /&gt;
Schneier on Security is an exceptionally important book that is overflowing with thought-provoking articles. Schneier gets above vague adages such as the war on terror and gets to the heart of the matter. His insight details what the real threats are, and what we should really be worrying about. The irony is that what Washington does is often the exact opposite of what should be done. &lt;br /&gt;
&lt;br /&gt;
Much of the security carried out in the name of 9/11 has proven to be infective in the seven years since the attack. Schneier on Security is a manifesto of what should have been done, and what should be done. The book is eye-opening from the first page to the last. It lets you know that the next time you see grandma asked to take her shoes off by a TSA agent at the airport, why she is simply a bit player in the large security theater. And why spending tens of billions on a charade like that, makes that a tragedy of epic proportions. &lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: None&lt;br /&gt;
&lt;br /&gt;
 Table of Contents&lt;br /&gt;
  Introduction&lt;br /&gt;
  Terrorism and Security&lt;br /&gt;
  National Security Policy&lt;br /&gt;
  Airline Travel&lt;br /&gt;
  Privacy and Surveillance&lt;br /&gt;
  ID Cards and Security&lt;br /&gt;
  Election Security&lt;br /&gt;
  Security and Disasters&lt;br /&gt;
  Economics of Security&lt;br /&gt;
  Psychology of Security&lt;br /&gt;
  Business of Security&lt;br /&gt;
  Cybercrime and Cyberwar&lt;br /&gt;
  Computer and Information Security&lt;br /&gt;
  References&lt;br /&gt;
  Index&lt;br /&gt;
&lt;br /&gt;
[http://www.schneier.com/blog/archives/2010/10/stuxnet.html Bruce Schneier&#039;s analysis of the Stuxnet worm]&lt;br /&gt;
&lt;br /&gt;
[http://www.schneier.com/ Bruce Schneier&#039;s blog covering security and security technology.] &lt;br /&gt;
&lt;br /&gt;
[http://www.schneier.com/crypto-gram-back.html Back issues] of Bruce Schneier&#039;s monthly email newsletter.  (Most of the essays in this reference can be found here.)&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6341</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6341"/>
		<updated>2010-09-21T14:42:51Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=hptippingpoint:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
* Approaches: [[Technology]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#DDoS_Attack | DDoS Attack]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In 2010, information security threats are striking networks with more sophisticated techniques than ever and exploit reports continue to dominate the media.  The collective findings described within this report establish the fact that the proliferation of technology, along with the quick and effortless manner in which that technology is accessed, is dramatically and negatively impacting security. While we are not advocates for making technology more difficult, we do advocate implementing common sense security policies and technologies that battle well-known and new threats. This report evaluates some of the most significant security liabilities that the enterprise is facing today. The report focuses on four key areas:&lt;br /&gt;
* Increased Consumerization of Enterprise Computing&lt;br /&gt;
* Prolonged and Persistent Targeting of Web Applications&lt;br /&gt;
* Increased Organization and Sophistication of Attackers&lt;br /&gt;
* The Unrelenting Presence of Legacy Threats&lt;br /&gt;
In addition to explaining how and where the enterprise is vulnerable, the report provides insights into how organizations can protect themselves&lt;br /&gt;
from attack, including what the next generation of computing should look like to maximize security for the corporate network.&lt;br /&gt;
&lt;br /&gt;
===Increased Consumerization of Enterprise Computing===&lt;br /&gt;
Some of the most serious information security issues&lt;br /&gt;
the research team has seen this year stem from the&lt;br /&gt;
increasingly high use of consumer technologies within&lt;br /&gt;
the enterprise. For example, there are several thousand&lt;br /&gt;
organizations that utilize Facebook, Twitter, WordPress,&lt;br /&gt;
and iTunes for promotion and brand awareness. While&lt;br /&gt;
these technologies may offer a wealth of marketing&lt;br /&gt;
recognition, they also open the door to a multitude&lt;br /&gt;
of security risks. Another trend impacting enterprise&lt;br /&gt;
IT department is an “anything goes” mentality that&lt;br /&gt;
allows users to download and manage applications&lt;br /&gt;
and programs of their choosing. While some of&lt;br /&gt;
these applications may be fine, and may even boost&lt;br /&gt;
productivity, an overwhelming majority of them are a&lt;br /&gt;
significant liability to corporate networks.&lt;br /&gt;
===Web Applications continue to be highly attractive targets===&lt;br /&gt;
The team highlighted the risks of running Web&lt;br /&gt;
applications in last year’s Threat Report. Our current&lt;br /&gt;
research indicates that Web applications continue to&lt;br /&gt;
pose one of the biggest risks to corporate networks.&lt;br /&gt;
Web applications offer an easy way for organizations&lt;br /&gt;
to create an interactive relationship between&lt;br /&gt;
constituents such as customers, employees, and&lt;br /&gt;
partners, and their back-end systems. Because Web&lt;br /&gt;
application systems are relatively easy to build and&lt;br /&gt;
offer inexpensive extensibility, they yield a great deal of&lt;br /&gt;
value and functionality. Because of this, the number of&lt;br /&gt;
Web applications continues to steadily grow.&lt;br /&gt;
===Attackers are more organized and sophisticated===&lt;br /&gt;
One of the more alarming trends observed in the&lt;br /&gt;
previous six months is the increased sophistication&lt;br /&gt;
of attacks. Attackers have not only become more&lt;br /&gt;
organized, they are also increasingly subversive and&lt;br /&gt;
inconspicuous in the way they execute their attacks.&lt;br /&gt;
The attacks are so sophisticated and subtle that few&lt;br /&gt;
victims realize they are under attack until it is too late. It&lt;br /&gt;
is increasingly common to hear of attackers remaining&lt;br /&gt;
inside a compromised organization for months,&lt;br /&gt;
gathering information with which they design and build&lt;br /&gt;
even more sophisticated attacks. Once the desired&lt;br /&gt;
information is obtained, the attackers launch exploits&lt;br /&gt;
that are both more devastating and more covert.&lt;br /&gt;
&lt;br /&gt;
Attack sophistication has increased across the board,&lt;br /&gt;
from client side-attacks such as malicious JavaScript,&lt;br /&gt;
to server-side attacks like PHP file include. This report&lt;br /&gt;
includes examples of real-world attack techniques&lt;br /&gt;
employed by these increasingly sophisticated attackers&lt;br /&gt;
&lt;br /&gt;
===Legacy attacks still a threat===&lt;br /&gt;
Despite the rising sophistication of attacks, it is still&lt;br /&gt;
worth highlighting that over the sample period of this&lt;br /&gt;
report, the number of attacks from well-known legacy&lt;br /&gt;
threats continues to plague computer systems. While&lt;br /&gt;
many of these attacks are well understood and well&lt;br /&gt;
protected against, it is not unheard of to see large&lt;br /&gt;
organizations as the source of some of these attacks,&lt;br /&gt;
indicating that when large organizations implement&lt;br /&gt;
new systems without threat management controls,&lt;br /&gt;
the systems are quickly infected with familiar threats.&lt;br /&gt;
While this is an extreme example, it highlights the&lt;br /&gt;
need for continued diligence against well-known&lt;br /&gt;
threats, ideally addressing them with strong patch and&lt;br /&gt;
configuration management policies.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;br /&gt;
&lt;br /&gt;
While the sections of the report which explain in detail how attackers hide exploits in seemingly innocuous code require some technical expertise, there is a very clear explanation of how such an exploit is downloaded and executed on a victim&#039;s computer within the corporate firewall that requires no special expertise to understand. &#039;&#039;See&#039;&#039; page 27.&lt;br /&gt;
&lt;br /&gt;
[http://dvlabs.tippingpoint.com/ Web Site of Author Organization]&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6340</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6340"/>
		<updated>2010-09-21T14:41:30Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Key Words */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=hptippingpoint:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
* Approaches: [[Technology]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#DDoS_Attack | DDoS Attack]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In 2010, information security threats are striking networks with more sophisticated techniques than ever and exploit reports continue to dominate the media.  The collective findings described within this report establish the fact that the proliferation of technology, along with the quick and effortless manner in which that technology is accessed, is dramatically and negatively impacting security. While we are not advocates for making technology more difficult, we do advocate implementing common sense security policies and technologies that battle well-known and new threats. This report evaluates some of the most significant security liabilities that the enterprise is facing today. The report focuses on four key areas:&lt;br /&gt;
* Increased Consumerization of Enterprise Computing&lt;br /&gt;
* Prolonged and Persistent Targeting of Web Applications&lt;br /&gt;
* Increased Organization and Sophistication of Attackers&lt;br /&gt;
* The Unrelenting Presence of Legacy Threats&lt;br /&gt;
In addition to explaining how and where the enterprise is vulnerable, the report provides insights into how organizations can protect themselves&lt;br /&gt;
from attack, including what the next generation of computing should look like to maximize security for the corporate network.&lt;br /&gt;
&lt;br /&gt;
===Increased Consumerization of Enterprise Computing===&lt;br /&gt;
Some of the most serious information security issues&lt;br /&gt;
the research team has seen this year stem from the&lt;br /&gt;
increasingly high use of consumer technologies within&lt;br /&gt;
the enterprise. For example, there are several thousand&lt;br /&gt;
organizations that utilize Facebook, Twitter, WordPress,&lt;br /&gt;
and iTunes for promotion and brand awareness. While&lt;br /&gt;
these technologies may offer a wealth of marketing&lt;br /&gt;
recognition, they also open the door to a multitude&lt;br /&gt;
of security risks. Another trend impacting enterprise&lt;br /&gt;
IT department is an “anything goes” mentality that&lt;br /&gt;
allows users to download and manage applications&lt;br /&gt;
and programs of their choosing. While some of&lt;br /&gt;
these applications may be fine, and may even boost&lt;br /&gt;
productivity, an overwhelming majority of them are a&lt;br /&gt;
significant liability to corporate networks.&lt;br /&gt;
===Web Applications continue to be highly attractive targets===&lt;br /&gt;
The team highlighted the risks of running Web&lt;br /&gt;
applications in last year’s Threat Report. Our current&lt;br /&gt;
research indicates that Web applications continue to&lt;br /&gt;
pose one of the biggest risks to corporate networks.&lt;br /&gt;
Web applications offer an easy way for organizations&lt;br /&gt;
to create an interactive relationship between&lt;br /&gt;
constituents such as customers, employees, and&lt;br /&gt;
partners, and their back-end systems. Because Web&lt;br /&gt;
application systems are relatively easy to build and&lt;br /&gt;
offer inexpensive extensibility, they yield a great deal of&lt;br /&gt;
value and functionality. Because of this, the number of&lt;br /&gt;
Web applications continues to steadily grow.&lt;br /&gt;
===Attackers are more organized and sophisticated===&lt;br /&gt;
One of the more alarming trends observed in the&lt;br /&gt;
previous six months is the increased sophistication&lt;br /&gt;
of attacks. Attackers have not only become more&lt;br /&gt;
organized, they are also increasingly subversive and&lt;br /&gt;
inconspicuous in the way they execute their attacks.&lt;br /&gt;
The attacks are so sophisticated and subtle that few&lt;br /&gt;
victims realize they are under attack until it is too late. It&lt;br /&gt;
is increasingly common to hear of attackers remaining&lt;br /&gt;
inside a compromised organization for months,&lt;br /&gt;
gathering information with which they design and build&lt;br /&gt;
even more sophisticated attacks. Once the desired&lt;br /&gt;
information is obtained, the attackers launch exploits&lt;br /&gt;
that are both more devastating and more covert.&lt;br /&gt;
&lt;br /&gt;
Attack sophistication has increased across the board,&lt;br /&gt;
from client side-attacks such as malicious JavaScript,&lt;br /&gt;
to server-side attacks like PHP file include. This report&lt;br /&gt;
includes examples of real-world attack techniques&lt;br /&gt;
employed by these increasingly sophisticated attackers&lt;br /&gt;
&lt;br /&gt;
===Legacy attacks still a threat===&lt;br /&gt;
Despite the rising sophistication of attacks, it is still&lt;br /&gt;
worth highlighting that over the sample period of this&lt;br /&gt;
report, the number of attacks from well-known legacy&lt;br /&gt;
threats continues to plague computer systems. While&lt;br /&gt;
many of these attacks are well understood and well&lt;br /&gt;
protected against, it is not unheard of to see large&lt;br /&gt;
organizations as the source of some of these attacks,&lt;br /&gt;
indicating that when large organizations implement&lt;br /&gt;
new systems without threat management controls,&lt;br /&gt;
the systems are quickly infected with familiar threats.&lt;br /&gt;
While this is an extreme example, it highlights the&lt;br /&gt;
need for continued diligence against well-known&lt;br /&gt;
threats, ideally addressing them with strong patch and&lt;br /&gt;
configuration management policies.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;br /&gt;
&lt;br /&gt;
While the sections of the report which explain in detail how attackers hide exploits in seemingly innocuous code require some technical expertise, there is a very clear explanation of how such an exploit is downloaded and executed on a victim&#039;s computer within the corporate firewall that requires no special expertise to understand. &#039;&#039;See&#039;&#039; page 27.&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6339</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6339"/>
		<updated>2010-09-21T14:40:51Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Zero-Day Exploit */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6338</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6338"/>
		<updated>2010-09-21T14:40:39Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Worm */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6337</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6337"/>
		<updated>2010-09-21T14:40:27Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Trojan */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6336</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6336"/>
		<updated>2010-09-21T14:40:10Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* SPAM */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6335</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6335"/>
		<updated>2010-09-21T14:39:43Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Patching */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6334</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6334"/>
		<updated>2010-09-21T14:39:21Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Patching */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6333</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6333"/>
		<updated>2010-09-21T14:39:04Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Patching */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6332</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6332"/>
		<updated>2010-09-21T14:38:48Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Malware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6331</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6331"/>
		<updated>2010-09-21T14:38:32Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* DDoS Attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6330</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6330"/>
		<updated>2010-09-21T14:38:05Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Cyber Crime */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6329</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6329"/>
		<updated>2010-09-21T14:37:51Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Botnet */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6328</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6328"/>
		<updated>2010-09-21T14:37:36Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Antivirus */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[2010 Top Cyber Security Risks Report | HP TippingPoint DVLabs]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6327</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6327"/>
		<updated>2010-09-21T14:36:45Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Antivirus */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[HP TippingPoint DVLabs| 2010 Top Cyber Security Risks Report]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6326</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6326"/>
		<updated>2010-09-21T14:35:46Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Key Words */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=hptippingpoint:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
* Approaches: [[Technology]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Distributed_Denial_of_Service_(DDoS) | Distributed Denial of Service (DDoS)]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In 2010, information security threats are striking networks with more sophisticated techniques than ever and exploit reports continue to dominate the media.  The collective findings described within this report establish the fact that the proliferation of technology, along with the quick and effortless manner in which that technology is accessed, is dramatically and negatively impacting security. While we are not advocates for making technology more difficult, we do advocate implementing common sense security policies and technologies that battle well-known and new threats. This report evaluates some of the most significant security liabilities that the enterprise is facing today. The report focuses on four key areas:&lt;br /&gt;
* Increased Consumerization of Enterprise Computing&lt;br /&gt;
* Prolonged and Persistent Targeting of Web Applications&lt;br /&gt;
* Increased Organization and Sophistication of Attackers&lt;br /&gt;
* The Unrelenting Presence of Legacy Threats&lt;br /&gt;
In addition to explaining how and where the enterprise is vulnerable, the report provides insights into how organizations can protect themselves&lt;br /&gt;
from attack, including what the next generation of computing should look like to maximize security for the corporate network.&lt;br /&gt;
&lt;br /&gt;
===Increased Consumerization of Enterprise Computing===&lt;br /&gt;
Some of the most serious information security issues&lt;br /&gt;
the research team has seen this year stem from the&lt;br /&gt;
increasingly high use of consumer technologies within&lt;br /&gt;
the enterprise. For example, there are several thousand&lt;br /&gt;
organizations that utilize Facebook, Twitter, WordPress,&lt;br /&gt;
and iTunes for promotion and brand awareness. While&lt;br /&gt;
these technologies may offer a wealth of marketing&lt;br /&gt;
recognition, they also open the door to a multitude&lt;br /&gt;
of security risks. Another trend impacting enterprise&lt;br /&gt;
IT department is an “anything goes” mentality that&lt;br /&gt;
allows users to download and manage applications&lt;br /&gt;
and programs of their choosing. While some of&lt;br /&gt;
these applications may be fine, and may even boost&lt;br /&gt;
productivity, an overwhelming majority of them are a&lt;br /&gt;
significant liability to corporate networks.&lt;br /&gt;
===Web Applications continue to be highly attractive targets===&lt;br /&gt;
The team highlighted the risks of running Web&lt;br /&gt;
applications in last year’s Threat Report. Our current&lt;br /&gt;
research indicates that Web applications continue to&lt;br /&gt;
pose one of the biggest risks to corporate networks.&lt;br /&gt;
Web applications offer an easy way for organizations&lt;br /&gt;
to create an interactive relationship between&lt;br /&gt;
constituents such as customers, employees, and&lt;br /&gt;
partners, and their back-end systems. Because Web&lt;br /&gt;
application systems are relatively easy to build and&lt;br /&gt;
offer inexpensive extensibility, they yield a great deal of&lt;br /&gt;
value and functionality. Because of this, the number of&lt;br /&gt;
Web applications continues to steadily grow.&lt;br /&gt;
===Attackers are more organized and sophisticated===&lt;br /&gt;
One of the more alarming trends observed in the&lt;br /&gt;
previous six months is the increased sophistication&lt;br /&gt;
of attacks. Attackers have not only become more&lt;br /&gt;
organized, they are also increasingly subversive and&lt;br /&gt;
inconspicuous in the way they execute their attacks.&lt;br /&gt;
The attacks are so sophisticated and subtle that few&lt;br /&gt;
victims realize they are under attack until it is too late. It&lt;br /&gt;
is increasingly common to hear of attackers remaining&lt;br /&gt;
inside a compromised organization for months,&lt;br /&gt;
gathering information with which they design and build&lt;br /&gt;
even more sophisticated attacks. Once the desired&lt;br /&gt;
information is obtained, the attackers launch exploits&lt;br /&gt;
that are both more devastating and more covert.&lt;br /&gt;
&lt;br /&gt;
Attack sophistication has increased across the board,&lt;br /&gt;
from client side-attacks such as malicious JavaScript,&lt;br /&gt;
to server-side attacks like PHP file include. This report&lt;br /&gt;
includes examples of real-world attack techniques&lt;br /&gt;
employed by these increasingly sophisticated attackers&lt;br /&gt;
&lt;br /&gt;
===Legacy attacks still a threat===&lt;br /&gt;
Despite the rising sophistication of attacks, it is still&lt;br /&gt;
worth highlighting that over the sample period of this&lt;br /&gt;
report, the number of attacks from well-known legacy&lt;br /&gt;
threats continues to plague computer systems. While&lt;br /&gt;
many of these attacks are well understood and well&lt;br /&gt;
protected against, it is not unheard of to see large&lt;br /&gt;
organizations as the source of some of these attacks,&lt;br /&gt;
indicating that when large organizations implement&lt;br /&gt;
new systems without threat management controls,&lt;br /&gt;
the systems are quickly infected with familiar threats.&lt;br /&gt;
While this is an extreme example, it highlights the&lt;br /&gt;
need for continued diligence against well-known&lt;br /&gt;
threats, ideally addressing them with strong patch and&lt;br /&gt;
configuration management policies.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;br /&gt;
&lt;br /&gt;
While the sections of the report which explain in detail how attackers hide exploits in seemingly innocuous code require some technical expertise, there is a very clear explanation of how such an exploit is downloaded and executed on a victim&#039;s computer within the corporate firewall that requires no special expertise to understand. &#039;&#039;See&#039;&#039; page 27.&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Approaches&amp;diff=6325</id>
		<title>Approaches</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Approaches&amp;diff=6325"/>
		<updated>2010-09-21T14:34:11Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;[[Table of Contents | TOC-&amp;gt;]][[Approaches]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross J.||||2008||[[Security Engineering]]||Book||Moderate:Technology; Moderate:Cryptography||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross, et. al|| ||2008||[[Security Economics and the Internal Market]]||Study||Low:Economics||[http://www.enisa.europa.eu/act/sr/reports/econ-sec/economics-sec/at_download/fullReport  &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross||||2001||[[Why Information Security is Hard]]||Conf. Paper||None||[http://www.acsac.org/2001/papers/110.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rja14/Papers/econ.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross||Moore, Tyler||2006||[[The Economics of Information Security]]||Journal Article||Low:Economics||[http://people.seas.harvard.edu/~tmoore/science-econ.pdf  &#039;&#039;Pdf&#039;&#039;] [http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.89.3331&amp;amp;rep=rep1&amp;amp;type=pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Aviram, Amitai||Tor, Avishalom||2004||[[Overcoming Impediments to Information Sharing]]||Law Review||Low:Economics||[http://law.haifa.ac.il/faculty/lec_papers/tor/55Ala1.L.Rev.231.pdf &#039;&#039;Pdf&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=435600 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Barkham, Jason||||2001||[[Information Warfare and International Law on the Use of Force]]||Law Review||Moderate:Law||[http://www1.law.nyu.edu/journals/jilp/issues/34/pdf/34_1_b.pdf &#039;&#039;Pdf&#039;&#039;] [http://activeresponse.org/files/34_1_b.pdf &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Beard, Jack M.||||2009||[[Law and War in the Virtual Era]]||Law Review||Low:Law||[http://www.asil.org/ajil/July2009_1selectedpiece.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Bohme, Rainer||Kataria, Gaurav||2006||[[Models and Measures for Correlation in Cyber-Insurance]]||Conf. Paper||High:Economics||[http://weis2006.econinfosec.org/docs/16.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Bohme, Rainer||Schwartz, Galina||2010||[[Modeling Cyber-Insurance]]||Conf. Paper||High:Economics||[http://www1.inf.tu-dresden.de/~rb21/publications/BS2010_Modeling_Cyber-Insurance_WEIS.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Brown, Davis||||2006||[[A Proposal for an International Convention To Regulate the Use of Information Systems in Armed Conflict]]||Law Review||Moderate:Law||[http://www.harvardilj.org/attach.php?id=59 &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Camp, L. Jean||Lewis, Stephen||2004||[[Economics of Information Security]]||Book||High:Economics||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Center for Strategic and International Studies||||2008||[[Securing Cyberspace for the 44th Presidency]]||Independent Report||Low:Policy||[http://www.cyber.st.dhs.gov/docs/081208_securingcyberspace_44.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Clarke, Richard A.||Knake, Robert||2010||[[Cyber War]]||Book||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Clinton, Larry||||Undated||[[Cyber-Insurance Metrics and Impact on Cyber-Security]]||Online Paper||Low:Technology; Low:Law||[http://www.whitehouse.gov/files/documents/cyber/ISA%20-%20Cyber-Insurance%20Metrics%20and%20Impact%20on%20Cyber-Security.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Commerce||||2010||[[Defense Industrial Base Assessment]]||Government Report||None||[http://www.bis.doc.gov/defenseindustrialbaseprograms/osies/defmarketresearchrpts/final_counterfeit_electronics_report.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||1999||[[An Assessment of International Legal Issues in Information Operations]]||Government Report||Moderate:Law||[http://www.au.af.mil/au/awc/awcgate/dod-io-legal/dod-io-legal.pdf &#039;&#039; Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||2005||[[Strategy for Homeland Defense and Civil Support]]||Government Report||None||[http://www.defense.gov/news/Jun2005/d20050630homeland.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||2007||[[Mission Impact of Foreign Influence on DoD Software]]||Government Report||Low:Defense Policy/Procurement||[http://www.cyber.st.dhs.gov/docs/Defense%20Science%20Board%20Task%20Force%20-%20Report%20on%20Mission%20Impact%20of%20Foreign%20Influence%20on%20DoD%20Software%20(2007).pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Homeland Security||||2003||[[The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets]]||Government Report||None||[http://www.dhs.gov/xlibrary/assets/Physical_Strategy.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Homeland Security||||2009||[[A Roadmap for Cybersecurity Research]]||Government Report||Low:Technology||[http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Deputy Chief of Staff for Intelligence||||2006||[[Critical Infrastructure Threats and Terrorism]]||Government Report||Low:Organizational Analysis; Low:Risk Management||[http://www.fas.org/irp/threat/terrorism/sup2.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Dörmann, Knut||||2004||[[Applicability of the Additional Protocols to Computer Network Attacks]]||Independent Report||Low:Law||[http://www.icrc.org/Web/eng/siteeng0.nsf/htmlall/68LG92/$File/ApplicabilityofIHLtoCNA.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Dunlap, Charles J. Jr.||||2009||[[Towards a Cyberspace Legal Regime in the Twenty-First Century]]||Speech||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Epstein, Richard A.||Brown, Thomas P.||2008||[[Cybersecurity in the Payment Card Industry]]||Law Review||Low:Law; Low:Economics||[http://lawreview.uchicago.edu/issues/archive/v75/75_1/EpsteinArticle.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Gandal, Neil||||2008||[[An Introduction to Key Themes in the Economics of Cyber Security]]||Book Chapter||Low:Economics||[http://www.tau.ac.il/~gandal/security%20encyclopedia%20entry.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Grady, Mark F.||Parisi, Francesco||2006||[[The Law and Economics of Cybersecurity]]||Book||Low:Economics; Low:Law||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Granick, Jennifer Stisa||||2005||[[The Price of Restricting Vulnerability Publications]]||Law Review||Low/Moderate:Law||[http://www.ijclp.net/files/ijclp_web-doc_10-cy-2004.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Hollis, Duncan B.||||2007||[[Why States Need an International Law for Information Operations]]||Law Review||Moderate:Law||[http://legacy.lclark.edu/org/lclr/objects/LCB_11_4_Art7_Hollis.pdf  &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|HP TippingPoint DVLabs||||2010||[[2010 Top Cyber Security Risks Report]]||Industry report||Moderate:Technology||[http://dvlabs.tippingpoint.com/toprisks2010  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Institute for Information Infrastructure Protection||||2003||[[Cyber Security Research and Development Agenda]]||Independent Report||Low/None:Technology||[http://www.cyber.st.dhs.gov/docs/I3P%20Research%20Agenda%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Johnson, Eric M.||||2008||[[Managing Information Risk and the Economics of Security]]||Book||High:Economics||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Johnson, Vincent R.||||2005||[[Cybersecurity, Identity Theft, and the Limits of Tort Liability]]||Law Review||Moderate:Law||[http://www.stmarytx.edu/law/pdf/Johnsoncyber.pdf &#039;&#039;Pdf&#039;&#039;] [http://law.bepress.com/cgi/viewcontent.cgi?article=3530&amp;amp;context=expresso &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Kobayashi, Bruce H.|| ||2006||[[An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods]]||Journal Article ||High:Economics||[http://www.law.gmu.edu/assets/files/publications/working_papers/05-11.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Korns, Stephen W.|| ||2009||[[Cyber Operations]]||Journal Article||Low:International Warfare||[http://www.carlisle.army.mil/DIME/documents/Cyber%20Operations%20-%20The%20New%20Balance%20-%20Korns.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Kramer, Franklin D., et. al||||2009||[[Cyberpower and National Security]]||Book||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Lernard, Thomas M.||Rubin, Paul H.||2005||[[An Economic Analysis of Notification Requirements for Data Security Breaches]]||Online Paper||Low:Economics||[http://www.pff.org/issues-pubs/pops/pop12.12datasecurity.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Lernard, Thomas M.||Rubin, Paul H.||2006||[[Much Ado About Notification]]||Journal Article||Low:Economics||[http://www.cato.org/pubs/regulation/regv29n1/v29n1-5.pdf &#039;&#039;Pdf&#039;&#039;]  [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=898208# &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2007||[[Examining the Impact of Website Take-down on Phishing]]||Conf. Paper||Low:Technology||[http://www.ecrimeresearch.org/2007/proceedings/p1_moore.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime07.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2008||[[The Consequence of Non-Cooperation in the Fight Against Phishing]]||Conf. Paper||Low:Technology; Low:Economics||[http://people.seas.harvard.edu/~tmoore/ecrime08.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime08pre.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2009||[[The Impact of Incentives on Notice and Take-down]]||Book Chapter||Moderate:Technology; Low:Law||[http://weis2008.econinfosec.org/papers/MooreImpact.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Defense Initiative||||2009||[[National Cyber Defense Financial Services Workshop Report]]||Independent Report||Moderate:Financial Services Infrastructure; Moderate:Acronym Tolerance||[http://www.cyber.st.dhs.gov/docs/NCDI_FI_Workshop_Report.pdf &#039;&#039;Pdf&#039;&#039;] [http://ncdi.nps.edu/FI_Workshop_Report_100204.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Security Summit Task Force||||2004||[[Information Security Governance]]||Government Report||Moderate:Executive Administration||[http://www.cyber.st.dhs.gov/docs/Information%20Security%20Governance-%20A%20Call%20to%20Action%20(2004).pdf &#039;&#039;Pdf&#039;&#039;] [http://www.criminal-justice-careers.com/resources/InfoSecGov4_04.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Infrastructure Advisory Council||||2004||[[Hardening The Internet]]||Government Report||High:Technology||[http://www.cyber.st.dhs.gov/docs/NIAC%20Internet%20Hardening.pdf  &#039;&#039;Pdf&#039;&#039;] [http://www.dhs.gov/xlibrary/assets/niac/NIAC_HardeningInternetPaper_Jan05.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Institute of Standards and Technology||||2006||[[SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security]]||Government Report||Moderate:Technology||[http://www.cyber.st.dhs.gov/docs/NIST%20Guide%20to%20Supervisory%20and%20Data%20Acquisition-SCADA%20and%20Industrial%20Control%20Systems%20Security%20(2007).pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Research Council||||1999||[[Trust in Cyberspace]]||Independent Report||Moderate:Technology||[http://www.cyber.st.dhs.gov/docs/Trust%20in%20Cyberspace%20Report%201999.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Research Council||||2007||[[Toward a Safer and More Secure Cyberspace]]||Independent Report||Low:Research Processes; Low:Technology||[http://www.cyber.st.dhs.gov/docs/Toward_a_Safer_and_More_Secure_Cyberspace-Full_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Science and Technology Council||||2006||[[Federal Plan for Cyber Security and Information Assurance Research and Development]]||Government Report||Low:Technology||[http://www.cyber.st.dhs.gov/docs/Federal%20R&amp;amp;D%20Plan%202006.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Networking and Information Technology Research and Development||||2009||[[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report]]||Government Report||Low:Technology||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Nye, Joseph||||2010||[[Cyber Power]]||Book Chapter||Low:Technology; Low:Policy||[http://belfercenter.ksg.harvard.edu/files/cyber-power.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Powell, Benjamin||||2005||[[Is Cybersecurity a Public Good]]||Law Review||Low/Moderate:Economics||[http://www.independent.org/pdf/working_papers/57_cyber.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.ciaonet.org/wps/pob03/pob03.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Commission on Critical Infrastructure Protection||||1997||[[Critical Foundations]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PCCIP%20Report%201997.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Information Technology Advisory Council||||2005||[[Cyber Security: A Crisis of Prioritization]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PITAC%20Report%202005.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Romanosky et al.||||2008||[[Do Data Breach Disclosure Laws Reduce Identity Theft]]||Conf. Paper||Moderate:Economics||[http://weis2008.econinfosec.org/papers/Romanosky.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N., et. al||||2004||[[Computers and War]]||Conf. Paper||Moderate:Law||[http://www.ihlresearch.org/ihl/pdfs/schmittetal.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N.||||1999||[[Computer Network Attack and the Use of Force in International Law]]||Law Review||High:Law||[http://www.dtic.mil/cgi-bin/GetTRDoc?AD=ADA471993&amp;amp;Location=U2&amp;amp;doc=GetTRDoc.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N.||||2002||[[Wired Warfare]]||Journal Article||Moderate:Law||[http://www.icrc.org/Web/eng/siteeng0.nsf/htmlall/5C5D5C/$File/365_400_Schmitt.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schneier, Bruce||||2003||[[Beyond Fear]]||Book||None||[http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 &#039;&#039;Scribd&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schneier, Bruce||||2008||[[Schneier on Security]]||Book||None||[http://www.schneier.com/book-sos.html &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schwartz, Paul||Janger, Edward||2007||[[Notification of Data Security Breaches]]||Law Review||Low:Law; Low:Economics||[http://www.michiganlawreview.org/assets/pdfs/105/5/schwartz.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Sklerov, Matthew J.||||2009||[[Solving the Dilemma of State Responses to Cyberattacks]]||Law Review||Moderate:Law; Low:Technology||[http://www.loc.gov/rr/frd/Military_Law/Military_Law_Review/pdf-files/201-fall-2009.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Swire, Peter P.||||2004||[[A Model for When Disclosure Helps Security]]||Law Review||Low/Moderate:Logic||[http://www.rootsecure.net/content/downloads/pdf/disclosure_helps_security.pdf &#039;&#039;Pdf&#039;&#039;][http://papers.ssrn.com/sol3/papers.cfm?abstract_id=531782 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Swire, Peter P.||||2006||[[A Theory of Disclosure for Security and Competitive Reasons]]||Law Review||Low/Moderate:Logic||[http://papers.ssrn.com/sol3/papers.cfm?abstract_id=842228 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Todd, Graham H.||||2009||[[Armed Attack in Cyberspace]]||Law Review||Moderate:Law||[http://www.afjag.af.mil/shared/media/document/AFD-091026-024.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Verizon||||2010||[[2010 Data Breach Investigations Report]]||Industry Report||Low:Technology||[http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Watts, Sean||||2010||[[Combatant Status and Computer Network Attack]]||Law Review||Moderate:Law||[http://www.vjil.org/wp-content/uploads/2010/01/VJIL-50.2-Watts.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||||2009||[[Cyberspace Policy Review]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/Cyberspace_Policy_Review_final.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||||2003||[[The National Strategy to Secure Cyberspace]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/National%20Strategy%20to%20Secure%20Cyberspace%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Zittrain, Jonathan L.||||2008||[[The Future of the Internet and How To Stop It]]||Book||None||[http://futureoftheinternet.org/static/ZittrainTheFutureoftheInternet.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;&#039;&#039;Subcategories:&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Approaches | Approaches-&amp;gt;]][[Regulation/Liability]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Approaches | Approaches-&amp;gt;]][[Private Efforts/Organizations]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Approaches | Approaches-&amp;gt;]][[Government Organizations]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Approaches | Approaches-&amp;gt;]][[International Cooperation]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Approaches | Approaches-&amp;gt;]][[International Law (including Laws of War)]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Approaches | Approaches-&amp;gt;]][[Deterrence]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Approaches | Approaches-&amp;gt;]][[Technology]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Table of Contents | Jump to Table of Contents]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Technology&amp;diff=6324</id>
		<title>Technology</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Technology&amp;diff=6324"/>
		<updated>2010-09-21T14:34:00Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;[[Table of Contents | TOC-&amp;gt;]][[Approaches | Approaches-&amp;gt;]][[Technology]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross||Moore, Tyler||2006||[[The Economics of Information Security]]||Journal Article||Low:Economics||[http://people.seas.harvard.edu/~tmoore/science-econ.pdf  &#039;&#039;Pdf&#039;&#039;] [http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.89.3331&amp;amp;rep=rep1&amp;amp;type=pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Gandal, Neil||||2008||[[An Introduction to Key Themes in the Economics of Cyber Security]]||Book Chapter||Low:Economics||[http://www.tau.ac.il/~gandal/security%20encyclopedia%20entry.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|HP TippingPoint DVLabs||||2010||[[2010 Top Cyber Security Risks Report]]||Industry report||Moderate:Technology||[http://dvlabs.tippingpoint.com/toprisks2010  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2007||[[Examining the Impact of Website Take-down on Phishing]]||Conf. Paper||Low:Technology||[http://www.ecrimeresearch.org/2007/proceedings/p1_moore.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime07.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2008||[[The Consequence of Non-Cooperation in the Fight Against Phishing]]||Conf. Paper||Low:Technology; Low:Economics||[http://people.seas.harvard.edu/~tmoore/ecrime08.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime08pre.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Defense Initiative||||2009||[[National Cyber Defense Financial Services Workshop Report]]||Independent Report||Moderate:Financial Services Infrastructure; Moderate:Acronym Tolerance||[http://www.cyber.st.dhs.gov/docs/NCDI_FI_Workshop_Report.pdf &#039;&#039;Pdf&#039;&#039;] [http://ncdi.nps.edu/FI_Workshop_Report_100204.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Security Summit Task Force||||2004||[[Information Security Governance]]||Government Report||Moderate:Executive Administration||[http://www.cyber.st.dhs.gov/docs/Information%20Security%20Governance-%20A%20Call%20to%20Action%20(2004).pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Infrastructure Advisory Council||||2004||[[Hardening The Internet]]||Government Report||High:Technology||[http://www.cyber.st.dhs.gov/docs/NIAC%20Internet%20Hardening.pdf  &#039;&#039;Pdf&#039;&#039;] [http://www.dhs.gov/xlibrary/assets/niac/NIAC_HardeningInternetPaper_Jan05.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Institute of Standards and Technology||||2006||[[SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security]]||Government Report||Moderate:Technology||[http://www.cyber.st.dhs.gov/docs/NIST%20Guide%20to%20Supervisory%20and%20Data%20Acquisition-SCADA%20and%20Industrial%20Control%20Systems%20Security%20(2007).pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Security Summit Task Force||||2004||[[Information Security Governance]]||Government Report||Moderate:Executive Administration||[http://www.cyber.st.dhs.gov/docs/Information%20Security%20Governance-%20A%20Call%20to%20Action%20(2004).pdf &#039;&#039;Pdf&#039;&#039;] [http://www.criminal-justice-careers.com/resources/InfoSecGov4_04.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Science and Technology Council||||2006||[[Federal Plan for Cyber Security and Information Assurance Research and Development]]||Government Report||Low:Technology||[http://www.cyber.st.dhs.gov/docs/Federal%20R&amp;amp;D%20Plan%202006.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Networking and Information Technology Research and Development||||2009||[[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report]]||Government Report||Low:Technology||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Commission on Critical Infrastructure Protection||||1997||[[Critical Foundations]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PCCIP%20Report%201997.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Information Technology Advisory Council||||2005||[[Cyber Security: A Crisis of Prioritization]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PITAC%20Report%202005.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Verizon||||2010||[[2010 Data Breach Investigations Report]]||Industry Report||Low:Technology||[http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;&#039;&#039;Subcategories:&#039;&#039;&#039;&#039;&#039; &#039;&#039;None&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Table of Contents| Jump to Table of Contents]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Issues&amp;diff=6323</id>
		<title>Issues</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Issues&amp;diff=6323"/>
		<updated>2010-09-21T14:33:45Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;[[Table of Contents | TOC-&amp;gt;]][[Issues]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text &lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross J.||||2008||[[Security Engineering]]||Book||Moderate:Technology; Moderate:Cryptography||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross, et. al|| ||2008||[[Security Economics and the Internal Market]]||Study||Low:Economics||[http://www.enisa.europa.eu/act/sr/reports/econ-sec/economics-sec/at_download/fullReport  &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross||||2001||[[Why Information Security is Hard]]||Conf. Paper||None||[http://www.acsac.org/2001/papers/110.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rja14/Papers/econ.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross||Moore, Tyler||2006||[[The Economics of Information Security]]||Journal Article||Low:Economics||[http://people.seas.harvard.edu/~tmoore/science-econ.pdf &#039;&#039;Pdf&#039;&#039;] [http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.89.3331&amp;amp;rep=rep1&amp;amp;type=pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Arora et al.||||2006||[[Does Information Security Attack Frequency Increase With Vulnerability Disclosure]]||Journal Article||Moderate:Economics||[http://www.heinz.cmu.edu/~rtelang/vuln_freq_ISF.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Aviram, Amitai||Tor, Avishalom||2004||[[Overcoming Impediments to Information Sharing]]||Law Review||Low:Economics||[http://law.haifa.ac.il/faculty/lec_papers/tor/55Ala1.L.Rev.231.pdf &#039;&#039;Pdf&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=435600 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Barkham, Jason||||2001||[[Information Warfare and International Law on the Use of Force]]||Law Review||Moderate:Law||[http://www1.law.nyu.edu/journals/jilp/issues/34/pdf/34_1_b.pdf &#039;&#039;Pdf&#039;&#039;] [http://activeresponse.org/files/34_1_b.pdf &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Beard, Jack M.||||2009||[[Law and War in the Virtual Era]]||Law Review||Low:Law||[http://www.asil.org/ajil/July2009_1selectedpiece.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Bohme, Rainer||||2005||[[Cyber-Insurance Revisited]]||Conf. Paper||High:Economics||[http://infosecon.net/workshop/pdf/15.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Bohme, Rainer||Kataria, Gaurav||2006||[[Models and Measures for Correlation in Cyber-Insurance]]||Conf. Paper||High:Economics||[http://weis2006.econinfosec.org/docs/16.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Bohme, Rainer||Schwartz, Galina||2010||[[Modeling Cyber-Insurance]]||Conf. Paper||High:Economics||[http://www1.inf.tu-dresden.de/~rb21/publications/BS2010_Modeling_Cyber-Insurance_WEIS.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Brown, Davis||||2006||[[A Proposal for an International Convention To Regulate the Use of Information Systems in Armed Conflict]]||Law Review||Moderate:Law||[http://www.harvardilj.org/attach.php?id=59 &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Camp, L. Jean||Lewis, Stephen||2004||[[Economics of Information Security]]||Book||High:Economics||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Camp, L. Jean||Wolfram, Catherine||2004||[[Pricing Security]]||Book Chapter||Low:Economics||[http://books.google.com/books?id=PbzP9tgeDcAC&amp;amp;lpg=PA17&amp;amp;ots=8AOrvEojH5&amp;amp;dq=Economics%20of%20Information%20Security&amp;amp;lr&amp;amp;pg=PA17#v=onepage&amp;amp;q&amp;amp;f=false &#039;&#039;Web&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=894966 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Center for Strategic and International Studies||||2008||[[Securing Cyberspace for the 44th Presidency]]||Independent Report||Low:Policy||[http://www.cyber.st.dhs.gov/docs/081208_securingcyberspace_44.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Clarke, Richard A.||Knake, Robert||2010||[[Cyber War]]||Book||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Clinton, Larry||||Undated||[[Cyber-Insurance Metrics and Impact on Cyber-Security]]||Online Paper||Low:Technology; Low:Law||[http://www.whitehouse.gov/files/documents/cyber/ISA%20-%20Cyber-Insurance%20Metrics%20and%20Impact%20on%20Cyber-Security.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Computer Economics, Inc.||||2007||[[2007 Malware Report]]||Industry Report||None||[http://www.computereconomics.com/article.cfm?id=1224 &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Computing Research Association||||2003||[[Four Grand Challenges in Trustworthy Computing]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/CRA%20Grand%20Challenges%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Commerce||||2010||[[Defense Industrial Base Assessment]]||Government Report||None||[http://www.bis.doc.gov/defenseindustrialbaseprograms/osies/defmarketresearchrpts/final_counterfeit_electronics_report.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||1999||[[An Assessment of International Legal Issues in Information Operations]]||Government Report||Moderate:Law||[http://www.au.af.mil/au/awc/awcgate/dod-io-legal/dod-io-legal.pdf &#039;&#039; Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||2005||[[Strategy for Homeland Defense and Civil Support]]||Government Report||None||[http://www.defense.gov/news/Jun2005/d20050630homeland.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||2007||[[Mission Impact of Foreign Influence on DoD Software]]||Government Report||Low:Defense Policy/Procurement||[http://www.cyber.st.dhs.gov/docs/Defense%20Science%20Board%20Task%20Force%20-%20Report%20on%20Mission%20Impact%20of%20Foreign%20Influence%20on%20DoD%20Software%20(2007).pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Homeland Security||||2003||[[The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets]]||Government Report||None||[http://www.dhs.gov/xlibrary/assets/Physical_Strategy.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Homeland Security||||2009||[[A Roadmap for Cybersecurity Research]]||Government Report||Low:Technology||[http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Deputy Chief of Staff for Intelligence||||2006||[[Critical Infrastructure Threats and Terrorism]]||Government Report||Low:Organizational Analysis; Low:Risk Management||[http://www.fas.org/irp/threat/terrorism/sup2.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Dörmann, Knut||||2004||[[Applicability of the Additional Protocols to Computer Network Attacks]]||Independent Report||Low:Law||[http://www.icrc.org/Web/eng/siteeng0.nsf/htmlall/68LG92/$File/ApplicabilityofIHLtoCNA.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Dunlap, Charles J. Jr.||||2009||[[Towards a Cyberspace Legal Regime in the Twenty-First Century]]||Speech||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Energetics Inc.||||2006||[[Roadmap to Secure Control Systems in the Energy Sector]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/DOE%20Roadmap%202006.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Epstein, Richard A.||Brown, Thomas P.||2008||[[Cybersecurity in the Payment Card Industry]]||Law Review||Low:Law; Low:Economics||[http://lawreview.uchicago.edu/issues/archive/v75/75_1/EpsteinArticle.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Financial Services Sector Coordinating Council for Critical Infrastructure Protection||||2008||[[Research Agenda for the Banking and Finance Sector]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/RD_Agenda-FINAL.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Franklin, Jason, et. al||||2007||[[An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants]]||Conf. Paper||Low:Statistics; Low:Economics||[http://sparrow.ece.cmu.edu/group/pub/franklin_paxson_perrig_savage_miscreants.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cs.cmu.edu/~jfrankli/acmccs07/ccs07_franklin_eCrime.pdf  &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Gandal, Neil||||2008||[[An Introduction to Key Themes in the Economics of Cyber Security]]||Book Chapter||Low:Economics||[http://www.tau.ac.il/~gandal/security%20encyclopedia%20entry.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Grady, Mark F.||Parisi, Francesco||2006||[[The Law and Economics of Cybersecurity]]||Book||Low:Economics; Low:Law||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Granick, Jennifer Stisa||||2005||[[The Price of Restricting Vulnerability Publications]]||Law Review||Low/Moderate:Law||[http://www.ijclp.net/files/ijclp_web-doc_10-cy-2004.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Hollis, Duncan B.||||2007||[[Why States Need an International Law for Information Operations]]||Law Review||Moderate:Law||[http://legacy.lclark.edu/org/lclr/objects/LCB_11_4_Art7_Hollis.pdf  &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|HP TippingPoint DVLabs||||2010||[[2010 Top Cyber Security Risks Report]]||Industry report||Moderate:Technology||[http://dvlabs.tippingpoint.com/toprisks2010  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Institute for Information Infrastructure Protection||||2003||[[Cyber Security Research and Development Agenda]]||Independent Report||Low/None:Technology||[http://www.cyber.st.dhs.gov/docs/I3P%20Research%20Agenda%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Johnson, Eric M.||||2008||[[Managing Information Risk and the Economics of Security]]||Book||High:Economics||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Johnson, Vincent R.||||2005||[[Cybersecurity, Identity Theft, and the Limits of Tort Liability]]||Law Review||Moderate:Law||[http://www.stmarytx.edu/law/pdf/Johnsoncyber.pdf &#039;&#039;Pdf&#039;&#039;] [http://law.bepress.com/cgi/viewcontent.cgi?article=3530&amp;amp;context=expresso &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Kobayashi, Bruce H.|| ||2006||[[An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods]]||Journal Article ||High:Economics||[http://www.law.gmu.edu/assets/files/publications/working_papers/05-11.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Korns, Stephen W.|| ||2009||[[Cyber Operations]]||Journal Article||Low:International Warfare||[http://www.carlisle.army.mil/DIME/documents/Cyber%20Operations%20-%20The%20New%20Balance%20-%20Korns.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Kramer, Franklin D., et. al||||2009||[[Cyberpower and National Security]]||Book||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Lernard, Thomas M.||Rubin, Paul H.||2005||[[An Economic Analysis of Notification Requirements for Data Security Breaches]]||Online Paper||Low:Economics||[http://www.pff.org/issues-pubs/pops/pop12.12datasecurity.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Lernard, Thomas M.||Rubin, Paul H.||2006||[[Much Ado About Notification]]||Journal Article||Low:Economics||[http://www.cato.org/pubs/regulation/regv29n1/v29n1-5.pdf  &#039;&#039;Pdf&#039;&#039;]  [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=898208# &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|McAfee, Inc.||||2010||[[McAfee Threats Report]]||Industry Report||None||[http://www.mcafee.com/us/local_content/reports/2010q1_threats_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler, et. al||||2009||[[The Economics of Online Crime]]||Journal Article||Low:Technology||[http://people.seas.harvard.edu/~tmoore/jep09.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2007||[[Examining the Impact of Website Take-down on Phishing]]||Conf. Paper||Low:Technology||[http://www.ecrimeresearch.org/2007/proceedings/p1_moore.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime07.pdf  &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2008||[[The Consequence of Non-Cooperation in the Fight Against Phishing]]||Conf. Paper||Low:Technology; Low:Economics||[http://people.seas.harvard.edu/~tmoore/ecrime08.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime08pre.pdf  &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2009||[[The Impact of Incentives on Notice and Take-down]]||Book Chapter||Moderate:Technology; Low:Law||[http://weis2008.econinfosec.org/papers/MooreImpact.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Defense Initiative||||2009||[[National Cyber Defense Financial Services Workshop Report]]||Independent Report||Moderate:Financial Services Infrastructure; Moderate:Acronym Tolerance||[http://www.cyber.st.dhs.gov/docs/NCDI_FI_Workshop_Report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Security Summit Task Force||||2004||[[Information Security Governance]]||Government Report||Moderate:Executive Administration||[http://www.cyber.st.dhs.gov/docs/Information%20Security%20Governance-%20A%20Call%20to%20Action%20(2004).pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Infrastructure Advisory Council||||2004||[[Hardening The Internet]]||Government Report||High:Technology||[http://www.cyber.st.dhs.gov/docs/NIAC%20Internet%20Hardening.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Institute of Standards and Technology||||2006||[[SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security]]||Government Report||Moderate:Technology||[http://www.cyber.st.dhs.gov/docs/NIST%20Guide%20to%20Supervisory%20and%20Data%20Acquisition-SCADA%20and%20Industrial%20Control%20Systems%20Security%20(2007).pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Research Council||||1999||[[Trust in Cyberspace]]||Independent Report||Moderate:Technology||[http://www.cyber.st.dhs.gov/docs/Trust%20in%20Cyberspace%20Report%201999.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Research Council||||2007||[[Toward a Safer and More Secure Cyberspace]]||Independent Report||Low:Research Processes; Low:Technology||[http://www.cyber.st.dhs.gov/docs/Toward_a_Safer_and_More_Secure_Cyberspace-Full_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Science and Technology Council||||2006||[[Federal Plan for Cyber Security and Information Assurance Research and Development]]||Government Report||Low:Technology||[http://www.cyber.st.dhs.gov/docs/Federal%20R&amp;amp;D%20Plan%202006.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Networking and Information Technology Research and Development||||2009||[[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report]]||Government Report||Low:Technology||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Nye, Joseph||||2010||[[Cyber Power]]||Book Chapter||Low:Technology; Low:Policy||[http://belfercenter.ksg.harvard.edu/files/cyber-power.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Powell, Benjamin||||2005||[[Is Cybersecurity a Public Good]]||Law Review||Low/Moderate:Economics||[http://www.independent.org/pdf/working_papers/57_cyber.pdf  &#039;&#039;Pdf&#039;&#039;] [http://www.ciaonet.org/wps/pob03/pob03.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Commission on Critical Infrastructure Protection||||1997||[[Critical Foundations]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PCCIP%20Report%201997.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Information Technology Advisory Council||||2005||[[Cyber Security: A Crisis of Prioritization]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PITAC%20Report%202005.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Romanosky et al.||||2008||[[Do Data Breach Disclosure Laws Reduce Identity Theft]]||Conf. Paper||Moderate:Economics||[http://weis2008.econinfosec.org/papers/Romanosky.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Rotenberg et. al.||||2010||[[The Cyber War Threat Has Been Grossly Exaggerated]]||Debate||None||[http://intelligencesquaredus.org/index.php/past-debates/cyber-war-threat-has-been-grossly-exaggerated/ &#039;&#039;Audio/Transcript&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N., et. al||||2004||[[Computers and War]]||Conf. Paper||Moderate:Law||[http://www.ihlresearch.org/ihl/pdfs/schmittetal.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N.||||1999||[[Computer Network Attack and the Use of Force in International Law]]||Law Review||High:Law||[http://www.dtic.mil/cgi-bin/GetTRDoc?AD=ADA471993&amp;amp;Location=U2&amp;amp;doc=GetTRDoc.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N.||||2002||[[Wired Warfare]]||Journal Article||Moderate:Law||[http://www.icrc.org/Web/eng/siteeng0.nsf/htmlall/5C5D5C/$File/365_400_Schmitt.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schneier, Bruce||||2003||[[Beyond Fear]]||Book||None||[http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 &#039;&#039;Scribd&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schneier, Bruce||||2008||[[Schneier on Security]]||Book||None||[http://www.schneier.com/book-sos.html &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schwartz, Paul||Janger, Edward||2007||[[Notification of Data Security Breaches]]||Law Review||Low:Law; Low:Economics||[http://www.michiganlawreview.org/assets/pdfs/105/5/schwartz.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Sklerov, Matthew J.|| ||2009||[[Solving the Dilemma of State Responses to Cyberattacks]]||Law Review||Moderate:Law; Low:Technology||[http://www.loc.gov/rr/frd/Military_Law/Military_Law_Review/pdf-files/201-fall-2009.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Stohl, Michael||||2006||[[Cyber Terrorism]]||Journal Article||None||[http://www.ingentaconnect.com/content/klu/cris/2006/00000046/F0020004/00009061 &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Swire, Peter P.||||2004||[[A Model for When Disclosure Helps Security]]||Law Review||Low/Moderate:Logic||[http://www.rootsecure.net/content/downloads/pdf/disclosure_helps_security.pdf &#039;&#039;Pdf&#039;&#039;][http://papers.ssrn.com/sol3/papers.cfm?abstract_id=531782 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Swire, Peter P.||||2006||[[A Theory of Disclosure for Security and Competitive Reasons]]||Law Review||Low/Moderate:Logic||[http://papers.ssrn.com/sol3/papers.cfm?abstract_id=842228 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Symantec Corporation||||2010||[[Symantec Global Internet Security Threat Report]]||Industry Report||Low/Moderate:Technology||[http://www4.symantec.com/Vrt/wl?tu_id=SUKX1271711282503126202 &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Telang, Rahul||Wattal, Sunil||2007||[[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors]]||Journal Article||Moderate:Economics||[http://infosecon.net/workshop/pdf/telang_wattal.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Thomas, Rob||Martin, Jerry||2006||[[The Underground Economy]]||Journal Article||Low:Technology||[http://www.usenix.org/publications/login/2006-12/openpdfs/cymru.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Todd, Graham H.|| ||2009||[[Armed Attack in Cyberspace]]||Law Review||Moderate:Law||[http://www.afjag.af.mil/shared/media/document/AFD-091026-024.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Trend Micro Incorporated||||2010||[[Trend Micro Annual Report]]||Industry Report||Moderate:Technology||[http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/2009s_most_persistent_malware_threats__march_2010_.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|United States Secret Service||||2004||[[Insider Threat Study]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/its_report_040820.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|van Eeten, Michel J. G.||Bauer, Johannes M.||2008||[[Economics of Malware]]||Non-US Govt. Report||Moderate:Economics||[http://www.oecd.org/dataoecd/53/17/40722462.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Varian, Hal||||2000||[[Managing Online Security Risks]]||Newspaper Article||None||[http://people.ischool.berkeley.edu/~hal/people/hal/NYTimes/2000-06-01.html &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Varian, Hal||||2004||[[System Reliability and Free Riding]]||Book Chapter||High:Economics||[http://www.sims.berkeley.edu/resources/affiliates/workshops/econsecurity/econws/48-old.pdf &#039;&#039;Pdf&#039;&#039;]   [http://people.ischool.berkeley.edu/~hal/Papers/2004/reliability  &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Verizon||||2010||[[2010 Data Breach Investigations Report]]||Industry Report||Low:Technology||[http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Watts, Sean|| ||2010||[[Combatant Status and Computer Network Attack]]||Law Review||Moderate:Law||[http://www.vjil.org/wp-content/uploads/2010/01/VJIL-50.2-Watts.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||||2009||[[Cyberspace Policy Review]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/Cyberspace_Policy_Review_final.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||||2003||[[The National Strategy to Secure Cyberspace]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/National%20Strategy%20to%20Secure%20Cyberspace%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Zittrain, Jonathan L.||||2008||[[The Future of the Internet and How To Stop It]]||Book||None||[http://futureoftheinternet.org/static/ZittrainTheFutureoftheInternet.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;&#039;&#039;Subcategories:&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Metrics]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]][[Risk Management and Investment]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]][[Incentives]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]][[Insurance]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]][[Behavioral Economics]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]][[Market Failure]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Supply Chain Issues]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Usability/Human Factors]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Psychology and Politics]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Information Sharing/Disclosure]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Public-Private Cooperation]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Attribution]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Identity Management]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Privacy]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Cybercrime]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Cyberwar]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Espionage | Espionage-&amp;gt;]][[Government to Government]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Espionage | Espionage-&amp;gt;]][[Industrial]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Issues | Issues-&amp;gt;]][[Espionage | Espionage-&amp;gt;]][[Media Perceptions]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Table of Contents| Jump to Table of Contents]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Cybercrime&amp;diff=6322</id>
		<title>Cybercrime</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Cybercrime&amp;diff=6322"/>
		<updated>2010-09-21T14:33:31Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;[[Table of Contents | TOC-&amp;gt;]][[Issues | Issues-&amp;gt;]][[Cybercrime]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross J.||||2008||[[Security Engineering]]||Book||Moderate:Technology; Moderate:Cryptography||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross, et. al|| ||2008||[[Security Economics and the Internal Market]]||Study||Low:Economics||[http://www.enisa.europa.eu/act/sr/reports/econ-sec/economics-sec/at_download/fullReport  &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Deputy Chief of Staff for Intelligence||||2006||[[Critical Infrastructure Threats and Terrorism]]||Government Report||Low:Organizational Analysis; Low:Risk Management||[http://www.fas.org/irp/threat/terrorism/sup2.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Epstein, Richard A.||Brown, Thomas P.||2008||[[Cybersecurity in the Payment Card Industry]]||Law Review||Low:Law; Low:Economics||[http://lawreview.uchicago.edu/issues/archive/v75/75_1/EpsteinArticle.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Franklin, Jason, et. al||||2007||[[An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants]]||Conf. Paper||Low:Statistics; Low:Economics||[http://sparrow.ece.cmu.edu/group/pub/franklin_paxson_perrig_savage_miscreants.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cs.cmu.edu/~jfrankli/acmccs07/ccs07_franklin_eCrime.pdf  &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|HP TippingPoint DVLabs||||2010||[[2010 Top Cyber Security Risks Report]]||Industry report||Moderate:Technology||[http://dvlabs.tippingpoint.com/toprisks2010  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Johnson, Eric M.||||2008||[[Managing Information Risk and the Economics of Security]]||Book||High:Economics||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Kramer, Franklin D., et. al||||2009||[[Cyberpower and National Security]]||Book||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|McAfee, Inc.||||2010||[[McAfee Threats Report]]||Industry Report||None||[http://www.mcafee.com/us/local_content/reports/2010q1_threats_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2007||[[Examining the Impact of Website Take-down on Phishing]]||Conf. Paper||Low:Technology||[http://www.ecrimeresearch.org/2007/proceedings/p1_moore.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime07.pdf  &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2008||[[The Consequence of Non-Cooperation in the Fight Against Phishing]]||Conf. Paper||Low:Technology; Low:Economics||[http://people.seas.harvard.edu/~tmoore/ecrime08.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime08pre.pdf  &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2009||[[The Impact of Incentives on Notice and Take-down]]||Book Chapter||Moderate:Technology; Low:Law||[http://weis2008.econinfosec.org/papers/MooreImpact.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler, et. al||||2009||[[The Economics of Online Crime]]||Journal Article||Low:Technology||[http://people.seas.harvard.edu/~tmoore/jep09.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Research Council||||2007||[[Toward a Safer and More Secure Cyberspace]]||Independent Report||Low:Research Processes; Low:Technology||[http://www.cyber.st.dhs.gov/docs/Toward_a_Safer_and_More_Secure_Cyberspace-Full_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Symantec Corporation||||2010||[[Symantec Global Internet Security Threat Report]]||Industry Report||Low/Moderate:Technology||[http://www4.symantec.com/Vrt/wl?tu_id=SUKX1271711282503126202 &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Thomas, Rob||Martin, Jerry||2006||[[The Underground Economy]]||Journal Article||Low:Technology||[http://www.usenix.org/publications/login/2006-12/openpdfs/cymru.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Trend Micro Incorporated||||2010||[[Trend Micro Annual Report]]||Industry Report||Moderate:Technology||[http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/2009s_most_persistent_malware_threats__march_2010_.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Verizon||||2010||[[2010 Data Breach Investigations Report]]||Industry Report||Low:Technology||[http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;&#039;&#039;Subcategories:&#039;&#039;&#039;&#039;&#039; &#039;&#039;None&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Table of Contents| Jump to Table of Contents]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Resource_by_Type&amp;diff=6321</id>
		<title>Resource by Type</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Resource_by_Type&amp;diff=6321"/>
		<updated>2010-09-21T14:33:08Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;[[Table of Contents | TOC-&amp;gt;]][[Resource by Type]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross J.|| ||2008||[[Security Engineering]]||Book||Moderate:Technology; Moderate:Cryptography|| N/A&lt;br /&gt;
|-&lt;br /&gt;
|Camp, L. Jean || Lewis, Stephen||2004||[[Economics of Information Security]]||Book||High:Economics|| N/A&lt;br /&gt;
|-&lt;br /&gt;
|Center for Strategic and International Studies||  ||2008||[[Securing Cyberspace for the 44th Presidency]]||Independent Report||Low:Policy||[http://www.cyber.st.dhs.gov/docs/081208_securingcyberspace_44.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Clarke, Richard A. || Knake, Robert ||2010||[[Cyber War]]||Book||None|| N/A&lt;br /&gt;
|-&lt;br /&gt;
|Computer Economics, Inc.||  ||2007||[[2007 Malware Report]]||Industry Report||None||[http://www.computereconomics.com/article.cfm?id=1224 &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Computing Research Association||  ||2003||[[Four Grand Challenges in Trustworthy Computing]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/CRA%20Grand%20Challenges%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Commerce||  ||2010||[[Defense Industrial Base Assessment]]||Government Report||None||[http://www.bis.doc.gov/defenseindustrialbaseprograms/osies/defmarketresearchrpts/final_counterfeit_electronics_report.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||1999||[[An Assessment of International Legal Issues in Information Operations]]||Government Report||Moderate:Law||[http://www.au.af.mil/au/awc/awcgate/dod-io-legal/dod-io-legal.pdf &#039;&#039; Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||  ||2005||[[Strategy for Homeland Defense and Civil Support]]||Government Report||None||[http://www.defense.gov/news/Jun2005/d20050630homeland.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||  ||2007||[[Mission Impact of Foreign Influence on DoD Software]]||Government Report||Low:Defense Policy/Procurement||[http://www.cyber.st.dhs.gov/docs/Defense%20Science%20Board%20Task%20Force%20-%20Report%20on%20Mission%20Impact%20of%20Foreign%20Influence%20on%20DoD%20Software%20(2007).pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Homeland Security||  ||2003||[[The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets]]||Government Report||None||[http://www.dhs.gov/xlibrary/assets/Physical_Strategy.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Homeland Security||  ||2009||[[A Roadmap for Cybersecurity Research]]||Government Report||Low:Technology||[http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Deputy Chief of Staff for Intelligence||  ||2006||[[Critical Infrastructure Threats and Terrorism]]||Government Report||Low:Organizational Analysis; Low:Risk Management||[http://www.fas.org/irp/threat/terrorism/sup2.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Dörmann, Knut||||2004||[[Applicability of the Additional Protocols to Computer Network Attacks]]||Independent Report||Low:Law||[http://www.icrc.org/Web/eng/siteeng0.nsf/htmlall/68LG92/$File/ApplicabilityofIHLtoCNA.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Energetics Inc.||  ||2006||[[Roadmap to Secure Control Systems in the Energy Sector]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/DOE%20Roadmap%202006.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Financial Services Sector Coordinating Council for Critical Infrastructure Protection||  ||2008||[[Research Agenda for the Banking and Finance Sector]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/RD_Agenda-FINAL.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Grady, Mark F. || Parisi, Francesco ||2006||[[The Law and Economics of Cybersecurity]]||Book||Low:Economics; Low:Law|| N/A&lt;br /&gt;
|-&lt;br /&gt;
|HP TippingPoint DVLabs||||2010||[[2010 Top Cyber Security Risks Report]]||Industry report||Moderate:Technology||[http://dvlabs.tippingpoint.com/toprisks2010  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Institute for Information Infrastructure Protection||  ||2003||[[Cyber Security Research and Development Agenda]]||Independent Report||Low/None:Technology||[http://www.cyber.st.dhs.gov/docs/I3P%20Research%20Agenda%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Johnson, Eric M. || || 2008 ||[[Managing Information Risk and the Economics of Security]]||Book||High:Economics|| N/A&lt;br /&gt;
|-&lt;br /&gt;
|Kramer, Franklin D., et. al || ||2009||[[Cyberpower and National Security]]||Book||None|| N/A&lt;br /&gt;
|-&lt;br /&gt;
|McAfee, Inc.||  ||2010||[[McAfee Threats Report]]||Industry Report||None||[http://www.mcafee.com/us/local_content/reports/2010q1_threats_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Defense Initiative||  ||2009||[[National Cyber Defense Financial Services Workshop Report]]||Independent Report||Moderate:Financial Services Infrastructure; Moderate:Acronym Tolerance||[http://www.cyber.st.dhs.gov/docs/NCDI_FI_Workshop_Report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Security Summit Task Force||  ||2004||[[Information Security Governance]]||Government Report||Moderate:Executive Administration||[http://www.cyber.st.dhs.gov/docs/Information%20Security%20Governance-%20A%20Call%20to%20Action%20(2004).pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Infrastructure Advisory Council||  ||2004||[[Hardening The Internet]]||Government Report||High:Technology||[http://www.cyber.st.dhs.gov/docs/NIAC%20Internet%20Hardening.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Institute of Standards and Technology||  ||2006||[[SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security]]||Government Report||Moderate:Technology||[http://www.cyber.st.dhs.gov/docs/NIST%20Guide%20to%20Supervisory%20and%20Data%20Acquisition-SCADA%20and%20Industrial%20Control%20Systems%20Security%20(2007).pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Research Council||  ||1999||[[Trust in Cyberspace]]||Independent Report||Moderate:Technology||[http://www.cyber.st.dhs.gov/docs/Trust%20in%20Cyberspace%20Report%201999.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Research Council||  ||2007||[[Toward a Safer and More Secure Cyberspace]]||Independent Report||Low:Research Processes; Low:Technology||[http://www.cyber.st.dhs.gov/docs/Toward_a_Safer_and_More_Secure_Cyberspace-Full_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Science and Technology Council||  ||2006||[[Federal Plan for Cyber Security and Information Assurance Research and Development]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/Federal%20R&amp;amp;D%20Plan%202006.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Networking and Information Technology Research and Development||  ||2009||[[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Commission on Critical Infrastructure Protection||  ||1997||[[Critical Foundations]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PCCIP%20Report%201997.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Information Technology Advisory Council||  ||2005||[[Cyber Security: A Crisis of Prioritization]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PITAC%20Report%202005.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schneier, Bruce || ||2003||[[Beyond Fear]]||Book||None||[http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 &#039;&#039;Scribd&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schneier, Bruce || ||2008||[[Schneier on Security]]||Book||None||[http://www.schneier.com/book-sos.html &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Symantec Corporation||  ||2010||[[Symantec Global Internet Security Threat Report]]||Industry Report||Low/Moderate:Technology||[http://www4.symantec.com/Vrt/wl?tu_id=SUKX1271711282503126202 &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Trend Micro Incorporated||  ||2010||[[Trend Micro Annual Report]]||Industry Report||Moderate:Technology||[http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/2009s_most_persistent_malware_threats__march_2010_.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|United States Secret Service||  ||2004||[[Insider Threat Study]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/its_report_040820.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|van Eeten, Michel J. G.||Bauer, Johannes M.||2008||[[Economics of Malware]]||Non-US Govt. Report||Moderate:Economics||[http://www.oecd.org/dataoecd/53/17/40722462.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Verizon||||2010||[[2010 Data Breach Investigations Report]]||Industry Report||Low:Technology||[http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||  ||2003||[[The National Strategy to Secure Cyberspace]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/National%20Strategy%20to%20Secure%20Cyberspace%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||  ||2010||[[The Comprehensive National Cybersecurity Initiative]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/CNCI-Cybersecurity.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||  ||2009||[[Cyberspace Policy Review]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/Cyberspace_Policy_Review_final.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Zittrain, Jonathan L.|| ||2008||[[The Future of the Internet and How To Stop It]]||Book||None||[http://futureoftheinternet.org/static/ZittrainTheFutureoftheInternet.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;&#039;&#039;Subcategories:&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Resource by Type | Resource by Type-&amp;gt;]][[Government Reports and Documents | Government Reports and Documents-&amp;gt;]][[US Government Reports and Documents]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Resource by Type | Resource by Type-&amp;gt;]][[Government Reports and Documents | Government Reports and Documents-&amp;gt;]][[Non-US Government Reports and Documents]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Resource by Type | Resource by Type-&amp;gt;]][[Independent Report]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Resource by Type | Resource by Type-&amp;gt;]][[Industry Reports]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Resource by Type | Resource by Type-&amp;gt;]][[Books]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Table of Contents | Jump to Table of Contents]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Industry_Reports&amp;diff=6320</id>
		<title>Industry Reports</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Industry_Reports&amp;diff=6320"/>
		<updated>2010-09-21T14:32:41Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;[[Table of Contents | TOC-&amp;gt;]][[Resource by Type | Resource by Type-&amp;gt;]][[Industry Reports]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Organization&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Computer Economics, Inc.||2007||[[2007 Malware Report]]||Industry Report||None||[http://www.computereconomics.com/article.cfm?id=1224 &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|HP TippingPoint DVLabs||2010||[[2010 Top Cyber Security Risks Report]]||Industry report||Moderate:Technology||[http://dvlabs.tippingpoint.com/toprisks2010  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|McAfee, Inc.||2010||[[McAfee Threats Report]]||Industry Report||None||[http://www.mcafee.com/us/local_content/reports/2010q1_threats_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Symantec Corporation||2010||[[Symantec Global Internet Security Threat Report]]||Industry Report||Low/Moderate:Technology||[http://www4.symantec.com/Vrt/wl?tu_id=SUKX1271711282503126202 &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Trend Micro Incorporated||2010||[[Trend Micro Annual Report]]||Industry Report||Moderate:Technology||[http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/2009s_most_persistent_malware_threats__march_2010_.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Verizon||2010||[[2010 Data Breach Investigations Report]]||Industry Report||Low:Technology||[http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;&#039;&#039;Subcategories:&#039;&#039;&#039;&#039;&#039; &#039;&#039;None&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Table of Contents | Jump to Table of Contents]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Industry_Reports&amp;diff=6319</id>
		<title>Industry Reports</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Industry_Reports&amp;diff=6319"/>
		<updated>2010-09-21T14:32:29Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;[[Table of Contents | TOC-&amp;gt;]][[Resource by Type | Resource by Type-&amp;gt;]][[Industry Reports]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Organization&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Computer Economics, Inc.||2007||[[2007 Malware Report]]||Industry Report||None||[http://www.computereconomics.com/article.cfm?id=1224 &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|HP TippingPoint DVLabs||||2010||[[2010 Top Cyber Security Risks Report]]||Industry report||Moderate:Technology||[http://dvlabs.tippingpoint.com/toprisks2010  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|McAfee, Inc.||2010||[[McAfee Threats Report]]||Industry Report||None||[http://www.mcafee.com/us/local_content/reports/2010q1_threats_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Symantec Corporation||2010||[[Symantec Global Internet Security Threat Report]]||Industry Report||Low/Moderate:Technology||[http://www4.symantec.com/Vrt/wl?tu_id=SUKX1271711282503126202 &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Trend Micro Incorporated||2010||[[Trend Micro Annual Report]]||Industry Report||Moderate:Technology||[http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/2009s_most_persistent_malware_threats__march_2010_.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Verizon||2010||[[2010 Data Breach Investigations Report]]||Industry Report||Low:Technology||[http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;&#039;&#039;Subcategories:&#039;&#039;&#039;&#039;&#039; &#039;&#039;None&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Table of Contents | Jump to Table of Contents]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6318</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6318"/>
		<updated>2010-09-21T14:31:42Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Categorization */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=hptippingpoint:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
* Approaches: [[Technology]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Phishing | Phishing]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Social_Engineering | Social Engineering]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In 2010, information security threats are striking networks with more sophisticated techniques than ever and exploit reports continue to dominate the media.  The collective findings described within this report establish the fact that the proliferation of technology, along with the quick and effortless manner in which that technology is accessed, is dramatically and negatively impacting security. While we are not advocates for making technology more difficult, we do advocate implementing common sense security policies and technologies that battle well-known and new threats. This report evaluates some of the most significant security liabilities that the enterprise is facing today. The report focuses on four key areas:&lt;br /&gt;
* Increased Consumerization of Enterprise Computing&lt;br /&gt;
* Prolonged and Persistent Targeting of Web Applications&lt;br /&gt;
* Increased Organization and Sophistication of Attackers&lt;br /&gt;
* The Unrelenting Presence of Legacy Threats&lt;br /&gt;
In addition to explaining how and where the enterprise is vulnerable, the report provides insights into how organizations can protect themselves&lt;br /&gt;
from attack, including what the next generation of computing should look like to maximize security for the corporate network.&lt;br /&gt;
&lt;br /&gt;
===Increased Consumerization of Enterprise Computing===&lt;br /&gt;
Some of the most serious information security issues&lt;br /&gt;
the research team has seen this year stem from the&lt;br /&gt;
increasingly high use of consumer technologies within&lt;br /&gt;
the enterprise. For example, there are several thousand&lt;br /&gt;
organizations that utilize Facebook, Twitter, WordPress,&lt;br /&gt;
and iTunes for promotion and brand awareness. While&lt;br /&gt;
these technologies may offer a wealth of marketing&lt;br /&gt;
recognition, they also open the door to a multitude&lt;br /&gt;
of security risks. Another trend impacting enterprise&lt;br /&gt;
IT department is an “anything goes” mentality that&lt;br /&gt;
allows users to download and manage applications&lt;br /&gt;
and programs of their choosing. While some of&lt;br /&gt;
these applications may be fine, and may even boost&lt;br /&gt;
productivity, an overwhelming majority of them are a&lt;br /&gt;
significant liability to corporate networks.&lt;br /&gt;
===Web Applications continue to be highly attractive targets===&lt;br /&gt;
The team highlighted the risks of running Web&lt;br /&gt;
applications in last year’s Threat Report. Our current&lt;br /&gt;
research indicates that Web applications continue to&lt;br /&gt;
pose one of the biggest risks to corporate networks.&lt;br /&gt;
Web applications offer an easy way for organizations&lt;br /&gt;
to create an interactive relationship between&lt;br /&gt;
constituents such as customers, employees, and&lt;br /&gt;
partners, and their back-end systems. Because Web&lt;br /&gt;
application systems are relatively easy to build and&lt;br /&gt;
offer inexpensive extensibility, they yield a great deal of&lt;br /&gt;
value and functionality. Because of this, the number of&lt;br /&gt;
Web applications continues to steadily grow.&lt;br /&gt;
===Attackers are more organized and sophisticated===&lt;br /&gt;
One of the more alarming trends observed in the&lt;br /&gt;
previous six months is the increased sophistication&lt;br /&gt;
of attacks. Attackers have not only become more&lt;br /&gt;
organized, they are also increasingly subversive and&lt;br /&gt;
inconspicuous in the way they execute their attacks.&lt;br /&gt;
The attacks are so sophisticated and subtle that few&lt;br /&gt;
victims realize they are under attack until it is too late. It&lt;br /&gt;
is increasingly common to hear of attackers remaining&lt;br /&gt;
inside a compromised organization for months,&lt;br /&gt;
gathering information with which they design and build&lt;br /&gt;
even more sophisticated attacks. Once the desired&lt;br /&gt;
information is obtained, the attackers launch exploits&lt;br /&gt;
that are both more devastating and more covert.&lt;br /&gt;
&lt;br /&gt;
Attack sophistication has increased across the board,&lt;br /&gt;
from client side-attacks such as malicious JavaScript,&lt;br /&gt;
to server-side attacks like PHP file include. This report&lt;br /&gt;
includes examples of real-world attack techniques&lt;br /&gt;
employed by these increasingly sophisticated attackers&lt;br /&gt;
&lt;br /&gt;
===Legacy attacks still a threat===&lt;br /&gt;
Despite the rising sophistication of attacks, it is still&lt;br /&gt;
worth highlighting that over the sample period of this&lt;br /&gt;
report, the number of attacks from well-known legacy&lt;br /&gt;
threats continues to plague computer systems. While&lt;br /&gt;
many of these attacks are well understood and well&lt;br /&gt;
protected against, it is not unheard of to see large&lt;br /&gt;
organizations as the source of some of these attacks,&lt;br /&gt;
indicating that when large organizations implement&lt;br /&gt;
new systems without threat management controls,&lt;br /&gt;
the systems are quickly infected with familiar threats.&lt;br /&gt;
While this is an extreme example, it highlights the&lt;br /&gt;
need for continued diligence against well-known&lt;br /&gt;
threats, ideally addressing them with strong patch and&lt;br /&gt;
configuration management policies.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;br /&gt;
&lt;br /&gt;
While the sections of the report which explain in detail how attackers hide exploits in seemingly innocuous code require some technical expertise, there is a very clear explanation of how such an exploit is downloaded and executed on a victim&#039;s computer within the corporate firewall that requires no special expertise to understand. &#039;&#039;See&#039;&#039; page 27.&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6317</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6317"/>
		<updated>2010-09-21T14:30:45Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Additional Notes and Highlights */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=hptippingpoint:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Phishing | Phishing]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Social_Engineering | Social Engineering]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In 2010, information security threats are striking networks with more sophisticated techniques than ever and exploit reports continue to dominate the media.  The collective findings described within this report establish the fact that the proliferation of technology, along with the quick and effortless manner in which that technology is accessed, is dramatically and negatively impacting security. While we are not advocates for making technology more difficult, we do advocate implementing common sense security policies and technologies that battle well-known and new threats. This report evaluates some of the most significant security liabilities that the enterprise is facing today. The report focuses on four key areas:&lt;br /&gt;
* Increased Consumerization of Enterprise Computing&lt;br /&gt;
* Prolonged and Persistent Targeting of Web Applications&lt;br /&gt;
* Increased Organization and Sophistication of Attackers&lt;br /&gt;
* The Unrelenting Presence of Legacy Threats&lt;br /&gt;
In addition to explaining how and where the enterprise is vulnerable, the report provides insights into how organizations can protect themselves&lt;br /&gt;
from attack, including what the next generation of computing should look like to maximize security for the corporate network.&lt;br /&gt;
&lt;br /&gt;
===Increased Consumerization of Enterprise Computing===&lt;br /&gt;
Some of the most serious information security issues&lt;br /&gt;
the research team has seen this year stem from the&lt;br /&gt;
increasingly high use of consumer technologies within&lt;br /&gt;
the enterprise. For example, there are several thousand&lt;br /&gt;
organizations that utilize Facebook, Twitter, WordPress,&lt;br /&gt;
and iTunes for promotion and brand awareness. While&lt;br /&gt;
these technologies may offer a wealth of marketing&lt;br /&gt;
recognition, they also open the door to a multitude&lt;br /&gt;
of security risks. Another trend impacting enterprise&lt;br /&gt;
IT department is an “anything goes” mentality that&lt;br /&gt;
allows users to download and manage applications&lt;br /&gt;
and programs of their choosing. While some of&lt;br /&gt;
these applications may be fine, and may even boost&lt;br /&gt;
productivity, an overwhelming majority of them are a&lt;br /&gt;
significant liability to corporate networks.&lt;br /&gt;
===Web Applications continue to be highly attractive targets===&lt;br /&gt;
The team highlighted the risks of running Web&lt;br /&gt;
applications in last year’s Threat Report. Our current&lt;br /&gt;
research indicates that Web applications continue to&lt;br /&gt;
pose one of the biggest risks to corporate networks.&lt;br /&gt;
Web applications offer an easy way for organizations&lt;br /&gt;
to create an interactive relationship between&lt;br /&gt;
constituents such as customers, employees, and&lt;br /&gt;
partners, and their back-end systems. Because Web&lt;br /&gt;
application systems are relatively easy to build and&lt;br /&gt;
offer inexpensive extensibility, they yield a great deal of&lt;br /&gt;
value and functionality. Because of this, the number of&lt;br /&gt;
Web applications continues to steadily grow.&lt;br /&gt;
===Attackers are more organized and sophisticated===&lt;br /&gt;
One of the more alarming trends observed in the&lt;br /&gt;
previous six months is the increased sophistication&lt;br /&gt;
of attacks. Attackers have not only become more&lt;br /&gt;
organized, they are also increasingly subversive and&lt;br /&gt;
inconspicuous in the way they execute their attacks.&lt;br /&gt;
The attacks are so sophisticated and subtle that few&lt;br /&gt;
victims realize they are under attack until it is too late. It&lt;br /&gt;
is increasingly common to hear of attackers remaining&lt;br /&gt;
inside a compromised organization for months,&lt;br /&gt;
gathering information with which they design and build&lt;br /&gt;
even more sophisticated attacks. Once the desired&lt;br /&gt;
information is obtained, the attackers launch exploits&lt;br /&gt;
that are both more devastating and more covert.&lt;br /&gt;
&lt;br /&gt;
Attack sophistication has increased across the board,&lt;br /&gt;
from client side-attacks such as malicious JavaScript,&lt;br /&gt;
to server-side attacks like PHP file include. This report&lt;br /&gt;
includes examples of real-world attack techniques&lt;br /&gt;
employed by these increasingly sophisticated attackers&lt;br /&gt;
&lt;br /&gt;
===Legacy attacks still a threat===&lt;br /&gt;
Despite the rising sophistication of attacks, it is still&lt;br /&gt;
worth highlighting that over the sample period of this&lt;br /&gt;
report, the number of attacks from well-known legacy&lt;br /&gt;
threats continues to plague computer systems. While&lt;br /&gt;
many of these attacks are well understood and well&lt;br /&gt;
protected against, it is not unheard of to see large&lt;br /&gt;
organizations as the source of some of these attacks,&lt;br /&gt;
indicating that when large organizations implement&lt;br /&gt;
new systems without threat management controls,&lt;br /&gt;
the systems are quickly infected with familiar threats.&lt;br /&gt;
While this is an extreme example, it highlights the&lt;br /&gt;
need for continued diligence against well-known&lt;br /&gt;
threats, ideally addressing them with strong patch and&lt;br /&gt;
configuration management policies.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;br /&gt;
&lt;br /&gt;
While the sections of the report which explain in detail how attackers hide exploits in seemingly innocuous code require some technical expertise, there is a very clear explanation of how such an exploit is downloaded and executed on a victim&#039;s computer within the corporate firewall that requires no special expertise to understand. &#039;&#039;See&#039;&#039; page 27.&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6316</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6316"/>
		<updated>2010-09-21T14:30:19Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Additional Notes and Highlights */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=hptippingpoint:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Phishing | Phishing]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Social_Engineering | Social Engineering]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In 2010, information security threats are striking networks with more sophisticated techniques than ever and exploit reports continue to dominate the media.  The collective findings described within this report establish the fact that the proliferation of technology, along with the quick and effortless manner in which that technology is accessed, is dramatically and negatively impacting security. While we are not advocates for making technology more difficult, we do advocate implementing common sense security policies and technologies that battle well-known and new threats. This report evaluates some of the most significant security liabilities that the enterprise is facing today. The report focuses on four key areas:&lt;br /&gt;
* Increased Consumerization of Enterprise Computing&lt;br /&gt;
* Prolonged and Persistent Targeting of Web Applications&lt;br /&gt;
* Increased Organization and Sophistication of Attackers&lt;br /&gt;
* The Unrelenting Presence of Legacy Threats&lt;br /&gt;
In addition to explaining how and where the enterprise is vulnerable, the report provides insights into how organizations can protect themselves&lt;br /&gt;
from attack, including what the next generation of computing should look like to maximize security for the corporate network.&lt;br /&gt;
&lt;br /&gt;
===Increased Consumerization of Enterprise Computing===&lt;br /&gt;
Some of the most serious information security issues&lt;br /&gt;
the research team has seen this year stem from the&lt;br /&gt;
increasingly high use of consumer technologies within&lt;br /&gt;
the enterprise. For example, there are several thousand&lt;br /&gt;
organizations that utilize Facebook, Twitter, WordPress,&lt;br /&gt;
and iTunes for promotion and brand awareness. While&lt;br /&gt;
these technologies may offer a wealth of marketing&lt;br /&gt;
recognition, they also open the door to a multitude&lt;br /&gt;
of security risks. Another trend impacting enterprise&lt;br /&gt;
IT department is an “anything goes” mentality that&lt;br /&gt;
allows users to download and manage applications&lt;br /&gt;
and programs of their choosing. While some of&lt;br /&gt;
these applications may be fine, and may even boost&lt;br /&gt;
productivity, an overwhelming majority of them are a&lt;br /&gt;
significant liability to corporate networks.&lt;br /&gt;
===Web Applications continue to be highly attractive targets===&lt;br /&gt;
The team highlighted the risks of running Web&lt;br /&gt;
applications in last year’s Threat Report. Our current&lt;br /&gt;
research indicates that Web applications continue to&lt;br /&gt;
pose one of the biggest risks to corporate networks.&lt;br /&gt;
Web applications offer an easy way for organizations&lt;br /&gt;
to create an interactive relationship between&lt;br /&gt;
constituents such as customers, employees, and&lt;br /&gt;
partners, and their back-end systems. Because Web&lt;br /&gt;
application systems are relatively easy to build and&lt;br /&gt;
offer inexpensive extensibility, they yield a great deal of&lt;br /&gt;
value and functionality. Because of this, the number of&lt;br /&gt;
Web applications continues to steadily grow.&lt;br /&gt;
===Attackers are more organized and sophisticated===&lt;br /&gt;
One of the more alarming trends observed in the&lt;br /&gt;
previous six months is the increased sophistication&lt;br /&gt;
of attacks. Attackers have not only become more&lt;br /&gt;
organized, they are also increasingly subversive and&lt;br /&gt;
inconspicuous in the way they execute their attacks.&lt;br /&gt;
The attacks are so sophisticated and subtle that few&lt;br /&gt;
victims realize they are under attack until it is too late. It&lt;br /&gt;
is increasingly common to hear of attackers remaining&lt;br /&gt;
inside a compromised organization for months,&lt;br /&gt;
gathering information with which they design and build&lt;br /&gt;
even more sophisticated attacks. Once the desired&lt;br /&gt;
information is obtained, the attackers launch exploits&lt;br /&gt;
that are both more devastating and more covert.&lt;br /&gt;
&lt;br /&gt;
Attack sophistication has increased across the board,&lt;br /&gt;
from client side-attacks such as malicious JavaScript,&lt;br /&gt;
to server-side attacks like PHP file include. This report&lt;br /&gt;
includes examples of real-world attack techniques&lt;br /&gt;
employed by these increasingly sophisticated attackers&lt;br /&gt;
&lt;br /&gt;
===Legacy attacks still a threat===&lt;br /&gt;
Despite the rising sophistication of attacks, it is still&lt;br /&gt;
worth highlighting that over the sample period of this&lt;br /&gt;
report, the number of attacks from well-known legacy&lt;br /&gt;
threats continues to plague computer systems. While&lt;br /&gt;
many of these attacks are well understood and well&lt;br /&gt;
protected against, it is not unheard of to see large&lt;br /&gt;
organizations as the source of some of these attacks,&lt;br /&gt;
indicating that when large organizations implement&lt;br /&gt;
new systems without threat management controls,&lt;br /&gt;
the systems are quickly infected with familiar threats.&lt;br /&gt;
While this is an extreme example, it highlights the&lt;br /&gt;
need for continued diligence against well-known&lt;br /&gt;
threats, ideally addressing them with strong patch and&lt;br /&gt;
configuration management policies.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;br /&gt;
&lt;br /&gt;
While the sections of the report which explain in detail how attackers hide exploits in seemingly innocuous code require some technical expertise, there is a very clear explanation of such an exploit is downloaded and executed on a victim&#039;s computer wihtin the corporate firewall that requires no special expertise to understand. &#039;&#039;See&#039;&#039; page 27.&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6315</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6315"/>
		<updated>2010-09-21T14:27:38Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Attackers are more organized and sophisticated */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=hptippingpoint:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Phishing | Phishing]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Social_Engineering | Social Engineering]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In 2010, information security threats are striking networks with more sophisticated techniques than ever and exploit reports continue to dominate the media.  The collective findings described within this report establish the fact that the proliferation of technology, along with the quick and effortless manner in which that technology is accessed, is dramatically and negatively impacting security. While we are not advocates for making technology more difficult, we do advocate implementing common sense security policies and technologies that battle well-known and new threats. This report evaluates some of the most significant security liabilities that the enterprise is facing today. The report focuses on four key areas:&lt;br /&gt;
* Increased Consumerization of Enterprise Computing&lt;br /&gt;
* Prolonged and Persistent Targeting of Web Applications&lt;br /&gt;
* Increased Organization and Sophistication of Attackers&lt;br /&gt;
* The Unrelenting Presence of Legacy Threats&lt;br /&gt;
In addition to explaining how and where the enterprise is vulnerable, the report provides insights into how organizations can protect themselves&lt;br /&gt;
from attack, including what the next generation of computing should look like to maximize security for the corporate network.&lt;br /&gt;
&lt;br /&gt;
===Increased Consumerization of Enterprise Computing===&lt;br /&gt;
Some of the most serious information security issues&lt;br /&gt;
the research team has seen this year stem from the&lt;br /&gt;
increasingly high use of consumer technologies within&lt;br /&gt;
the enterprise. For example, there are several thousand&lt;br /&gt;
organizations that utilize Facebook, Twitter, WordPress,&lt;br /&gt;
and iTunes for promotion and brand awareness. While&lt;br /&gt;
these technologies may offer a wealth of marketing&lt;br /&gt;
recognition, they also open the door to a multitude&lt;br /&gt;
of security risks. Another trend impacting enterprise&lt;br /&gt;
IT department is an “anything goes” mentality that&lt;br /&gt;
allows users to download and manage applications&lt;br /&gt;
and programs of their choosing. While some of&lt;br /&gt;
these applications may be fine, and may even boost&lt;br /&gt;
productivity, an overwhelming majority of them are a&lt;br /&gt;
significant liability to corporate networks.&lt;br /&gt;
===Web Applications continue to be highly attractive targets===&lt;br /&gt;
The team highlighted the risks of running Web&lt;br /&gt;
applications in last year’s Threat Report. Our current&lt;br /&gt;
research indicates that Web applications continue to&lt;br /&gt;
pose one of the biggest risks to corporate networks.&lt;br /&gt;
Web applications offer an easy way for organizations&lt;br /&gt;
to create an interactive relationship between&lt;br /&gt;
constituents such as customers, employees, and&lt;br /&gt;
partners, and their back-end systems. Because Web&lt;br /&gt;
application systems are relatively easy to build and&lt;br /&gt;
offer inexpensive extensibility, they yield a great deal of&lt;br /&gt;
value and functionality. Because of this, the number of&lt;br /&gt;
Web applications continues to steadily grow.&lt;br /&gt;
===Attackers are more organized and sophisticated===&lt;br /&gt;
One of the more alarming trends observed in the&lt;br /&gt;
previous six months is the increased sophistication&lt;br /&gt;
of attacks. Attackers have not only become more&lt;br /&gt;
organized, they are also increasingly subversive and&lt;br /&gt;
inconspicuous in the way they execute their attacks.&lt;br /&gt;
The attacks are so sophisticated and subtle that few&lt;br /&gt;
victims realize they are under attack until it is too late. It&lt;br /&gt;
is increasingly common to hear of attackers remaining&lt;br /&gt;
inside a compromised organization for months,&lt;br /&gt;
gathering information with which they design and build&lt;br /&gt;
even more sophisticated attacks. Once the desired&lt;br /&gt;
information is obtained, the attackers launch exploits&lt;br /&gt;
that are both more devastating and more covert.&lt;br /&gt;
&lt;br /&gt;
Attack sophistication has increased across the board,&lt;br /&gt;
from client side-attacks such as malicious JavaScript,&lt;br /&gt;
to server-side attacks like PHP file include. This report&lt;br /&gt;
includes examples of real-world attack techniques&lt;br /&gt;
employed by these increasingly sophisticated attackers&lt;br /&gt;
&lt;br /&gt;
===Legacy attacks still a threat===&lt;br /&gt;
Despite the rising sophistication of attacks, it is still&lt;br /&gt;
worth highlighting that over the sample period of this&lt;br /&gt;
report, the number of attacks from well-known legacy&lt;br /&gt;
threats continues to plague computer systems. While&lt;br /&gt;
many of these attacks are well understood and well&lt;br /&gt;
protected against, it is not unheard of to see large&lt;br /&gt;
organizations as the source of some of these attacks,&lt;br /&gt;
indicating that when large organizations implement&lt;br /&gt;
new systems without threat management controls,&lt;br /&gt;
the systems are quickly infected with familiar threats.&lt;br /&gt;
While this is an extreme example, it highlights the&lt;br /&gt;
need for continued diligence against well-known&lt;br /&gt;
threats, ideally addressing them with strong patch and&lt;br /&gt;
configuration management policies.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6314</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6314"/>
		<updated>2010-09-21T14:27:26Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Synopsis */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=hptippingpoint:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Phishing | Phishing]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Social_Engineering | Social Engineering]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In 2010, information security threats are striking networks with more sophisticated techniques than ever and exploit reports continue to dominate the media.  The collective findings described within this report establish the fact that the proliferation of technology, along with the quick and effortless manner in which that technology is accessed, is dramatically and negatively impacting security. While we are not advocates for making technology more difficult, we do advocate implementing common sense security policies and technologies that battle well-known and new threats. This report evaluates some of the most significant security liabilities that the enterprise is facing today. The report focuses on four key areas:&lt;br /&gt;
* Increased Consumerization of Enterprise Computing&lt;br /&gt;
* Prolonged and Persistent Targeting of Web Applications&lt;br /&gt;
* Increased Organization and Sophistication of Attackers&lt;br /&gt;
* The Unrelenting Presence of Legacy Threats&lt;br /&gt;
In addition to explaining how and where the enterprise is vulnerable, the report provides insights into how organizations can protect themselves&lt;br /&gt;
from attack, including what the next generation of computing should look like to maximize security for the corporate network.&lt;br /&gt;
&lt;br /&gt;
===Increased Consumerization of Enterprise Computing===&lt;br /&gt;
Some of the most serious information security issues&lt;br /&gt;
the research team has seen this year stem from the&lt;br /&gt;
increasingly high use of consumer technologies within&lt;br /&gt;
the enterprise. For example, there are several thousand&lt;br /&gt;
organizations that utilize Facebook, Twitter, WordPress,&lt;br /&gt;
and iTunes for promotion and brand awareness. While&lt;br /&gt;
these technologies may offer a wealth of marketing&lt;br /&gt;
recognition, they also open the door to a multitude&lt;br /&gt;
of security risks. Another trend impacting enterprise&lt;br /&gt;
IT department is an “anything goes” mentality that&lt;br /&gt;
allows users to download and manage applications&lt;br /&gt;
and programs of their choosing. While some of&lt;br /&gt;
these applications may be fine, and may even boost&lt;br /&gt;
productivity, an overwhelming majority of them are a&lt;br /&gt;
significant liability to corporate networks.&lt;br /&gt;
===Web Applications continue to be highly attractive targets===&lt;br /&gt;
The team highlighted the risks of running Web&lt;br /&gt;
applications in last year’s Threat Report. Our current&lt;br /&gt;
research indicates that Web applications continue to&lt;br /&gt;
pose one of the biggest risks to corporate networks.&lt;br /&gt;
Web applications offer an easy way for organizations&lt;br /&gt;
to create an interactive relationship between&lt;br /&gt;
constituents such as customers, employees, and&lt;br /&gt;
partners, and their back-end systems. Because Web&lt;br /&gt;
application systems are relatively easy to build and&lt;br /&gt;
offer inexpensive extensibility, they yield a great deal of&lt;br /&gt;
value and functionality. Because of this, the number of&lt;br /&gt;
Web applications continues to steadily grow.&lt;br /&gt;
===Attackers are more organized and sophisticated===&lt;br /&gt;
 One of the more alarming trends observed in the&lt;br /&gt;
previous six months is the increased sophistication&lt;br /&gt;
of attacks. Attackers have not only become more&lt;br /&gt;
organized, they are also increasingly subversive and&lt;br /&gt;
inconspicuous in the way they execute their attacks.&lt;br /&gt;
The attacks are so sophisticated and subtle that few&lt;br /&gt;
victims realize they are under attack until it is too late. It&lt;br /&gt;
is increasingly common to hear of attackers remaining&lt;br /&gt;
inside a compromised organization for months,&lt;br /&gt;
gathering information with which they design and build&lt;br /&gt;
even more sophisticated attacks. Once the desired&lt;br /&gt;
information is obtained, the attackers launch exploits&lt;br /&gt;
that are both more devastating and more covert.&lt;br /&gt;
&lt;br /&gt;
Attack sophistication has increased across the board,&lt;br /&gt;
from client side-attacks such as malicious JavaScript,&lt;br /&gt;
to server-side attacks like PHP file include. This report&lt;br /&gt;
includes examples of real-world attack techniques&lt;br /&gt;
employed by these increasingly sophisticated attackers&lt;br /&gt;
&lt;br /&gt;
===Legacy attacks still a threat===&lt;br /&gt;
Despite the rising sophistication of attacks, it is still&lt;br /&gt;
worth highlighting that over the sample period of this&lt;br /&gt;
report, the number of attacks from well-known legacy&lt;br /&gt;
threats continues to plague computer systems. While&lt;br /&gt;
many of these attacks are well understood and well&lt;br /&gt;
protected against, it is not unheard of to see large&lt;br /&gt;
organizations as the source of some of these attacks,&lt;br /&gt;
indicating that when large organizations implement&lt;br /&gt;
new systems without threat management controls,&lt;br /&gt;
the systems are quickly infected with familiar threats.&lt;br /&gt;
While this is an extreme example, it highlights the&lt;br /&gt;
need for continued diligence against well-known&lt;br /&gt;
threats, ideally addressing them with strong patch and&lt;br /&gt;
configuration management policies.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6313</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6313"/>
		<updated>2010-09-21T14:25:42Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Synopsis */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=hptippingpoint:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Phishing | Phishing]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Social_Engineering | Social Engineering]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In 2010, information security threats are striking networks with more sophisticated techniques than ever and exploit reports continue to dominate the media.  The collective findings described within this report establish the fact that the proliferation of technology, along with the quick and effortless manner in which that technology is accessed, is dramatically and negatively impacting security. While we are not advocates for making technology more difficult, we do advocate implementing common sense security policies and technologies that battle well-known and new threats. This report evaluates some of the most significant security liabilities that the enterprise is facing today. The report focuses on four key areas:&lt;br /&gt;
* Increased Consumerization of Enterprise Computing&lt;br /&gt;
* Prolonged and Persistent Targeting of Web Applications&lt;br /&gt;
* Increased Organization and Sophistication of Attackers&lt;br /&gt;
* The Unrelenting Presence of Legacy Threats&lt;br /&gt;
In addition to explaining how and where the enterprise is vulnerable, the report provides insights into how organizations can protect themselves&lt;br /&gt;
from attack, including what the next generation of computing should look like to maximize security for the corporate network.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6312</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6312"/>
		<updated>2010-09-21T14:24:34Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Additional Notes and Highlights */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=hptippingpoint:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Phishing | Phishing]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Social_Engineering | Social Engineering]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In this report, TrendLabs, Trend Micro&#039;s research lab, discusses 2009&#039;s most persistent threats and presents why users need to be more engaged in keeping their systems secure than ever before. These five most recurring and ever-present threats effectively challenge even the more tech-savvy businesses who encounter them either through lack of network security or of education and appreciation of the severity of threats on the part of employees. At the end of each discussion, a list of security dos are recommended for large enterprises and smaller businesses alike.  The threats discussed are:&lt;br /&gt;
&lt;br /&gt;
* Downad/Conficker Network Worm&lt;br /&gt;
* Koobface Social Network Worm&lt;br /&gt;
* Zeus/Zbot Crimeware&lt;br /&gt;
* Rogue Antivirus Applications&lt;br /&gt;
* Zero-Day Exploits&lt;br /&gt;
&lt;br /&gt;
Unlike the [[Symantec Global Internet Security Threat Report]], trend Trend Micro report is primarily concerned with the threats themselves and does not provide an extensive statistical or financial discussion of cybercrime or its prevalence.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6311</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6311"/>
		<updated>2010-09-21T14:24:05Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=hptippingpoint:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Phishing | Phishing]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Social_Engineering | Social Engineering]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In this report, TrendLabs, Trend Micro&#039;s research lab, discusses 2009&#039;s most persistent threats and presents why users need to be more engaged in keeping their systems secure than ever before. These five most recurring and ever-present threats effectively challenge even the more tech-savvy businesses who encounter them either through lack of network security or of education and appreciation of the severity of threats on the part of employees. At the end of each discussion, a list of security dos are recommended for large enterprises and smaller businesses alike.  The threats discussed are:&lt;br /&gt;
&lt;br /&gt;
* Downad/Conficker Network Worm&lt;br /&gt;
* Koobface Social Network Worm&lt;br /&gt;
* Zeus/Zbot Crimeware&lt;br /&gt;
* Rogue Antivirus Applications&lt;br /&gt;
* Zero-Day Exploits&lt;br /&gt;
&lt;br /&gt;
Unlike the [[Symantec Global Internet Security Threat Report]], trend Trend Micro report is primarily concerned with the threats themselves and does not provide an extensive statistical or financial discussion of cybercrime or its prevalence.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;br /&gt;
&lt;br /&gt;
Link to the latest [http://us.trendmicro.com/us/trendwatch/research-and-analysis/threat-reports/index.html  Trend Micro&#039;s Threat Reports].&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6310</id>
		<title>2010 Top Cyber Security Risks Report</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=2010_Top_Cyber_Security_Risks_Report&amp;diff=6310"/>
		<updated>2010-09-21T14:19:58Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: New page: ==Full Title of Reference== 2010 Top Cyber Security Risks Report  ==Full Citation==  HP TippingPoint DVLabs, &amp;#039;&amp;#039;2010 Top Cyber Security Risks Reports&amp;#039;&amp;#039; (2010). Online Paper.  [http://dvlabs...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
2010 Top Cyber Security Risks Report&lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
HP TippingPoint DVLabs, &#039;&#039;2010 Top Cyber Security Risks Reports&#039;&#039; (2010). Online Paper.  [http://dvlabs.tippingpoint.com/toprisks2010 &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography?f=wikibiblio.bib&amp;amp;title=Special:Bibliography&amp;amp;view=detailed&amp;amp;action=&amp;amp;keyword=Trend_Micro:2010 &#039;&#039;BibTeX&#039;&#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
* Resource by Type: [[Industry Reports]]&lt;br /&gt;
* Issues: [[Cybercrime]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Antivirus | Antivirus]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | Botnet]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Crime | Cyber Crime]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | Malware]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Patching | Patching]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Phishing | Phishing]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Social_Engineering | Social Engineering]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#SPAM | SPAM]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Trojan | Trojan]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Worm | Worm]],&lt;br /&gt;
[[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]]&lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
In this report, TrendLabs, Trend Micro&#039;s research lab, discusses 2009&#039;s most persistent threats and presents why users need to be more engaged in keeping their systems secure than ever before. These five most recurring and ever-present threats effectively challenge even the more tech-savvy businesses who encounter them either through lack of network security or of education and appreciation of the severity of threats on the part of employees. At the end of each discussion, a list of security dos are recommended for large enterprises and smaller businesses alike.  The threats discussed are:&lt;br /&gt;
&lt;br /&gt;
* Downad/Conficker Network Worm&lt;br /&gt;
* Koobface Social Network Worm&lt;br /&gt;
* Zeus/Zbot Crimeware&lt;br /&gt;
* Rogue Antivirus Applications&lt;br /&gt;
* Zero-Day Exploits&lt;br /&gt;
&lt;br /&gt;
Unlike the [[Symantec Global Internet Security Threat Report]], trend Trend Micro report is primarily concerned with the threats themselves and does not provide an extensive statistical or financial discussion of cybercrime or its prevalence.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Expertise Required: Technology - Moderate&lt;br /&gt;
&lt;br /&gt;
Link to the latest [http://us.trendmicro.com/us/trendwatch/research-and-analysis/threat-reports/index.html  Trend Micro&#039;s Threat Reports].&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Cybersecurity_Annotated_Bibliography&amp;diff=6309</id>
		<title>Cybersecurity Annotated Bibliography</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Cybersecurity_Annotated_Bibliography&amp;diff=6309"/>
		<updated>2010-09-21T14:17:32Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross J.||||2008||[[Security Engineering]]||Book||Moderate:Technology; Moderate:Cryptography||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross, et. al|| ||2008||[[Security Economics and the Internal Market]]||Study||Low:Economics||[http://www.enisa.europa.eu/act/sr/reports/econ-sec/economics-sec/at_download/fullReport  &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross||||2001||[[Why Information Security is Hard]]||Conf. Paper||None||[http://www.acsac.org/2001/papers/110.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rja14/Papers/econ.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross||Moore, Tyler||2006||[[The Economics of Information Security]]||Journal Article||Low:Economics||[http://people.seas.harvard.edu/~tmoore/science-econ.pdf &#039;&#039;Pdf&#039;&#039;] [http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.89.3331&amp;amp;rep=rep1&amp;amp;type=pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Arora et al.||||2006||[[Does Information Security Attack Frequency Increase With Vulnerability Disclosure]]||Journal Article||Moderate:Economics||[http://www.heinz.cmu.edu/~rtelang/vuln_freq_ISF.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Aviram, Amitai||Tor, Avishalom||2004||[[Overcoming Impediments to Information Sharing]]||Law Review||Low:Economics||[http://law.haifa.ac.il/faculty/lec_papers/tor/55Ala1.L.Rev.231.pdf &#039;&#039;Pdf&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=435600 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Barkham, Jason||||2001||[[Information Warfare and International Law on the Use of Force]]||Law Review||Moderate:Law||[http://www1.law.nyu.edu/journals/jilp/issues/34/pdf/34_1_b.pdf &#039;&#039;Pdf&#039;&#039;] [http://activeresponse.org/files/34_1_b.pdf &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Beard, Jack M.||||2009||[[Law and War in the Virtual Era]]||Law Review||Low:Law||[http://www.asil.org/ajil/July2009_1selectedpiece.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Bohme, Rainer||||2005||[[Cyber-Insurance Revisited]]||Conf. Paper||High:Economics||[http://infosecon.net/workshop/pdf/15.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Bohme, Rainer||Kataria, Gaurav||2006||[[Models and Measures for Correlation in Cyber-Insurance]]||Conf. Paper||High:Economics||[http://weis2006.econinfosec.org/docs/16.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Bohme, Rainer||Schwartz, Galina||2010||[[Modeling Cyber-Insurance]]||Conf. Paper||High:Economics||[http://www1.inf.tu-dresden.de/~rb21/publications/BS2010_Modeling_Cyber-Insurance_WEIS.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Brown, Davis||||2006||[[A Proposal for an International Convention To Regulate the Use of Information Systems in Armed Conflict]]||Law Review||Moderate:Law||[http://www.harvardilj.org/attach.php?id=59 &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Camp, L. Jean|| Lewis, Stephen||2004||[[Economics of Information Security]]||Book||High:Economics|| N/A&lt;br /&gt;
|-&lt;br /&gt;
|Camp, L. Jean||Wolfram, Catherine||2004||[[Pricing Security]]||Book Chapter||Low:Economics||[http://books.google.com/books?id=PbzP9tgeDcAC&amp;amp;lpg=PA17&amp;amp;ots=8AOrvEojH5&amp;amp;dq=Economics%20of%20Information%20Security&amp;amp;lr&amp;amp;pg=PA17#v=onepage&amp;amp;q&amp;amp;f=false &#039;&#039;Web&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=894966 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Center for Strategic and International Studies||  ||2008||[[Securing Cyberspace for the 44th Presidency]]||Independent Report||Low:Policy||[http://www.cyber.st.dhs.gov/docs/081208_securingcyberspace_44.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Clarke, Richard A.||Knake, Robert||2010||[[Cyber War]]||Book||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Clinton, Larry||||Undated||[[Cyber-Insurance Metrics and Impact on Cyber-Security]]||Online Paper||Low:Technology; Low:Law||[http://www.whitehouse.gov/files/documents/cyber/ISA%20-%20Cyber-Insurance%20Metrics%20and%20Impact%20on%20Cyber-Security.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Computer Economics, Inc.||||2007||[[2007 Malware Report]]||Industry Report||None||[http://www.computereconomics.com/article.cfm?id=1224 &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Computing Research Association||||2003||[[Four Grand Challenges in Trustworthy Computing]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/CRA%20Grand%20Challenges%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Commerce||||2010||[[Defense Industrial Base Assessment]]||Government Report||None||[http://www.bis.doc.gov/defenseindustrialbaseprograms/osies/defmarketresearchrpts/final_counterfeit_electronics_report.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||1999||[[An Assessment of International Legal Issues in Information Operations]]||Government Report||Moderate:Law||[http://www.au.af.mil/au/awc/awcgate/dod-io-legal/dod-io-legal.pdf &#039;&#039; Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||2005||[[Strategy for Homeland Defense and Civil Support]]||Government Report||None||[http://www.defense.gov/news/Jun2005/d20050630homeland.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||2007||[[Mission Impact of Foreign Influence on DoD Software]]||Government Report||Low:Defense Policy/Procurement||[http://www.cyber.st.dhs.gov/docs/Defense%20Science%20Board%20Task%20Force%20-%20Report%20on%20Mission%20Impact%20of%20Foreign%20Influence%20on%20DoD%20Software%20(2007).pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Homeland Security||||2003||[[The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets]]||Government Report||None||[http://www.dhs.gov/xlibrary/assets/Physical_Strategy.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Homeland Security||||2009||[[A Roadmap for Cybersecurity Research]]||Government Report||Low:Technology||[http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Deputy Chief of Staff for Intelligence||||2006||[[Critical Infrastructure Threats and Terrorism]]||Government Report||Low:Organizational Analysis; Low:Risk Management||[http://www.fas.org/irp/threat/terrorism/sup2.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Dörmann, Knut||||2004||[[Applicability of the Additional Protocols to Computer Network Attacks]]||Independent Report||Low:Law||[http://www.icrc.org/Web/eng/siteeng0.nsf/htmlall/68LG92/$File/ApplicabilityofIHLtoCNA.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Dunlap, Charles J. Jr.||||2009||[[Towards a Cyberspace Legal Regime in the Twenty-First Century]]||Speech||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Energetics Inc.||||2006||[[Roadmap to Secure Control Systems in the Energy Sector]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/DOE%20Roadmap%202006.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Epstein, Richard A.||Brown, Thomas P.||2008||[[Cybersecurity in the Payment Card Industry]]||Law Review||Low:Law; Low:Economics||[http://lawreview.uchicago.edu/issues/archive/v75/75_1/EpsteinArticle.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Financial Services Sector Coordinating Council for Critical Infrastructure Protection||||2008||[[Research Agenda for the Banking and Finance Sector]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/RD_Agenda-FINAL.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Franklin, Jason, et. al||||2007||[[An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants]]||Conf. Paper||Low:Statistics; Low:Economics||[http://sparrow.ece.cmu.edu/group/pub/franklin_paxson_perrig_savage_miscreants.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cs.cmu.edu/~jfrankli/acmccs07/ccs07_franklin_eCrime.pdf  &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Gandal, Neil||||2008||[[An Introduction to Key Themes in the Economics of Cyber Security]]||Book Chapter||Low:Economics||[http://www.tau.ac.il/~gandal/security%20encyclopedia%20entry.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Grady, Mark F.||Parisi, Francesco||2006||[[The Law and Economics of Cybersecurity]]||Book||Low:Economics; Low:Law||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Granick, Jennifer Stisa||||2005||[[The Price of Restricting Vulnerability Publications]]||Law Review||Low/Moderate:Law||[http://www.ijclp.net/files/ijclp_web-doc_10-cy-2004.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Hollis, Duncan B.||||2007||[[Why States Need an International Law for Information Operations]]||Law Review||Moderate:Law||[http://legacy.lclark.edu/org/lclr/objects/LCB_11_4_Art7_Hollis.pdf  &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|HP TippingPoint DVLabs||||2010||[[2010 Top Cyber Security Risks Report]]||Industry report||Moderate:Technology||[http://dvlabs.tippingpoint.com/toprisks2010  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Institute for Information Infrastructure Protection||  ||2003||[[Cyber Security Research and Development Agenda]]||Independent Report||Low/None:Technology||[http://www.cyber.st.dhs.gov/docs/I3P%20Research%20Agenda%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Johnson, Eric M.||||2008||[[Managing Information Risk and the Economics of Security]]||Book||High:Economics||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Johnson, Vincent R.||||2005||[[Cybersecurity, Identity Theft, and the Limits of Tort Liability]]||Law Review||Moderate:Law||[http://www.stmarytx.edu/law/pdf/Johnsoncyber.pdf &#039;&#039;Pdf&#039;&#039;] [http://law.bepress.com/cgi/viewcontent.cgi?article=3530&amp;amp;context=expresso &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Kobayashi, Bruce H.|| ||2006||[[An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods]]||Journal Article ||High:Economics||[http://www.law.gmu.edu/assets/files/publications/working_papers/05-11.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Korns, Stephen W.|| ||2009||[[Cyber Operations]]||Journal Article||Low:International Warfare||[http://www.carlisle.army.mil/DIME/documents/Cyber%20Operations%20-%20The%20New%20Balance%20-%20Korns.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Kramer, Franklin D., et. al||||2009||[[Cyberpower and National Security]]||Book||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Lernard, Thomas M.||Rubin, Paul H.||2005||[[An Economic Analysis of Notification Requirements for Data Security Breaches]]||Online Paper||Low:Economics||[http://www.pff.org/issues-pubs/pops/pop12.12datasecurity.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Lernard, Thomas M.||Rubin, Paul H.||2006||[[Much Ado About Notification]]||Journal Article||Low:Economics||[http://www.cato.org/pubs/regulation/regv29n1/v29n1-5.pdf &#039;&#039;Pdf&#039;&#039;]  [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=898208# &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|McAfee, Inc.||||2010||[[McAfee Threats Report]]||Industry Report||None||[http://www.mcafee.com/us/local_content/reports/2010q1_threats_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler, et. al||||2009||[[The Economics of Online Crime]]||Journal Article||Low:Technology||[http://people.seas.harvard.edu/~tmoore/jep09.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2007||[[Examining the Impact of Website Take-down on Phishing]]||Conf. Paper||Low:Technology||[http://www.ecrimeresearch.org/2007/proceedings/p1_moore.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime07.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2008||[[The Consequence of Non-Cooperation in the Fight Against Phishing]]||Conf. Paper||Low:Technology; Low:Economics||[http://people.seas.harvard.edu/~tmoore/ecrime08.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime08pre.pdf  &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2009||[[The Impact of Incentives on Notice and Take-down]]||Book Chapter||Moderate:Technology; Low:Law||[http://weis2008.econinfosec.org/papers/MooreImpact.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Defense Initiative||||2009||[[National Cyber Defense Financial Services Workshop Report]]||Independent Report||Moderate:Financial Services Infrastructure; Moderate:Acronym Tolerance||[http://www.cyber.st.dhs.gov/docs/NCDI_FI_Workshop_Report.pdf &#039;&#039;Pdf&#039;&#039;] [http://ncdi.nps.edu/FI_Workshop_Report_100204.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Security Summit Task Force||||2004||[[Information Security Governance]]||Government Report||Moderate:Executive Administration||[http://www.cyber.st.dhs.gov/docs/Information%20Security%20Governance-%20A%20Call%20to%20Action%20(2004).pdf &#039;&#039;Pdf&#039;&#039;] [http://www.criminal-justice-careers.com/resources/InfoSecGov4_04.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Infrastructure Advisory Council||||2004||[[Hardening The Internet]]||Government Report||High:Technology||[http://www.cyber.st.dhs.gov/docs/NIAC%20Internet%20Hardening.pdf  &#039;&#039;Pdf&#039;&#039;] [http://www.dhs.gov/xlibrary/assets/niac/NIAC_HardeningInternetPaper_Jan05.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Institute of Standards and Technology||||2006||[[SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security]]||Government Report||Moderate:Technology||[http://www.cyber.st.dhs.gov/docs/NIST%20Guide%20to%20Supervisory%20and%20Data%20Acquisition-SCADA%20and%20Industrial%20Control%20Systems%20Security%20(2007).pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Research Council||||1999||[[Trust in Cyberspace]]||Independent Report||Moderate:Technology||[http://www.cyber.st.dhs.gov/docs/Trust%20in%20Cyberspace%20Report%201999.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Research Council||||2007||[[Toward a Safer and More Secure Cyberspace]]||Independent Report||Low:Research Processes; Low:Technology||[http://www.cyber.st.dhs.gov/docs/Toward_a_Safer_and_More_Secure_Cyberspace-Full_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Science and Technology Council||||2006||[[Federal Plan for Cyber Security and Information Assurance Research and Development]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/Federal%20R&amp;amp;D%20Plan%202006.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Networking and Information Technology Research and Development||  ||2009||[[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Nye, Joseph||||2010||[[Cyber Power]]||Book Chapter||Low:Technology; Low:Policy||[http://belfercenter.ksg.harvard.edu/files/cyber-power.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Powell, Benjamin||||2005||[[Is Cybersecurity a Public Good]]||Law Review||Low/Moderate:Economics||[http://www.independent.org/pdf/working_papers/57_cyber.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.ciaonet.org/wps/pob03/pob03.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Commission on Critical Infrastructure Protection||  ||&#039;&#039;1997&#039;&#039;||[[Critical Foundations]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PCCIP%20Report%201997.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Information Technology Advisory Council||  ||2005||[[Cyber Security: A Crisis of Prioritization]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PITAC%20Report%202005.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Romanosky et al.||||2008||[[Do Data Breach Disclosure Laws Reduce Identity Theft]]||Conf. Paper||Moderate:Economics||[http://weis2008.econinfosec.org/papers/Romanosky.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Rotenberg et. al.||||2010||[[The Cyber War Threat Has Been Grossly Exaggerated]]||Debate||None||[http://intelligencesquaredus.org/index.php/past-debates/cyber-war-threat-has-been-grossly-exaggerated/ &#039;&#039;Audio/Transcript&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N., et. al||||2004||[[Computers and War]]||Conf. Paper||Moderate:Law||[http://www.ihlresearch.org/ihl/pdfs/schmittetal.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N.||||1999||[[Computer Network Attack and the Use of Force in International Law]]||Law Review||High:Law||[http://www.dtic.mil/cgi-bin/GetTRDoc?AD=ADA471993&amp;amp;Location=U2&amp;amp;doc=GetTRDoc.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N.||||2002||[[Wired Warfare]]||Journal Article||Moderate:Law||[http://www.icrc.org/Web/eng/siteeng0.nsf/htmlall/5C5D5C/$File/365_400_Schmitt.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schneier, Bruce||||2003||[[Beyond Fear]]||Book||None||[http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 &#039;&#039;Scribd&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schneier, Bruce||||2008||[[Schneier on Security]]||Book||None||[http://www.schneier.com/book-sos.html &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schwartz, Paul||Janger, Edward||2007||[[Notification of Data Security Breaches]]||Law Review||Low:Law; Low:Economics||[http://www.michiganlawreview.org/assets/pdfs/105/5/schwartz.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Sklerov, Matthew J.||||2009||[[Solving the Dilemma of State Responses to Cyberattacks]]||Law Review||Moderate:Law; Low:Technology||[http://www.loc.gov/rr/frd/Military_Law/Military_Law_Review/pdf-files/201-fall-2009.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Stohl, Michael||||2006||[[Cyber Terrorism]]||Journal Article||None||[http://www.ingentaconnect.com/content/klu/cris/2006/00000046/F0020004/00009061 &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Swire, Peter P.||||2004||[[A Model for When Disclosure Helps Security]]||Law Review||Low/Moderate:Logic||[http://www.rootsecure.net/content/downloads/pdf/disclosure_helps_security.pdf &#039;&#039;Pdf&#039;&#039;][http://papers.ssrn.com/sol3/papers.cfm?abstract_id=531782 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Swire, Peter P.||||2006||[[A Theory of Disclosure for Security and Competitive Reasons]]||Law Review||Low/Moderate:Logic||[http://papers.ssrn.com/sol3/papers.cfm?abstract_id=842228 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Symantec Corporation||||2010||[[Symantec Global Internet Security Threat Report]]||Industry Report||Low/Moderate:Technology||[http://www4.symantec.com/Vrt/wl?tu_id=SUKX1271711282503126202 &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Telang, Rahul||Wattal, Sunil||2007||[[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors]]||Journal Article||Moderate:Economics||[http://infosecon.net/workshop/pdf/telang_wattal.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Thomas, Rob||Martin, Jerry||2006||[[The Underground Economy]]||Journal Article||Low:Technology||[http://www.usenix.org/publications/login/2006-12/openpdfs/cymru.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Todd, Graham H.||||2009||[[Armed Attack in Cyberspace]]||Law Review||Moderate:Law||[http://www.afjag.af.mil/shared/media/document/AFD-091026-024.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Trend Micro Incorporated||  ||2010||[[Trend Micro Annual Report]]||Industry Report||Moderate:Technology||[http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/2009s_most_persistent_malware_threats__march_2010_.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|United States Secret Service||||2004||[[Insider Threat Study]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/its_report_040820.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|van Eeten, Michel J. G.||Bauer, Johannes M.||2008||[[Economics of Malware]]||Non-US Govt. Report||Moderate:Economics||[http://www.oecd.org/dataoecd/53/17/40722462.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Varian, Hal||||2000||[[Managing Online Security Risks]]||Newspaper Article||None||[http://people.ischool.berkeley.edu/~hal/people/hal/NYTimes/2000-06-01.html &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Varian, Hal||||2004||[[System Reliability and Free Riding]]||Book Chapter||High:Economics||[http://www.sims.berkeley.edu/resources/affiliates/workshops/econsecurity/econws/48-old.pdf &#039;&#039;Pdf&#039;&#039;]   [http://people.ischool.berkeley.edu/~hal/Papers/2004/reliability  &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Verizon||||2010||[[2010 Data Breach Investigations Report]]||Industry Report||Low:Technology||[http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Watts, Sean||||2010||[[Combatant Status and Computer Network Attack]]||Law Review||Moderate:Law||[http://www.vjil.org/wp-content/uploads/2010/01/VJIL-50.2-Watts.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||||2003||[[The National Strategy to Secure Cyberspace]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/National%20Strategy%20to%20Secure%20Cyberspace%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||||2010||[[The Comprehensive National Cybersecurity Initiative]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/CNCI-Cybersecurity.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||||2009||[[Cyberspace Policy Review]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/Cyberspace_Policy_Review_final.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Zittrain, Jonathan L.||||2008||[[The Future of the Internet and How To Stop It]]||Book||None||[http://futureoftheinternet.org/static/ZittrainTheFutureoftheInternet.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6308</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6308"/>
		<updated>2010-09-09T15:38:33Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* SCADA Systems */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6307</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6307"/>
		<updated>2010-09-09T15:38:10Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Red Team */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6306</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6306"/>
		<updated>2010-09-09T15:37:58Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Organized Crime */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6305</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6305"/>
		<updated>2010-09-09T15:37:42Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Malware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6304</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6304"/>
		<updated>2010-09-09T15:37:26Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Information Asymmetries */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6303</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6303"/>
		<updated>2010-09-09T15:37:10Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Hacker */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6302</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6302"/>
		<updated>2010-09-09T15:36:34Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Computer Network Attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6301</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6301"/>
		<updated>2010-09-09T15:36:06Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Computer Network Attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6300</id>
		<title>Keyword Index and Glossary of Core Ideas</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Keyword_Index_and_Glossary_of_Core_Ideas&amp;diff=6300"/>
		<updated>2010-09-09T15:35:52Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: /* Research &amp;amp; Development */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Keyword Index and Glossary of Core Ideas==&lt;br /&gt;
&lt;br /&gt;
===Air-Gapped Network===&lt;br /&gt;
Air gapping is a security measure that isolates a secure network from unsecure networks physically, electrically and electromagnetically.  &lt;br /&gt;
&lt;br /&gt;
See also: [[Keyword_Index_and_Glossary_of_Core_Ideas#Sneakernet | Sneakernet]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Antivirus===&lt;br /&gt;
Software which attempts to identify and delete or isolate [[#Malware |malware]].  Antivirus software may use both a database containing signatures of known threats and heuristics to identify malware.  Usually run as a background service to scan files and email copied to the protected system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Best Practices===&lt;br /&gt;
&lt;br /&gt;
The processes, practices, and systems identified in public and private organizations that performed exceptionally well and are widely recognized as improving an organization&#039;s performance and efficiency in specific areas. Successfully identifying and applying best practices can reduce business expenses and improve organizational efficiency. [http://www.gao.gov/special.pubs/bprag/bprgloss.htm GAO Glossary]&lt;br /&gt;
&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
&lt;br /&gt;
===Black Hat===&lt;br /&gt;
A black hat is a computer [[#Hacker | hacker]] who works to harm others (e.g., steal identities, spread computer viruses, install bot software).&lt;br /&gt;
&lt;br /&gt;
See also: [[#White_Hat | White Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Blacklist===&lt;br /&gt;
A list of computers, IP addresses, user names or other identifiers to block from access to a computing resource.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Whitelist | Whitelist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Botnet===&lt;br /&gt;
A portmanteau of &amp;quot;robot&amp;quot; and &amp;quot;network.&amp;quot;  Refers to networks of sometimes millions of infected machines that are remotely controlled by malicious actors.  A single infected computer may be referred to as a zombie computer.  The owners of the computer remotely controlled is often unaware of the infection.  The owners of a botnet may use the combined network processing power and bandwidth to send [[#SPAM | SPAM]], install [[#Malware | malware]] and mount [[#DDoS_Attack | DDoS attacks]] or may rent out the botnet to other malicious actors.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Schneier_on_Security | Schneier]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===&#039;&#039;Casus Belli&#039;&#039;===&lt;br /&gt;
The justification for going to war.  From the Latin &amp;quot;&#039;&#039;casus&#039;&#039;&amp;quot; meaning &amp;quot;incident&amp;quot; or &amp;quot;event&amp;quot; and &amp;quot;&#039;&#039;belli&#039;&#039;&amp;quot; meaning &amp;quot;of war.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Civilian Participation===&lt;br /&gt;
The involvement of non-military persons in warfare.  While civilians have often provided support to the military in kinetic wars, in [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Warfare | cyber warfare]] civilians are able to remotely participate in direct attacks against opponents.    This raises complicated questions of law when the combatants are not uniformed military personnel. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Combatant Status===&lt;br /&gt;
The legal status of combatants in warfare.  Existing law distinguishes between uniformed military and civilian status.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Communications Privacy Law===&lt;br /&gt;
Laws which regulate access to electronic communications.  In the United States, the [http://www.usiia.org/legis/ecpa.html Electronic Communications Privacy Act (ECPA]) protects electronic communications while in transit and prohibits the unlawful access and disclosure of communication contents.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research | Burstein]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace | Nojeim]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Emergency Response Team===&lt;br /&gt;
A group of experts brought together to deal with computer security issues.  The Computer Emergency Response Team (CERT) mandate is to develop and promote best management practices and technology applications to “resist attacks on networked systems, to limit damage, and to ensure continuity of critical services.” (Software Engineering Institute 2008).  CERT may be formed by governments to handle security at the national level or by academic institutions or individual corporations.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Computer Network Attack===&lt;br /&gt;
Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves. [http://www.fas.org/irp/doddir/dod/jp3_13.pdf  Joint Doctrine for Information Operations JP 3-13 at I-9 (1998)]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===COTS Software===&lt;br /&gt;
Commercial Off The Shelf Software.  Software that is prepackaged and sold as a commodity rather than custom written for a specific user/organization or purpose. Examples include operating systems, database management programs, email servers, application servers and office product suites. [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD at 18.]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Credit Card Fraud===&lt;br /&gt;
Theft of goods or services using false or stolen credit card information.&lt;br /&gt;
&lt;br /&gt;
See Also: [[#Shoulder_Surfing | Shoulder Surfing]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Crimeware===&lt;br /&gt;
Software tools designed to aid criminals in perpetrating online crime.  Refers only to programs not generally considered desirable or usable for ordinary tasks.  Thus, while a criminal may use Internet Explorer in the commission of a [[#Cyber_Crime | cybercrime]], the Internet Explorer application itself would not be considered crimeware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[2007_Malware_Report  |Computer Economics]]&lt;br /&gt;
* [[Cybersecurity | Bauer and van Eeten]], [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Crime===&lt;br /&gt;
In its broadest definition, cybercrime includes all crime perpetrated with or involving a computer.  Symantec defines it as any crime that is committed using a computer or network, or hardware device. The computer or device may be the agent of the crime, the facilitator of the crime, or the target of the crime. The crime may take place on the computer alone or in addition to other locations. [http://www.symantec.com/norton/cybercrime/definition.jsp Symantec]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as an Externality===&lt;br /&gt;
Economists define externalities as instances where an individual or firm’s actions have &lt;br /&gt;
economic consequences for others for which there is no compensation. One important &lt;br /&gt;
distinction is between positive and negative externalities. Instances of the latter are most &lt;br /&gt;
commonly discussed, such as the environmental pollution caused by a plant, which may &lt;br /&gt;
have impacts on the value of neighboring homes. Important examples of positive &lt;br /&gt;
externalities are so common in communications networks that there is a class of &amp;quot;network &lt;br /&gt;
externalities. For instance, the simple act of installing telephone service to one additional &lt;br /&gt;
customer creates positive externalities on everyone on the telephone network because &lt;br /&gt;
they can now each reach one additional person.&lt;br /&gt;
Several attributes of computer security suggest that it is an externality. Most importantly, &lt;br /&gt;
the lack of security on one machine can cause adverse effects on another. The most &lt;br /&gt;
obvious example of this is from electronic commerce, where credit card numbers stolen &lt;br /&gt;
from machines lacking security are used to commit fraud at other sites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]], [[Economics_of_Information_Security | 2]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]]&lt;br /&gt;
* [[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security | Gandal]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Security as a Public Good===&lt;br /&gt;
In economics, a public good is a good that is non-rivalrous and non-excludable. Non-rivalry means that consumption of the good by one individual does not reduce availability of the good for consumption by others; and non-excludability that no one can be effectively excluded from using the good.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]], [[Managing_Online_Security_Risks | 2]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Terrorism===&lt;br /&gt;
A criminal act perpetrated by the use of computers and telecommunications capabilities, resulting in violence, destruction and/or disruption of services to create fear by causing confusion and uncertainty within a given population, with the goal of influencing a government or population to conform to a particular political, social, or ideological agenda. [http://judiciary.senate.gov/hearings/testimony.cfm?id=1054&amp;amp;wit_id=2995 FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Evolving_Landscape_of_Maritime_Cybersecurity | Shah]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Cyber Warfare===&lt;br /&gt;
Actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruption. [[Cyber_War | Clarke]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks#Full_Citation | Cornish]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Global_Cyber_Deterrence | Lan]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Estonia_Three_Years_Later | Shackelford]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Data Mining===&lt;br /&gt;
The process of extracting hidden information and correlations from one or more databases or collections of data that would not normally be revealed by a simple database query.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy#Synopsis | Besunder]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Department of Homeland Security===&lt;br /&gt;
Cabinet level department of the United States assigned, &#039;&#039;inter alia&#039;&#039;, the task of protecting against terrorist threats and helping state and local authorities prepare for, respond to and recover from domestic disasters.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Schneier on Security | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===DDoS Attack===&lt;br /&gt;
The disabling of a targeted website or Internet connection by flooding it with such high levels of Internet traffic that it can no longer respond to normal connection requests.  Often mounted by directing an army of zombie computers (see [[#Botnet | botnet]]) to connect to the targeted site simultaneously.  The targeted site may crash while trying to respond to an overwhelming number of connections requests or it may be disabled because all available bandwidth and/or computing resources are tied up responding to the attack requests. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]], [[Security_Engineering | [2]]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin. et. al]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Digital Pearl Harbor===&lt;br /&gt;
A cyberwarfare attack similar in scale and surprise to the 1941 attack on Pearl Harbor.  The expression is often invoked by those who argue that a cyber-based attack is either imminent or inevitable and that by not being properly prepared, the United States will suffer significant and unnecessary losses.&lt;br /&gt;
&lt;br /&gt;
AKA: Electronic Pearl Harbor; Cyber Pearl harbor&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Disclosure Policy===&lt;br /&gt;
A policy that governs the disclosure to clients and other stakeholder by a provider of a computer program or system of defects discovered in those products. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Distributed Denial of Service (DDoS)===&lt;br /&gt;
See: [[#DDoS_Attack | DDoS Attack]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Dumpster Diving===&lt;br /&gt;
A method of obtaining  proprietary, confidential or useful information by searching through trash discarded by a target.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Einstein===&lt;br /&gt;
The operational name of the National Cybersecurity Protection System (NCPS).  Was created in 2003 by the United States Computer Emergency Readiness Team (US-CERT)14 in order to aid in its ability to help reduce and prevent computer network vulnerabilities across the federal government. The initial version of Einstein provided an automated process for collecting, correlating, and analyzing agencies’ computer network traffic information from sensors installed at their Internet connections. The Einstein sensors collected &lt;br /&gt;
network flow records at participating agencies, which were then analyzed by US-CERT to detect certain types of malicious activity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Security | GAO]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===E.U. Cybersecurity===&lt;br /&gt;
Discussions relating to cybersecurity of the European Union and of European Union states.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Generativity===&lt;br /&gt;
Generativity is a system’s capacity to produce unanticipated change through unﬁltered contributions from broad and varied audiences. &lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Geneva Conventions===&lt;br /&gt;
Four treaties and three additional protocols that regulates the conduct of hostilities between states and set the standards for humanitarian treatment of the victims of war.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Laws_of_War | Laws of War]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacker===&lt;br /&gt;
Advanced computer users who spend a lot of time on or with computers and work hard to find vulnerabilities in IT systems. [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivism===&lt;br /&gt;
The nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development.  [http://www.alexandrasamuel.com/dissertation/index.html Samuel, A.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity | Cetron and Davies]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Terrorism | Stohl]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Hacktivist===&lt;br /&gt;
A portmanteau of [[#Hacker | &amp;quot;hacker&amp;quot;]] and &amp;quot;activist.&amp;quot; Individuals that have a political motive for their activities, and identify that motivation by their actions, such as defacing opponents’ websites with counter-information or disinformation.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Hacktivism | Hacktivism]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Honeypot===&lt;br /&gt;
A computer, network or other information technology resource set as a trap to attract attacks.  Honeypots may be used to collect metrics (how long does it take for an unprotected system to be breached), to test defenses, to examine methods of attack or to catch attackers.  A honeypot system may also be used to collect [[#SPAM | SPAM]] so it can be added to a [[#Blacklist | blacklist]].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Identity Fraud/Theft===&lt;br /&gt;
The exploitation by malevolent third parties of unwarranted access to clients&#039; or consumers&#039; identities.  Often the result of lax data security or privacy measures.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Notification_of_Data_Security_Breaches | Schwartz and Janger]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Asymmetries===&lt;br /&gt;
Information asymmetry deals with the study of decisions in transactions where one party has more or better information than the other. This creates an imbalance of power in transactions which can sometimes cause the transactions to go awry.&lt;br /&gt;
&lt;br /&gt;
The software market suffers from the same information asymmetry. Vendors may make claims about the security of their products, but buyers have no reason to trust them. In many cases, even the vendor does not know how secure its software is. So buyers have no reason to pay more for protection, and vendors are disinclined to invest in it.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Cyber_War | Clarke]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Intelligence Infrastructure/Information Infrastructure===&lt;br /&gt;
The network of computers and communication lines underlying critical services that American society has come to depend on: financial systems, the power grid, transportation, emergency services, and government programs. Information infrastructure includes the Internet, telecommunications networks, “embedded” systems (the built-in microprocessors that control machines from microwaves to missiles), and “dedicated” devices like individual personal computers. [http://www.cfr.org/publication/10212/targets_for_terrorism.html Council on Foreign Relations]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Information Operations===&lt;br /&gt;
Actions taken to affect adversary information and information systems while defending one’s own information and information systems.” Information Operations (IO) can occur during peacetime and at every level of warfare.&lt;br /&gt;
Information warfare (IW), by contrast, is IO “conducted during time of crisis or conflict to achieve or promote specific objectives over a specific adversary or adversaries” [Joint Chiefs of Staff, Department of Defense, Dictionary of Military and Associated Terms, Joint Publication]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Interdependencies===&lt;br /&gt;
The inter-connections between supposedly independent but often interdependent systems.&lt;br /&gt;
&lt;br /&gt;
See also: [[#SCADA_Systems | SCADA Systems]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[The_Economics_of_Information_Security | Anderson and Moore]]&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Cyber-Insurance_Revisited | Bohme]] &lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Trust in Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cybersecurity_and_Economic_Incentives | OECD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Evolving_Cybersecurity_Issues_in_the_Utility_Industry | Perkins]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | Schmitt]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[System_Reliability_and_Free_Riding | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===International Humanitarian Law===&lt;br /&gt;
That part of international law which seek, for humanitarian reasons, to limit the effects of armed conflict. It protects persons who are not or are no longer participating in the hostilities and restricts the means and methods of warfare. International humanitarian law is also known as the law of war or the law of armed conflict.  International law is the body of rules governing relations between States.  It is contained in agreements between States (treaties or conventions), in customary rules, which consist of State practise considered by them as as legally binding, and in general principles.  [http://www.icrc.org/web/eng/siteeng0.nsf/html/humanitarian-law-factsheet ICRC]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Relay Chat (IRC)===&lt;br /&gt;
A method of real-time Internet communication often used by criminals to buy and sell purloined information such as credit card numbers and personal identity information.  IRC chatrooms may be open or private.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Internet Service Providers===&lt;br /&gt;
A company that offers access to the Internet.  Internet Service Providers may also provide add-on services such as web hosting, electronic mail, virus scanning, SPAM filtering, etc.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity | OECD]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Keylogger===&lt;br /&gt;
Software or hardware that monitors and logs the keystrokes a user types into a computer.  The keylogger may store the key sequences locally for later retrieval or send them to a remote location.  A hardware keylogger can only be detected by physically inspecting the computer for unusual hardware.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Kinetic Attack===&lt;br /&gt;
Traditional mode of warfare in which arms are used to kill opponents and/or destroy an opponent&#039;s infrastructure.  Usually used to distinguish a cyber attack in which destruction of the opponent&#039;s resources is accomplished through targeted information system attacks without resorting to bullets, bombs or explosives.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Computers_and_War | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Lawfare===&lt;br /&gt;
The use of international law to damage an opponent in a war without use of arms.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Laws of War===&lt;br /&gt;
The body of law that define the legality of using armed force to resolve a conflict (&#039;&#039;jus ad bellum&#039;&#039;) and the laws that define the legality of the actual hostilities and related activities (&#039;&#039;jus in bello&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks | Dörmann]]&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now | Gable]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | [2]]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [3]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Malware===&lt;br /&gt;
A variety of computer software designed to infiltrate a user&#039;s computer specifically for malicious purposes.  Includes, &#039;&#039;inter alia&#039;&#039;, computer virus software, botnet software, computer worms, spyware, trojan horses, crimeware and rootkits.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict | Brown]]&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Cybersecurity Strategy (U.S.)===&lt;br /&gt;
A comprehensive policy to secure America’s digital infrastructure as part of the Administrative Branch&#039;s [http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative].  The goals of the policy are: to establish a front line of defense against current immediate threats; to defend against threats by enhancing U.S. counterintelligence capabilities and; to strengthen the future cybersecurity environment by expanding cyber education and redirecting research and development efforts to define and develop strategies to deter hostile or malicious activity in cyberspace.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Cyber_Security_and_Regulation_in_the_United_States | Lewis]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===National Security===&lt;br /&gt;
Broadly refers to the requirement to maintain the survival of the nation-state through the use of economic, military and political power and the exercise of diplomacy. [http://en.wikipedia.org/wiki/National_security Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Nuclear_Security | Aloise]]&lt;br /&gt;
*[[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[An_Assessment_of_International_Legal_Issues_in_Information_Operations | DoD Office of General Counsel]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Why_States_Need_an_International_Law_for_Information_Operations | Hollis]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Terrorist_Capabilities_for_Cyberattack:_Overview_and_Policy_Issues | Rollins and Wilson]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law | [2]]] &lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]] &lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
* [[The Comprehensive National Cybersecurity Initiative | White House]], [[The National Strategy to Secure Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===New Normalcy===&lt;br /&gt;
New normalcy has become an episodic polict construct in U.S. strategic ideation. National leadership has relied on the new normalcy clarion call to illuminate moments in time when it is understood that the Nation faces not only a severe threat, but also a transcending reorientation. Often invoked in times of national crisis, new normalcy in the American experience signals a cardinal shift in the nature of U.S. security. [&amp;quot;Cyber Operations - The New Balance,&amp;quot; Stephen W. Korns]&lt;br /&gt;
&lt;br /&gt;
===Notice and Take-down===&lt;br /&gt;
Most commonly used to remove infringing web material under copyright law, a notice and take-down regime is a procedure by which an infringing web site is removed from a service provider&#039;s (ISP) network, or access to an allegedly infringing website, disabled. Websites violating copyright are subject to notice and take-down, as are phishing websites.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Organized Crime===&lt;br /&gt;
Groups having some manner of a formalized structure and whose primary objective is to obtain money through illegal activities. Such groups maintain their position through the use of actual or threatened violence, corrupt public officials, graft, or extortion, and generally have a significant impact on the people in their locales, region, or the country as a whole.  [http://www.fbi.gov/hq/cid/orgcrime/glossary.htm FBI]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Cybersecurity_in_the_Payment_Card_Industry | Epstein and Brown]]&lt;br /&gt;
* [[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants | Franklin et. al]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Outreach and Collaboration===&lt;br /&gt;
Working across government and with the private sector to share information on threats and other data, and to develop shared approaches to securing cyberspace. [http://www.fas.org/sgp/crs/natsec/R40836.pdf CRS Report for Congress, at 6 (2009).]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]], [[Strategy_for_Homeland_Defense_and_Civil_Support | [2]]]&lt;br /&gt;
* [[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets | DHS]], [[A Roadmap for Cybersecurity Research | [2]]]&lt;br /&gt;
* [[Introduction_to_Country_Reports | ENISA]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
*[[The_Law_and_Economics_of_Cybersecurity | Grady and Parisi]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security | Madnick et. al.]]&lt;br /&gt;
* [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | Moore and Clayton]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Cybersecurity:_Current_Legislation%2C_Executive_Branch_Initiatives%2C_and_Options_for_Congress | Theohary and Rollins]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Password Weakness===&lt;br /&gt;
Security threats caused by the use of easily guessable passwords which protect vital stores of confidential information stored online.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cybersecurity%2C_Identity_Theft%2C_and_the_Limits_of_Tort_Liability | Johnson, V.]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Patching===&lt;br /&gt;
Patching refers to the installation of a piece of software designed to fix problems  with, or update a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs, and improving the usability  or performance. Though meant to fix problems, poorly designed patches can sometimes introduce new problems. [http://en.wikipedia.org/wiki/Patch_%28computing%29 Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Security_Economics_and_the_Internal_Market | Anderson et. al.]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]],&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Examining_the_Impact_of_Website_Take-down_on_Phishing | Moore and Clayton]], [[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing | [2]]], [[The_Impact_of_Incentives_on_Notice_and_Take-down | [3]]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Privacy Law===&lt;br /&gt;
Laws which regulate the protection of confidential personal information stored in private records or disclosed to a professional.  Also includes laws which regulate the gathering of electronic data in which personal information is accumulated or misappropriated.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Best_Practices_for_Data_Protection_and_Privacy | Besunder]]&lt;br /&gt;
* [[Securing_Cyberspace_for_the_44th_Presidency | Center for Strategic and International Studies]]&lt;br /&gt;
* [[A Roadmap for Cybersecurity Research | DHS]]&lt;br /&gt;
* [[Strategy_for_Homeland_Defense_and_Civil_Support | DoD]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Red Team===&lt;br /&gt;
A structured, iterative process executed by trained, educated and practiced team members that provides commanders an independent capability to continuously challenge plans, operations, concepts, organizations and capabilities in the context of the operational environment and from our partners’ and adversaries’ perspectives. See [http://www.tradoc.army.mil/pao/tnsarchives/July05/070205.htm U.S. Army]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | Deputy Chief of Staff for Intelligence]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Research &amp;amp; Development===&lt;br /&gt;
Research and development (R&amp;amp;D) addressing cyber security and information infrastructure protection.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Pricing_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Research_Agenda_for_the_Banking_and_Finance_Sector | Financial Services Sector Coordinating Council for Critical Infrastructure Protection]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[Cyber_Security_Research_and_Development_Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda | Maughan]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Federal Plan for Cyber Security and Information Assurance Research and Development | National Science &amp;amp; Tech. Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Risk Modeling===&lt;br /&gt;
The creation of a model to estimate risk exposure, policy option efficacy and cost-benefit analysis of a particular threat and solution. See [http://cisac.stanford.edu/publications/how_much_is_enough__a_riskmanagement_approach_to_computer_security/ Soo Hoo, Kevin J.]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security | Clinton]]&lt;br /&gt;
* [[Nothing_Ventured%2C_Nothing_Gained | Geer and Conway]]&lt;br /&gt;
* [[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods | Kobayashi]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Making_the_Best_Use_of_Cybersecurity_Economic_Models | Rue and Pfleeger]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Managing_Online_Security_Risks | Varian]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SCADA Systems===&lt;br /&gt;
SCADA stands for &amp;quot;supervisory control and data acquisition&amp;quot; and in the cybersecurity context usually refers to industrial control systems that control infrastructure such as electrical power transmission and distribution, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines and large communication systems.  The focus is on whether as these systems are connected to the public Internet they become vulnerable to a remote attack.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century | Dunlap]]&lt;br /&gt;
* [[Cyberpower and National Security | Kramer et. al]] &lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies | Santos et. al.]]&lt;br /&gt;
* [[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks | Schneidewind]]&lt;br /&gt;
* [[The National Strategy to Secure Cyberspace | White House]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Scareware===&lt;br /&gt;
Software or web site that purports to be security software reporting a threat against a user&#039;s computer to convince the user to purchase unneeded software or install malware.&lt;br /&gt;
&lt;br /&gt;
* [[2007_Malware_Report | Computer Economics]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Script Kiddie===&lt;br /&gt;
A derogatory term for a [[#Black_Hat | Black Hat]] who uses canned tools and programs written by more skillful [[#Hacker | hackers]] to commit cyber crime without understanding how they work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Security Trade-Offs===&lt;br /&gt;
There is no single correct level of security; how much security you have depends on what you’re willing to give up in order to get it. This trade-off is, by its very nature, subjective—secu- rity decisions are based on personal judgments. Different people have different senses of what constitutes a threat, or what level of risk is acceptable. What’s more, between different commu- nities, or organizations, or even entire societies, there is no agreed-upon way in which to define threats or evaluate risks, and the modern technological and media-filled world makes these evaluations even harder. [http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 Bruce Schneier]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
&lt;br /&gt;
*[[Cyber-Insurance_Revisited | Bohme]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Shoulder Surfing===&lt;br /&gt;
The process of obtaining passwords or other sensitive information by covertly watching an authorized user enter information into a computer system.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sneakernet===&lt;br /&gt;
Describes the transfer of data between computers or networks that are not physically, electrically or electromagnetically connected requiring information to be shared by physically transporting media contain the shared information from one computer to another.  Initially described systems lacking the technology to network together, now usually refers to systems deliberately isolated for security reasons.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Air-Gapped_Network | Air-Gapped Network]]&lt;br /&gt;
&lt;br /&gt;
===Social Engineering===&lt;br /&gt;
Conning a human into supplying passwords, computer access or other sensitive information by pretending to be a person with rights to the information or who the target believes they must surrender the information to.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Emerging_Threats_to_Internet_Security_-_Incentives%2C_Externalities_and_Policy_Implications | Bauer and van Eeten]]&lt;br /&gt;
* [[Cyber_Power | Nye]]&lt;br /&gt;
* [[The_Market_Consequences_of_Cybersecurity:_Defining_Externalities_and_Ways_to_Address_Them | OECD]], [[Cybersecurity_and_Economic_Incentives | [2]]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Social Network===&lt;br /&gt;
A software application or website that allows a large group of users to interact with each other, often allowing the creation of online portals or identities to share with specific people or the online world at large.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Software Vulnerability===&lt;br /&gt;
&lt;br /&gt;
A software vulnerablilty refers to the existence of a flaw -- or &amp;quot;bug&amp;quot; -- in software that may allow a third party or program to obtain unauthorized access to the flaw and exploit it. [http://www.spi.dod.mil/tenets.htm U.S. Air Force Software Protection Initiative]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does Information Security Attack Frequency Increase With Vulnerability Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Four Grand Challenges in Trustworthy Computing | Computing Research Association]]&lt;br /&gt;
* [[Mission Impact of Foreign Influence on DoD Software | DoD]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[The Price of Restricting Vulnerability Publications | Granick]]&lt;br /&gt;
* [[Cyber Security Research and Development Agenda | Institute for Information Infrastructure Protection]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Cyber Security: A Crisis of Prioritization | PITAC]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]], [[Trust in Cyberspace | [2]]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[Insider_Threat_Study | U.S. Secret Service]]&lt;br /&gt;
* [[Economics_of_Malware | van Eeten and Bauer]]&lt;br /&gt;
* [[2010 Data Breach Investigations Report | Verizon]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===SPAM===&lt;br /&gt;
Unwanted or junk email usually sent indiscriminately in bulk selling illegal or near illegal goods or services.  Even with low response rates and heavy filtering, SPAM can stil be economically viable because of the extremely low costs in sending even huge quantities of electronic messages.  Commonly believed to be named after the [http://www.youtube.com/watch?v=anwy2MPT5RE Monty Python skit] where the breakfast meat Spam overwhelms all other food choices.&lt;br /&gt;
&lt;br /&gt;
References: &lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[The_Impact_of_Incentives_on_Notice_and_Take-down | Moore and Clayton]]&lt;br /&gt;
* [[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[Schneier on Security | Schneier]] &lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[The_Underground_Economy | Thomas and Martin]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Sponsored Attacks===&lt;br /&gt;
[[#Computer_Network_Attack | Computer network attacks]] commissioned by, supported by or carried out by a state or government.&lt;br /&gt;
&lt;br /&gt;
Reverences:&lt;br /&gt;
* [[The_Government_and_Cybersecurity | Bellovin]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===State Affiliation===&lt;br /&gt;
Under the control or command of a recognized state or government.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Cyber_Security_and_Politically%2C_Socially_and_Religiously_Motivated_Cyber_Attacks | Cornish]]&lt;br /&gt;
* [[Cyberspace_and_the_National_Security_of_the_United_Kingdom | Cornish et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber-Apocalypse_Now_-_Securing_the_Internet_Against_Cyberterrorism_and_Using_Universal_Jurisdiction_as_a_Deterrent | Gable]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[National_Cyber_Defense_Financial_Services_Workshop_Report | National Cyber Defense Initiative]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
* [[The Cyber War Threat Has Been Grossly Exaggerated | Rotenberg et. al]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Combatant_Status_and_Computer_Network_Attack | Watts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Tragedy of Commons===&lt;br /&gt;
A situation, first described in an influential article written by ecologist Garrett Hardin for the journal Science, in 1968, in which multiple individuals, acting independently, and solely and rationally consulting their own self-interest, will ultimately deplete a shared limited resource even when it is clear that it is not in anyone&#039;s long-term interest for this to happen. The term can be applied to any issue related to the management of a shared resource, from energy to the public domain, to cybersecurity.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Why_Information_Security_is_Hard | Anderson]]&lt;br /&gt;
* [[Economics_of_Information_Security | Camp and Wolfram]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Is_Cybersecurity_a_Public_Good | Powell]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Transparency===&lt;br /&gt;
A set of policies, practices and procedures that allow citizens to have accessibility, usability, informativeness, understandability and auditability of information and process held by centers of authority.  [http://en.wikipedia.org/wiki/Transparency_(social) Wikipedia]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Overcoming_Impediments_to_Information_Sharing | Aviram and Tor]]&lt;br /&gt;
* [[Research Agenda for the Banking and Finance Sector | FSSCC]]&lt;br /&gt;
* [[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches | Lenard and Rubin]], [[Much_Ado_About_Notification | [2]]]&lt;br /&gt;
* [[Managing_Information_Risk_and_the_Economics_of_Security | Johnson, E.]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft | Romanosky et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[A_Model_for_When_Disclosure_Helps_Security | Swire]], [[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons | [2]]]&lt;br /&gt;
* [[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors | Telang and Wattal]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Trojan===&lt;br /&gt;
[[#Malware | Malware]] which masquerades as some other type of program such as a link to a web site, a desirable image, etc. to trick a user into installing it.  Named for the Ancient Greek legend of the [http://www.mlahanas.de/Greeks/Mythology/TrojanHorse.html Trojan Horse].&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
*[[The_Economics_of_Online_Crime | Moore et. al.]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]]&lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Military Technologies===&lt;br /&gt;
Warfare made possible by advances in remotely controlled or semiautomated military technologies which remove the operator from risk of harm while attacking an opponent.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Information_Warfare_and_International_Law_on_the_Use_of_Force | Barkham]]&lt;br /&gt;
* [[Law_and_War_in_the_Virtual_Era | Beard]]&lt;br /&gt;
* [[Critical_Infrastructure_Threats_and_Terrorism | DCSINT]]&lt;br /&gt;
* [[Global_Cyber_Deterrence_Views_from_China | Lan]]&lt;br /&gt;
* [[Wired_Warfare | Schmitt]], [[Computers_and_War | 2]]&lt;br /&gt;
* [[Critical_Foundations | PCCIP]]&lt;br /&gt;
* [[Armed_Attack_in_Cyberspace | Todd]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Virtual Warfare===&lt;br /&gt;
&lt;br /&gt;
See: [[#Virtual_Military_Technologies | Virtual Military Technologies]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===White Hat===&lt;br /&gt;
A white hat is a computer [[#Hacker | hacker]] who works to find and fix computer security risks.  White hat consultants are often hired to attempt to break into their client&#039;s network to see if all security holes have been addressed.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Black_Hat | Black Hat]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]], [[Why_Information_Security_is_Hard | [2]]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Whitelist===&lt;br /&gt;
A list of computers, IP (Internet Protocol) addresses, user names or other identifiers to specifically allow access to a computing resource.  Normally combined with a default &amp;quot;no-access&amp;quot; policy.&lt;br /&gt;
&lt;br /&gt;
See also: [[#Blacklist | Blacklist]]&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Worm===&lt;br /&gt;
A type of malware that replicates itself and spreads to other computers through network connections.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Models_and_Measures_for_Correlation_in_Cyber-Insurance | Bohme and Kataria]]&lt;br /&gt;
* [[Modeling_Cyber-Insurance | Bohme and Schwartz]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[Cyber_Operations | Korns]]&lt;br /&gt;
* [[Hardening_The_Internet | National Infrastructure Advisory Council]]&lt;br /&gt;
* [[Toward_a_Safer_and_More_Secure_Cyberspace | National Research Council]]&lt;br /&gt;
* [[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report | NITRD]]&lt;br /&gt;
* [[Beyond_Fear | Schneier]], [[Schneier on Security | [2]]] &lt;br /&gt;
* [[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks | Sklerov]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
* [[The_Future_of_the_Internet_and_How_To_Stop_It | Zittrain]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Zero-Day Exploit===&lt;br /&gt;
[[#Malware | Malware]] designed to exploit a newly discovered security hole unknown to the software developer.  &amp;quot;Zero-day&amp;quot; refers to the amount of time a developer has between learning of a security hole and the time it becomes public or when [[#Black_Hat | black hat]] [[#Hacker | hackers]] find out about it and try to use the security hole for nefarious purposes.&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
* [[Security_Engineering | Anderson]]&lt;br /&gt;
* [[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure | Arora et. al.]]&lt;br /&gt;
* [[Mission_Impact_of_Foreign_Influence_on_DoD_Software | DoD]]&lt;br /&gt;
* [[The_Price_of_Restricting_Vulnerability_Publications | Granick]]&lt;br /&gt;
* [[McAfee Threats Report | McAfee]]&lt;br /&gt;
* [[Symantec Global Internet Security Threat Report | Symantec]]&lt;br /&gt;
* [[Trend Micro Annual Report | Trend Micro]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[[Keyword_Index_and_Glossary_of_Core_Ideas#Top | Jump to top of Glossary]]&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Cybersecurity_Annotated_Bibliography&amp;diff=6299</id>
		<title>Cybersecurity Annotated Bibliography</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Cybersecurity_Annotated_Bibliography&amp;diff=6299"/>
		<updated>2010-09-09T15:34:43Z</updated>

		<summary type="html">&lt;p&gt;WikiSysop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable sortable&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 1&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Author 2&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Year &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Title &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Source &lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; | Expertise&lt;br /&gt;
! style=&amp;quot;background-color: #efefef;&amp;quot; class=&amp;quot;unsortable&amp;quot; | Full Text  &lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross J.||||2008||[[Security Engineering]]||Book||Moderate:Technology; Moderate:Cryptography||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross, et. al|| ||2008||[[Security Economics and the Internal Market]]||Study||Low:Economics||[http://www.enisa.europa.eu/act/sr/reports/econ-sec/economics-sec/at_download/fullReport  &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross||||2001||[[Why Information Security is Hard]]||Conf. Paper||None||[http://www.acsac.org/2001/papers/110.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rja14/Papers/econ.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Anderson, Ross||Moore, Tyler||2006||[[The Economics of Information Security]]||Journal Article||Low:Economics||[http://people.seas.harvard.edu/~tmoore/science-econ.pdf &#039;&#039;Pdf&#039;&#039;] [http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.89.3331&amp;amp;rep=rep1&amp;amp;type=pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Arora et al.||||2006||[[Does Information Security Attack Frequency Increase With Vulnerability Disclosure]]||Journal Article||Moderate:Economics||[http://www.heinz.cmu.edu/~rtelang/vuln_freq_ISF.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Aviram, Amitai||Tor, Avishalom||2004||[[Overcoming Impediments to Information Sharing]]||Law Review||Low:Economics||[http://law.haifa.ac.il/faculty/lec_papers/tor/55Ala1.L.Rev.231.pdf &#039;&#039;Pdf&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=435600 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Barkham, Jason||||2001||[[Information Warfare and International Law on the Use of Force]]||Law Review||Moderate:Law||[http://www1.law.nyu.edu/journals/jilp/issues/34/pdf/34_1_b.pdf &#039;&#039;Pdf&#039;&#039;] [http://activeresponse.org/files/34_1_b.pdf &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Beard, Jack M.||||2009||[[Law and War in the Virtual Era]]||Law Review||Low:Law||[http://www.asil.org/ajil/July2009_1selectedpiece.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Bohme, Rainer||||2005||[[Cyber-Insurance Revisited]]||Conf. Paper||High:Economics||[http://infosecon.net/workshop/pdf/15.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Bohme, Rainer||Kataria, Gaurav||2006||[[Models and Measures for Correlation in Cyber-Insurance]]||Conf. Paper||High:Economics||[http://weis2006.econinfosec.org/docs/16.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Bohme, Rainer||Schwartz, Galina||2010||[[Modeling Cyber-Insurance]]||Conf. Paper||High:Economics||[http://www1.inf.tu-dresden.de/~rb21/publications/BS2010_Modeling_Cyber-Insurance_WEIS.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Brown, Davis||||2006||[[A Proposal for an International Convention To Regulate the Use of Information Systems in Armed Conflict]]||Law Review||Moderate:Law||[http://www.harvardilj.org/attach.php?id=59 &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Camp, L. Jean|| Lewis, Stephen||2004||[[Economics of Information Security]]||Book||High:Economics|| N/A&lt;br /&gt;
|-&lt;br /&gt;
|Camp, L. Jean||Wolfram, Catherine||2004||[[Pricing Security]]||Book Chapter||Low:Economics||[http://books.google.com/books?id=PbzP9tgeDcAC&amp;amp;lpg=PA17&amp;amp;ots=8AOrvEojH5&amp;amp;dq=Economics%20of%20Information%20Security&amp;amp;lr&amp;amp;pg=PA17#v=onepage&amp;amp;q&amp;amp;f=false &#039;&#039;Web&#039;&#039;] [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=894966 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Center for Strategic and International Studies||  ||2008||[[Securing Cyberspace for the 44th Presidency]]||Independent Report||Low:Policy||[http://www.cyber.st.dhs.gov/docs/081208_securingcyberspace_44.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Clarke, Richard A.||Knake, Robert||2010||[[Cyber War]]||Book||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Clinton, Larry||||Undated||[[Cyber-Insurance Metrics and Impact on Cyber-Security]]||Online Paper||Low:Technology; Low:Law||[http://www.whitehouse.gov/files/documents/cyber/ISA%20-%20Cyber-Insurance%20Metrics%20and%20Impact%20on%20Cyber-Security.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Computer Economics, Inc.||||2007||[[2007 Malware Report]]||Industry Report||None||[http://www.computereconomics.com/article.cfm?id=1224 &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Computing Research Association||||2003||[[Four Grand Challenges in Trustworthy Computing]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/CRA%20Grand%20Challenges%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Commerce||||2010||[[Defense Industrial Base Assessment]]||Government Report||None||[http://www.bis.doc.gov/defenseindustrialbaseprograms/osies/defmarketresearchrpts/final_counterfeit_electronics_report.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||1999||[[An Assessment of International Legal Issues in Information Operations]]||Government Report||Moderate:Law||[http://www.au.af.mil/au/awc/awcgate/dod-io-legal/dod-io-legal.pdf &#039;&#039; Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||2005||[[Strategy for Homeland Defense and Civil Support]]||Government Report||None||[http://www.defense.gov/news/Jun2005/d20050630homeland.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Defense||||2007||[[Mission Impact of Foreign Influence on DoD Software]]||Government Report||Low:Defense Policy/Procurement||[http://www.cyber.st.dhs.gov/docs/Defense%20Science%20Board%20Task%20Force%20-%20Report%20on%20Mission%20Impact%20of%20Foreign%20Influence%20on%20DoD%20Software%20(2007).pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Homeland Security||||2003||[[The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets]]||Government Report||None||[http://www.dhs.gov/xlibrary/assets/Physical_Strategy.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Department of Homeland Security||||2009||[[A Roadmap for Cybersecurity Research]]||Government Report||Low:Technology||[http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Deputy Chief of Staff for Intelligence||||2006||[[Critical Infrastructure Threats and Terrorism]]||Government Report||Low:Organizational Analysis; Low:Risk Management||[http://www.fas.org/irp/threat/terrorism/sup2.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Dörmann, Knut||||2004||[[Applicability of the Additional Protocols to Computer Network Attacks]]||Independent Report||Low:Law||[http://www.icrc.org/Web/eng/siteeng0.nsf/htmlall/68LG92/$File/ApplicabilityofIHLtoCNA.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Dunlap, Charles J. Jr.||||2009||[[Towards a Cyberspace Legal Regime in the Twenty-First Century]]||Speech||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Energetics Inc.||||2006||[[Roadmap to Secure Control Systems in the Energy Sector]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/DOE%20Roadmap%202006.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Epstein, Richard A.||Brown, Thomas P.||2008||[[Cybersecurity in the Payment Card Industry]]||Law Review||Low:Law; Low:Economics||[http://lawreview.uchicago.edu/issues/archive/v75/75_1/EpsteinArticle.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Financial Services Sector Coordinating Council for Critical Infrastructure Protection||||2008||[[Research Agenda for the Banking and Finance Sector]]||Independent Report||None||[http://www.cyber.st.dhs.gov/docs/RD_Agenda-FINAL.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Franklin, Jason, et. al||||2007||[[An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants]]||Conf. Paper||Low:Statistics; Low:Economics||[http://sparrow.ece.cmu.edu/group/pub/franklin_paxson_perrig_savage_miscreants.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cs.cmu.edu/~jfrankli/acmccs07/ccs07_franklin_eCrime.pdf  &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Gandal, Neil||||2008||[[An Introduction to Key Themes in the Economics of Cyber Security]]||Book Chapter||Low:Economics||[http://www.tau.ac.il/~gandal/security%20encyclopedia%20entry.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Grady, Mark F.||Parisi, Francesco||2006||[[The Law and Economics of Cybersecurity]]||Book||Low:Economics; Low:Law||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Granick, Jennifer Stisa||||2005||[[The Price of Restricting Vulnerability Publications]]||Law Review||Low/Moderate:Law||[http://www.ijclp.net/files/ijclp_web-doc_10-cy-2004.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Hollis, Duncan B.||||2007||[[Why States Need an International Law for Information Operations]]||Law Review||Moderate:Law||[http://legacy.lclark.edu/org/lclr/objects/LCB_11_4_Art7_Hollis.pdf  &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Institute for Information Infrastructure Protection||  ||2003||[[Cyber Security Research and Development Agenda]]||Independent Report||Low/None:Technology||[http://www.cyber.st.dhs.gov/docs/I3P%20Research%20Agenda%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Johnson, Eric M.||||2008||[[Managing Information Risk and the Economics of Security]]||Book||High:Economics||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Johnson, Vincent R.||||2005||[[Cybersecurity, Identity Theft, and the Limits of Tort Liability]]||Law Review||Moderate:Law||[http://www.stmarytx.edu/law/pdf/Johnsoncyber.pdf &#039;&#039;Pdf&#039;&#039;] [http://law.bepress.com/cgi/viewcontent.cgi?article=3530&amp;amp;context=expresso &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Kobayashi, Bruce H.|| ||2006||[[An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods]]||Journal Article ||High:Economics||[http://www.law.gmu.edu/assets/files/publications/working_papers/05-11.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Korns, Stephen W.|| ||2009||[[Cyber Operations]]||Journal Article||Low:International Warfare||[http://www.carlisle.army.mil/DIME/documents/Cyber%20Operations%20-%20The%20New%20Balance%20-%20Korns.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Kramer, Franklin D., et. al||||2009||[[Cyberpower and National Security]]||Book||None||N/A&lt;br /&gt;
|-&lt;br /&gt;
|Lernard, Thomas M.||Rubin, Paul H.||2005||[[An Economic Analysis of Notification Requirements for Data Security Breaches]]||Online Paper||Low:Economics||[http://www.pff.org/issues-pubs/pops/pop12.12datasecurity.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Lernard, Thomas M.||Rubin, Paul H.||2006||[[Much Ado About Notification]]||Journal Article||Low:Economics||[http://www.cato.org/pubs/regulation/regv29n1/v29n1-5.pdf &#039;&#039;Pdf&#039;&#039;]  [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=898208# &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|McAfee, Inc.||||2010||[[McAfee Threats Report]]||Industry Report||None||[http://www.mcafee.com/us/local_content/reports/2010q1_threats_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler, et. al||||2009||[[The Economics of Online Crime]]||Journal Article||Low:Technology||[http://people.seas.harvard.edu/~tmoore/jep09.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2007||[[Examining the Impact of Website Take-down on Phishing]]||Conf. Paper||Low:Technology||[http://www.ecrimeresearch.org/2007/proceedings/p1_moore.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime07.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2008||[[The Consequence of Non-Cooperation in the Fight Against Phishing]]||Conf. Paper||Low:Technology; Low:Economics||[http://people.seas.harvard.edu/~tmoore/ecrime08.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.cl.cam.ac.uk/~rnc1/ecrime08pre.pdf  &#039;&#039;Alt Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Moore, Tyler||Clayton, Richard||2009||[[The Impact of Incentives on Notice and Take-down]]||Book Chapter||Moderate:Technology; Low:Law||[http://weis2008.econinfosec.org/papers/MooreImpact.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Defense Initiative||||2009||[[National Cyber Defense Financial Services Workshop Report]]||Independent Report||Moderate:Financial Services Infrastructure; Moderate:Acronym Tolerance||[http://www.cyber.st.dhs.gov/docs/NCDI_FI_Workshop_Report.pdf &#039;&#039;Pdf&#039;&#039;] [http://ncdi.nps.edu/FI_Workshop_Report_100204.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Cyber Security Summit Task Force||||2004||[[Information Security Governance]]||Government Report||Moderate:Executive Administration||[http://www.cyber.st.dhs.gov/docs/Information%20Security%20Governance-%20A%20Call%20to%20Action%20(2004).pdf &#039;&#039;Pdf&#039;&#039;] [http://www.criminal-justice-careers.com/resources/InfoSecGov4_04.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Infrastructure Advisory Council||||2004||[[Hardening The Internet]]||Government Report||High:Technology||[http://www.cyber.st.dhs.gov/docs/NIAC%20Internet%20Hardening.pdf  &#039;&#039;Pdf&#039;&#039;] [http://www.dhs.gov/xlibrary/assets/niac/NIAC_HardeningInternetPaper_Jan05.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Institute of Standards and Technology||||2006||[[SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security]]||Government Report||Moderate:Technology||[http://www.cyber.st.dhs.gov/docs/NIST%20Guide%20to%20Supervisory%20and%20Data%20Acquisition-SCADA%20and%20Industrial%20Control%20Systems%20Security%20(2007).pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Research Council||||1999||[[Trust in Cyberspace]]||Independent Report||Moderate:Technology||[http://www.cyber.st.dhs.gov/docs/Trust%20in%20Cyberspace%20Report%201999.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Research Council||||2007||[[Toward a Safer and More Secure Cyberspace]]||Independent Report||Low:Research Processes; Low:Technology||[http://www.cyber.st.dhs.gov/docs/Toward_a_Safer_and_More_Secure_Cyberspace-Full_report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|National Science and Technology Council||||2006||[[Federal Plan for Cyber Security and Information Assurance Research and Development]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/Federal%20R&amp;amp;D%20Plan%202006.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Networking and Information Technology Research and Development||  ||2009||[[National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Nye, Joseph||||2010||[[Cyber Power]]||Book Chapter||Low:Technology; Low:Policy||[http://belfercenter.ksg.harvard.edu/files/cyber-power.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Powell, Benjamin||||2005||[[Is Cybersecurity a Public Good]]||Law Review||Low/Moderate:Economics||[http://www.independent.org/pdf/working_papers/57_cyber.pdf &#039;&#039;Pdf&#039;&#039;] [http://www.ciaonet.org/wps/pob03/pob03.pdf &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Commission on Critical Infrastructure Protection||  ||&#039;&#039;1997&#039;&#039;||[[Critical Foundations]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PCCIP%20Report%201997.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|President&#039;s Information Technology Advisory Council||  ||2005||[[Cyber Security: A Crisis of Prioritization]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/PITAC%20Report%202005.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Romanosky et al.||||2008||[[Do Data Breach Disclosure Laws Reduce Identity Theft]]||Conf. Paper||Moderate:Economics||[http://weis2008.econinfosec.org/papers/Romanosky.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Rotenberg et. al.||||2010||[[The Cyber War Threat Has Been Grossly Exaggerated]]||Debate||None||[http://intelligencesquaredus.org/index.php/past-debates/cyber-war-threat-has-been-grossly-exaggerated/ &#039;&#039;Audio/Transcript&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N., et. al||||2004||[[Computers and War]]||Conf. Paper||Moderate:Law||[http://www.ihlresearch.org/ihl/pdfs/schmittetal.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N.||||1999||[[Computer Network Attack and the Use of Force in International Law]]||Law Review||High:Law||[http://www.dtic.mil/cgi-bin/GetTRDoc?AD=ADA471993&amp;amp;Location=U2&amp;amp;doc=GetTRDoc.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Schmitt, Michael N.||||2002||[[Wired Warfare]]||Journal Article||Moderate:Law||[http://www.icrc.org/Web/eng/siteeng0.nsf/htmlall/5C5D5C/$File/365_400_Schmitt.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schneier, Bruce||||2003||[[Beyond Fear]]||Book||None||[http://www.scribd.com/doc/12185921/beyond-fear-thinking-sensibly-about-security-in-an-uncertain-world-bruce-schneier-copernicus-books-2003 &#039;&#039;Scribd&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schneier, Bruce||||2008||[[Schneier on Security]]||Book||None||[http://www.schneier.com/book-sos.html &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Schwartz, Paul||Janger, Edward||2007||[[Notification of Data Security Breaches]]||Law Review||Low:Law; Low:Economics||[http://www.michiganlawreview.org/assets/pdfs/105/5/schwartz.pdf &#039;&#039;Pdf&#039;&#039;] &lt;br /&gt;
|-&lt;br /&gt;
|Sklerov, Matthew J.||||2009||[[Solving the Dilemma of State Responses to Cyberattacks]]||Law Review||Moderate:Law; Low:Technology||[http://www.loc.gov/rr/frd/Military_Law/Military_Law_Review/pdf-files/201-fall-2009.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Stohl, Michael||||2006||[[Cyber Terrorism]]||Journal Article||None||[http://www.ingentaconnect.com/content/klu/cris/2006/00000046/F0020004/00009061 &#039;&#039;Purchase&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Swire, Peter P.||||2004||[[A Model for When Disclosure Helps Security]]||Law Review||Low/Moderate:Logic||[http://www.rootsecure.net/content/downloads/pdf/disclosure_helps_security.pdf &#039;&#039;Pdf&#039;&#039;][http://papers.ssrn.com/sol3/papers.cfm?abstract_id=531782 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Swire, Peter P.||||2006||[[A Theory of Disclosure for Security and Competitive Reasons]]||Law Review||Low/Moderate:Logic||[http://papers.ssrn.com/sol3/papers.cfm?abstract_id=842228 &#039;&#039;SSRN&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Symantec Corporation||||2010||[[Symantec Global Internet Security Threat Report]]||Industry Report||Low/Moderate:Technology||[http://www4.symantec.com/Vrt/wl?tu_id=SUKX1271711282503126202 &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Telang, Rahul||Wattal, Sunil||2007||[[Impact of Software Vulnerability Announcements on the Market Value of Software Vendors]]||Journal Article||Moderate:Economics||[http://infosecon.net/workshop/pdf/telang_wattal.pdf  &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Thomas, Rob||Martin, Jerry||2006||[[The Underground Economy]]||Journal Article||Low:Technology||[http://www.usenix.org/publications/login/2006-12/openpdfs/cymru.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Todd, Graham H.||||2009||[[Armed Attack in Cyberspace]]||Law Review||Moderate:Law||[http://www.afjag.af.mil/shared/media/document/AFD-091026-024.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Trend Micro Incorporated||  ||2010||[[Trend Micro Annual Report]]||Industry Report||Moderate:Technology||[http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/2009s_most_persistent_malware_threats__march_2010_.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|United States Secret Service||||2004||[[Insider Threat Study]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/its_report_040820.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|van Eeten, Michel J. G.||Bauer, Johannes M.||2008||[[Economics of Malware]]||Non-US Govt. Report||Moderate:Economics||[http://www.oecd.org/dataoecd/53/17/40722462.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Varian, Hal||||2000||[[Managing Online Security Risks]]||Newspaper Article||None||[http://people.ischool.berkeley.edu/~hal/people/hal/NYTimes/2000-06-01.html &#039;&#039;Web&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Varian, Hal||||2004||[[System Reliability and Free Riding]]||Book Chapter||High:Economics||[http://www.sims.berkeley.edu/resources/affiliates/workshops/econsecurity/econws/48-old.pdf &#039;&#039;Pdf&#039;&#039;]   [http://people.ischool.berkeley.edu/~hal/Papers/2004/reliability  &#039;&#039;AltPdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Verizon||||2010||[[2010 Data Breach Investigations Report]]||Industry Report||Low:Technology||[http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Watts, Sean||||2010||[[Combatant Status and Computer Network Attack]]||Law Review||Moderate:Law||[http://www.vjil.org/wp-content/uploads/2010/01/VJIL-50.2-Watts.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||||2003||[[The National Strategy to Secure Cyberspace]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/National%20Strategy%20to%20Secure%20Cyberspace%202003.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||||2010||[[The Comprehensive National Cybersecurity Initiative]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/CNCI-Cybersecurity.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|White House||||2009||[[Cyberspace Policy Review]]||Government Report||None||[http://www.cyber.st.dhs.gov/docs/Cyberspace_Policy_Review_final.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
|Zittrain, Jonathan L.||||2008||[[The Future of the Internet and How To Stop It]]||Book||None||[http://futureoftheinternet.org/static/ZittrainTheFutureoftheInternet.pdf &#039;&#039;Pdf&#039;&#039;]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
</feed>