[biblio01entry540] 540. R. Kahn, W. Corwin, T. Dennis, H. D'Hooge, D. Hubka, L. Hutcchins, J. Montague, F. Pollack, and M. Gifkins, “iMAX: A Multiprocessor Operating System for an Object-Based Computer,” Proceedings of the 8th Symposium on Operating Systems Principles, pp. 117–121 (Dec. 1979).

[biblio01entry541] 541. R. Kain, Advanced Computer Architecture: A Systems Design Approach, Prentice-Hall, Englewood Cliffs, NJ 07632 (<year>1996</year>).

[biblio01entry542] 542. R. Kain and C. Landwehr, “On Access Checking in Capability-Based Systems,” Proceedings of the 1986 IEEE Symposium on Security and Privacy, pp. 95–100 (May 1986).

[biblio01entry543] 543. B. Kaliski, The MD2 Message Digest Algorithm, RFC 1319 (Apr. 1992).

[biblio01entry544] 544. P.-H. Kamp and R. Watson, “Jails: Confining the Omnipotent Root,” Proceedings of the SANE 2000 Conference (<year>2000</year>).

[biblio01entry545] 545. M. Kang, A. Moore, and I. Moskowitz, “Design and Assurance Strategy for the NRL Pump,” IEEE Computer 31 (4), pp. 56–64 (Apr. 1998).

[biblio01entry546] 546. M. Kang and I. Moskowitz, “A Pump for Rapid, Reliable, Secure Communication,” Proceedings of the 1st ACM Conference on Computer and Communication Security, pp. 119–129 (Nov. 1993).

[biblio01entry547] 547. M. Kang, I. Moskowitz, and D. Lee, “A Network Version of the Pump,” Proceedings of the 1995 IEEE Symposium on Security and Privacy, pp.144–154 (May 1995).

[biblio01entry548] 548. M. Kang, I. Moskowitz, and D. Lee, “A Network Pump,” IEEE Transactions on Software Engineering 22 (5), pp. 329–338 (May 1996).

[biblio01entry549] 549. B. Kantor, BSD Rlogin, RFC 1282 (Dec. 1991).

[biblio01entry550] 550. P. Karger, “Limiting the Damage Potential of Discretionary Trojan Horses,” Proceedings of the 1987 IEEE Symposium on Security and Privacy, pp. 32–37 (Apr. 1987).

[biblio01entry551] 551. P. Karger and A. Herbert, “An Augmented Capability Architecture to Support Lattice Security and Traceability of Access,” Proceedings of the 1984 IEEE Symposium on Security and Privacy, pp. 2–12 (Apr. 1984).

[biblio01entry552] 552. P. Karger and R. Schell, “MULTICS Security Evaluation, Volume II: Vulnerability Analysis,” ESD-TR-74-193, Vol. II, Electronic Systems Division, Air Force Systems Command, Hanscom Field, Bedford, MA (June 1974).

[biblio01entry553] 553. P. Karger and J. Wray, “Covert Storage Channels in Disk Arm Optimization,” Proceedings of the 1991 Symposium on Research in Security and Privacy, pp. 52–61 (May 1991).

[biblio01entry554] 554. P. Karger, M. Zurko, D. Bonin, A. Mason, and C. Kahn, “A VMM Security Kernel for the VAX Architecture,” Proceedings of the 1990 Symposium on Research in Security and Privacy, pp. 2–19 (May 1990).

[biblio01entry555] 555. M. Kaufmann and J. Moore, “ACL2: An Industrial Strength Version of Nqthm,” Proceedings of the 11th Annual Conference on Computer Assurance, pp. 23–34 (June 1996).

[biblio01entry556] 556. G. Kedem and Y. Ishihara, “Brute Force Attack on UNIX Passwords with SIMD Computer,” Proceedings of the 8th USENIX Security Symposium, pp. 93–98 (Aug. 1999).

[biblio01entry557] 557. R. Kemmerer, “A Practical Approach to Identifying Storage and Timing Channels,” Proceedings of the 1982 IEEE Symposium on Security and Privacy, pp. 66–73 (Apr. 1982).

[biblio01entry558] 558. R. Kemmerer, “Shared Resource Matrix Methodology: An Approach to Identifying Storage and Timing Channels,” ACM Transactions on Computer Systems, 1 (3), pp. 256–277 (Aug. 1983).

[biblio01entry559] 559. R. Kemmerer, “Analyzing Encryption Protocols Using Formal Verification Techniques,” IEEE Journal on Selected Areas in Communications SAC-7 (4), pp. 448–457 (May 1989).

[biblio01entry560] 560. R. Kemmerer, C. Meadows, and J. Millen, “Three Systems for Cryptographic Protocol Analysis,” Journal of Cryptology 7 (2), pp. 79–130 (Spring 1994).

[biblio01entry561] 561. S. Kent, “Encryption-Based Protection Protocols for Interactive User-Computer Communication,” Technical Report MIT/LCS/TR-162, Laboratory for Computer Science, Massachusetts Institute of Technology, Cambridge, MA (May 1976); cited in Cryptography and Data Security [269].

[biblio01entry562] 562. S. Kent, “Comments on 'Security Problems in the TCP/IP Protocol Suite',” Computer Communications Review 19 (3), pp. 10–19 (July 1989).

[biblio01entry563] 563. S. Kent, Privacy Enhancement for Internet Electronic Mail: Part II: Certificate-Based Key Management, RFC 1422 (Feb. 1993).

[biblio01entry564] 564. B. Kernighan and P. Plauger, The Elements of Programming Style, McGraw-Hill Book Co., Reading, MA (<year>1974</year>).

[biblio01entry565] 565. B. Kernighan and P. Plauger, Software Tools, Addison-Wesley, Reading, MA (<year>1976</year>).

[biblio01entry566] 566. K. Keus, W. Kirth, and D. Loevenich, “Quality Assurance in the ITSEC-Evaluation Environment in Germany,” Proceedings of the 16th National Information Systems Security Conference, pp. 324–333 (Sep. 1993).

[biblio01entry567] 567. K. Keus and K.-W. Schröder, “Measuring Correctness and Effectiveness: A New Approach Using Process Evaluation,” Proceedings of the 18th National Information Systems Security Conference, pp. 366–373 (Oct. 1995).

[biblio01entry568] 568. G. Kim and E. Spafford, “Experiences with Tripwire: Using Integrity Checkers for Intrusion Detection,” Proceedings of SANS III, pp. 89–102 (Apr. 1994).

[biblio01entry569] 569. G. Kim and E. Spafford, “The Design and Implementation of Tripwire: A File System Integrity Checker,” Proceedings of the 2nd ACM Conference on Computer and Communications Security (Nov. 1994).

[biblio01entry570] 570. J.-Y. Kim and K.-C. Kwon, “Methodology for Safety-Related Software Development [for Nuclear Power Plants],” Proceedings of the 1996 American Nuclear Society International Topical Meeting on Nuclear Plant Instrumentation, Control and Human-Machine Interface Technologies, pp. 1041–1046 (May 1996).

[biblio01entry571] 571. J. Kirby, Jr., M. Archer, and C. Heitmeyer, “SCR: A Practical Approach to Building a High Assurance COMSEC System,” Proceedings of the 15th Annual Computer Security Applications Conference, pp. 109–118 (Dec. 1999).

[biblio01entry572] 572. D. Klein, “A Capability Based Protection Mechanism Under Unix,” Proceedings of the 1985 Winter USENIX Conference, pp. 152–159 (Jan. 1995).

[biblio01entry573] 573. D. Klein, “Foiling the Cracker: A Survey of, and Improvements to, Password Security,” Proceedings of the 2nd USENIX UNIX Security Workshop, pp. 5–14 (Aug. 1990).

[biblio01entry574] 574. J. Knight and N. Leveson, “An Experimental Evaluation of the Assumption of Independence in Multi-Version Programming,” IEEE Transactions on Software Engineering 12 (1), pp. 96–109 (Jan. 1986).

[biblio01entry575] 575. J. Knight and N. Leveson, “On N-version Programming,” Software Engineering Notes 15 (1), pp. 24–35 (Jan. 1990).

[biblio01entry576] 576. Knightmare, Secrets of a Super Hacker, Loompanics Unlimited (<year>1994</year>).

[biblio01entry577] 577. L. Knudsen, “Cryptanalysis of LOKI91,” Advances in Cryptology—AUSCRYPT '92 Proceedings, pp. 196–208 (<year>1992</year>).

[biblio01entry578] 578. D. Knuth, The Art of Computer Programming Volume 2: Seminumerical Algorithms, 3rd Edition, Addison-Wesley, Reading, MA (1998).

[biblio01entry579] 579. L. Kohnfelder, “A Method for Certification,” Laboratory for Computer Science, Massachusetts Institute of Technology, Cambridge, MA (May 1978); cited in Cryptography and Data Security [269].

[biblio01entry580] 580. C. Ko, G. Fink, and K. Levitt, “Automated Detection of Vulnerabilities in Privileged Programs by Execution Monitoring,” Proceedings of the10th Annual Computer Security Applications Conference, pp. 134–144 (Dec. 1994).

[biblio01entry581] 581. C. Ko, T. Fraser, L. Badger, and D. Kilpatrick, “Detecting and Countering System Intrusions Using Software Wrappers,” Proceedings of the 9th USENIX Security Symposium, pp. 145–156 (Aug. 2000).

[biblio01entry582] 582. C. Ko, M. Ruschitzka, and K. Levitt, “Execution Monitoring of Security-Critical Programs in Distributed Systems: A Specification-Based Approach,” Proceedings of the 1997 IEEE Symposium on Security and Privacy, pp. 175–187 (May 1997).

[biblio01entry583] 583. H.-P. Ko, “Security Properties of Ring Brackets,” Proceedings of the Computer Security Foundations Workshop II, pp. 41–46 (June 1989).

[biblio01entry584] 584. N. Koblitz, A Course in Number Theory and Cryptography, Springer-Verlag, New York, NY (<year>1994</year>).

[biblio01entry585] 585. C. Kocher, “Connecting Classified Nets to the Outside World: Costs and Benefits,” Proceedings of the 20th National Information Systems Security Conference, pp. 534–542 (Oct. 1997).

[biblio01entry586] 586. P. Kocher, “Timing Attacks on Implementations of Diffie-Hellman, RSA, DSS, and Other Systems,” Advances in Cryptology—Proceedings of CRYPTO '96, pp. 104–113 (Aug. 1996).

[biblio01entry587] 587. P. Kocher, J. Jaffe, and B. Jun, “Differential Power Analysis,” Advances in Cryptology—Proceedings of CRYPTO '99, pp. 388–397 (Aug. 1999).

[biblio01entry588] 588. A. Koenig, C Traps and Pitfalls, Addison-Wesley, Reading, MA (<year>1989</year>).

[biblio01entry589] 589. J. Kohl and C. Neuman, The Kerberos Network Authentication Service (V5), RFC 1510 (Sep. 1993).

[biblio01entry590] 590. A. Konheim, Cryptography: A Primer, John Wiley and Sons, New York, NY (<year>1981</year>).

[biblio01entry591] 591. C. Kormos, L. Gallagher, N. Givans, and N. Bartol, “Using Security Metrics to Assess Risk Management Capabilities,” Proceedings of the 22nd National Information Systems Security Conference, pp. 370–388 (Oct. 1999).

[biblio01entry592] 592. D. Kosiur, Building and Managing Virtual Private Networks, John Wiley and Sons, New York, NY (<year>1998</year>).

[biblio01entry593] 593. S. Kramer, “On Incorporating Access Control Lists into the UNIX Operating System,” Proceedings of the USENIX UNIX Security Workshop, pp. 38–48 (Aug. 1988).

[biblio01entry594] 594. H. Krawczyk, M. Bellare, and R. Canetti, HMAC: Keyed-Hashing for Message Authentication, RFC 2104 (Feb. 1997).

[biblio01entry595] 595. H. Krawczyk, “How to Predict Congruential Generators,” Journal of Algorithms 13 (4), pp. 527–545 (Dec. 1992).

[biblio01entry596] 596. W. Kremer, H. Saraidaridis, and A. Sripad, “The D5 Digital Terminal System: A Case Study of a Comprehensive Quality and Reliability Program,” IEEE Journal on Selected Areas in Communications 4 (7), pp. 1099–1103 (Oct. 1986).

[biblio01entry597] 597. D. Kristol and L. Montulli, HTTP State Management Mechanism, RFC 2109 (Feb. 1997).

[biblio01entry598] 598. I. Krsul and E. Spafford, “Authorship Analysis: Identifying the Author of a Program,” Proceedings of the 18th National Information Systems Security Conference, pp. 514–524 (Oct. 1995).

[biblio01entry599] 599. C. Kubicki, “The System Administration Maturity Model—SAMM,” Proceedings of the 7th Systems Administration Conference (LISA 1993), pp. 213–225 (Nov. 1993).

[biblio01entry600] 600. R. Kuhn, “Mutual Exclusion of Roles as a Means of Implementing Separation of Duty in Role-Based Access Control Systems,” Proceedings of the 2nd ACM Workshop on Role-Based Access Control, pp. 23–30 (Nov. 1997).

[biblio01entry601] 601. S. Kumar and E. Spafford, “A Pattern Matching Model for Misuse Intrusion Detection,” Proceedings of the 17th National Computer Security Conference, pp. 11–21 (Oct. 1994).

[biblio01entry602] 602. J. Lacy, D. Mitchell, and W. Schell, “CrptoLib: Cryptography in Software,” Proceedings of the 4th USENIX UNIX Security Symposium, pp. 1–17 (June 1993).

[biblio01entry603] 603. N. Lai and T. Gray, “Strengthening Discretionary Access Controls to Inhibit Trojan Horses and Computer Viruses,” Proceedings of the 1988 Summer USENIX Conference, pp. 275–286 (June 1988).

[biblio01entry604] 604. X. Lai, J. Massey, and S. Murphy, “Markov Ciphers and Differential Cryptanalysis,” Advances in Cryptology—Proceedings of EUROCRYPT '91, pp. 17–38 (<year>1991</year>).

[biblio01entry605] 605. B. LaMacchia and A. Odlyzko, “Computation of Discrete Logarithms in Prime Fields,” Designs, Codes, and Cryptography 1, pp. 46–62 (May 1991).

[biblio01entry606] 606. L. Lamport, “Password Authentication with Insecure Communication,” Communications of the ACM 24 (11), pp. 770–771 (Nov. 1981).

[biblio01entry607] 607. L. Lamport, “Time, Clocks, and the Ordering of Events in a Distributed System,” Communications of the ACM 21 (7), pp. 558–565 (July 1978).

[biblio01entry608] 608. B. Lampson, “Protection,” Proceedings of the Fifth Princeton Symposium of Information Science and Systems, pp. 437–443 (Mar. 1971); reprinted in Operating Systems Review 8 (1), pp. 18–24 (Jan. 1974).

[biblio01entry609] 609. B. Lampson, “A Note on the Confinement Problem,” Communications of the ACM 16 (10), pp. 613–615 (Oct. 1973).

[biblio01entry610] 610. L. Laudan, The Book of Risks: Fascinating Facts About the Chances We Take Every Day, John Wiley and Sons, New York, NY 10158 (<year>1994</year>).

[biblio01entry611] 611. T. Lane and C. Brodley, “Temporal Sequence Learning and Data Reduction for Anomaly Detection,” ACM Transactions on Information and System Security 2 (3), pp. 295–332 (Aug. 1999).

[biblio01entry612] 612. C. Landwehr, “Formal Models for Computer Security,” Computing Surveys 13 (3), pp. 247–278 (Sep. 1981).

[biblio01entry613] 613. C. Landwehr, C. Heitmeyer, and J. McLean, “A Security Model for Military Message Systems,” ACM Transactions on Computer Systems 2 (2), pp. 198–222 (Aug. 1984).

[biblio01entry614] 614. C. Landwehr, A. Bull, J. McDermott, and W. Choi, “A Taxonomy of Computer Program Security Flaws,” Computing Surveys 26 (3), pp. 211–254 (Sep. 1994).

[biblio01entry615] 615. C. Landwehr and D. Goldschlag, “Security Issues in Networks with Internet Access,” Proceedings of the IEEE 85 (12), pp. 2034–2051 (Dec. 1997).

[biblio01entry616] 616. L. Lankewicz and M. Benard, “Real-Time Anomaly Detection Using a Nonparametric Pattern Recognition Approach,” Proceedings of the 7th Annual Computer Security Applications Conference, pp. 80–89 (Dec. 1991).

[biblio01entry617] 617. L. LaPadula, “The 'Basic Security Theorem' of Bell and LaPadula Revisited,” handout from Computer Security Foundations Workshop (April 18, 1988).

[biblio01entry618] 618. G. Lawton, “Biometrics: A New Era in Security,” IEEE Computer 31 (8), pp. 16–18 (Aug. 1998).

[biblio01entry619] 619. T. Lee, “Using Mandatory Integrity to Enforce 'Commercial' Security,” Proceedings of the 1988 IEEE Symposium on Security and Privacy, pp. 140–146 (Apr. 1988).

[biblio01entry620] 620. W. Lee, “A Data Mining Framework for Building Intrusion Detection Models,” Proceedings of the 1999 IEEE Symposium on Security and Privacy, pp. 120–132 (May 1999).

[biblio01entry621] 621. P. Leong and C. Tham, “UNIX Password Encryption Considered Insecure,” Proceedings of the 1991 Winter USENIX Technical Conference, pp. 269–280 (Jan. 1991).

[biblio01entry622] 622. N. Leveson, Safeware: System Safety and Computers, Addison-Wesley, Reading, MA (<year>1995</year>).

[biblio01entry623] 623. A. Levi and M. Caglayan, “An Efficient, Dynamic, and Trust Preserving Public Key Infrastructure,” Proceedings of the 2000 IEEE Symposium on Security and Privacy, pp. 203–214 (May 2000).

[biblio01entry624] 624. R. Levin, The Computer Virus Handbook, Osborne McGraw-Hill, Berkeley, CA (<year>1990</year>).

[biblio01entry625] 625. W. Ley, Watchers of the Skies: An Informal History of Astronomy from Babylon to the Space Age, Viking Press, New York, NY (<year>1966</year>).

[biblio01entry626] 626. Q. Li and B.-H. Juang, “Speaker Verification Using Verbal Information Verification for Automatic Enrollment,” Proceedings of the 1998 IEEE International Conference on Acoustics, Speech, and Signal Processing, pp. 133–136 (May 1998).

[biblio01entry627] 627. Q. Li, B.-H. Juang, and C.-H. Lee, “Automatic Verbal Information Verification for User Authentication,” IEEE Transactions on Speech and Audio Processing 8 (5), pp. 585–596 (Sep. 2000).

[biblio01entry628] 628. Q. Li, B.-H. Juang, C.-H. Lee, Q. Zhou, and F. K. Soong, “Recent Advancements in Automatic Speaker Authentication,” IEEE Robotics and Automation Magazine 6 (1), pp. 24–34 (Mar. 1999).

[biblio01entry629] 629. A. Liebenberg and J. Eloff, “MASS—Model for an Auditing Security System,” Proceedings of SEC 2000: Information Security, pp. 141–150 (Aug. 2000).

[biblio01entry630] 630. H.-Y. Lin and L. Harn, “A Generalized Secret Sharing Scheme with Cheater Detection,” Advances in Cryptology—Proceedings of ASIACRYPT '91, pp. 149–158 (<year>1991</year>).

[biblio01entry631] 631. T. Lin, “Chinese Wall Security Policy—An Aggressive Model,” Proceedings of the 5th Annual Computer Security Conference, pp. 282–289 (Dec. 1989).

[biblio01entry632] 632. R. Linde, “Operating Systems Penetration,” 1978 National Computer Conference, AFIPS Conference Proceedings 44, pp. 361–368 (Nov. 1975).

[biblio01entry633] 633. R. Linde, C. Weissman, and C. Fox, “The ADEPT-50 Time-Sharing System,” Proceedings of the 1969 Fall Joint Computer Conference, pp. 39–50 (Nov. 1969).

[biblio01entry634] 634. J. Linn, Privacy Enhancement for Internet Electronic Mail: Part I: Message Encryption and Authentication Procedures, RFC 1421 (Feb. 1993).

[biblio01entry635] 635. S. Lipner, “A Comment on the Confinement Problem,” Proceedings of the 5th Symposium on Operating Systems Principles, pp. 192–196 (Nov. 1975).

[biblio01entry636] 636. S. Lipner, “Non-Discretionary Controls for Commercial Applications,” Proceedings of the 1982 Symposium on Privacy and Security, pp. 2–10 (Apr. 1982).

[biblio01entry637] 637. S. Lipner, “Twenty Years of Evaluation Criteria and Commercial Technology,” Proceedings of the 1999 IEEE Symposium on Security and Privacy, pp. 111–112 (May 1999).

[biblio01entry638] 638. R. Lippmann, D. Fried, I. Graf, J. Haines, K. Kendall, D. McClung, D. Weber, S. Webster, D. Wyschogrod, R. Cunningham, and M. Zissman, “Evaluating Intrusion Detection Systems: The 1998 DARPA Off-Line Intrusion Detection Evaluation,” Proceedings of the DARPA Information Survivability Conference and Exposition, 2, pp. 12–26 (Jan. 2000).

[biblio01entry639] 639. R. Lippmann, J. Haines, D. Fired, J. Korba, and K. Das, “Analysis and Results of the 1999 DARPA Off-Line Intrusion Detection Evaluation,” Proceedings of the 3rd International Workshop on Recent Advances in Intrusion Detection, pp. 162–182 (Oct. 2000).

[biblio01entry640] 640. R. Lipton and T. Budd, “On Classes of Protection Systems,” in Foundations of Secure Computing [265], pp. 281–291.

[biblio01entry641] 641. R. Lipton and L. Snyder, “A Linear Time Algorithm for Deciding Subject Security,” Journal of the ACM 24 (3), pp. 455–464 (July 1977).

[biblio01entry642] 642. J. Littman, The Watchman: The Twisted Life and Crimes of Serial Hacker Kevin Poulsen, Little, Brown, & Co., Boston, MA (<year>1997</year>).

[biblio01entry643] 643. S. Lodin and C. Schuba, “Firewalls Fend Off Invasions from the Net,” IEEE Spectrum 35 (2), pp. 26–34 (Feb. 1998).

[biblio01entry644] 644. L. Lopez and J. Carracedo, “Hierarchical Organization of Certification Authorities for Secure Environments,” Proceedings of the 1997 Symposium on Network and Distributed System Security, pp. 112–121 (Feb. 1997).

[biblio01entry645] 645. M. Ludwig, The Giant Black Book of Computer Viruses, American Eagle Publishers, Phoenix, AZ (<year>1998</year>).

[biblio01entry646] 646. E. Lundin and E. Jonsson, “Anomaly-Based Intrusion Detection: Privacy Concerns and Other Problems,” Computer Networks 34 (4), pp. 623–640 (Oct. 2000).

[biblio01entry647] 647. U. Lindqvist, T. Olovsson, and E. Jonsson, “An Analysis of a Secure System Based on Trusted Components,” Proceedings of the 11th Annual Conference on Computer Assurance, pp. 213–223 (June 1996).

[biblio01entry648] 648. T. Lunt and R. Jagannathan, “A Prototype Real-Time Intrusion-Detection Expert System,” Proceedings of the 1988 IEEE Symposium on Security and Privacy, pp. 2–10 (Apr. 1988).

[biblio01entry649] 649. T. Lunt, R. Schell, W. Shockley, M. Heckman, and D. Warren, “ A Near-Term Design for the SeaView Multilevel Database System,” Proceedings of the 1988 IEEE Symposium on Security and Privacy, pp. 234–244 (Apr. 1988).

[biblio01entry650] 650. E. Lupu and M. Sloman, “Towards a Role-Based Framework for Distributed Systems Management,” Journal of Network and Systems Management 5 (1), pp. 5–30 (Mar. 1997).

[biblio01entry651] 651. R. Lutz, “Analyzing Software Requirements Errors in Safety-Critical, Embedded Systems,” Proceedings of the IEEE International Symposium on Requirements Engineering, pp. 126–133 (Jan. 1993).

[biblio01entry652] 652. S. Maguire, Writing Solid Code: Microsoft's Techniques for Developing Bug-Free C Programs, Microsoft Press, Redmond, WA (<year>1993</year>).

[biblio01entry653] 653. Her Majesty's Stationery Office, Securities and Investment Board Rules, Chapter III, Part 5:08, London, UK; cited in “The Chinese Wall Policy” [146].

[biblio01entry654] 654. Her Majesty's Stationery Office, Financial Services Act 1986, §48(2)(h), London, UK (<year>1986</year>); cited in “The Chinese Wall Policy” [146].

[biblio01entry655] 655. D. Malkhi, M. Reiter, and A. Rubin, “Secure Execution of Java Applets Using a Remote Playground,” Proceedings of the 1998 IEEE Symposium on Security and Privacy, pp. 40–51 (May 1998).

[biblio01entry656] 656. U. Manber, “A Simple Scheme to Make Passwords Based on One-Way Functions Much Harder to Crack,” Computers and Security 15 (2), pp. 171–176, (Mar. 1996).

[biblio01entry657] 657. D. Mann and S. Christey, “Towards a Common Enumeration of Vulnerabilities,” Proceedings of the 2nd Workshop on Research with Security Vulnerability Databases (Jan. 1999).

[biblio01entry658] 658. C. Markantonakis, “Secure Log File Download Mechanisms for Smart Cards,” Proceedings of the 3rd International Conference on Smart Card Research and Applications, pp. 285–304 (Sep. 1998).

[biblio01entry659] 659. C. Markantonakis and S. Xenitellis, “Implementing a Secure Log File Download Manager for the Java Card,” Proceedings of the Conference on Communications and Multi-Media Security, pp. 143–159 (Sep. 1999).

[biblio01entry660] 660. T. Markham and C. Williams, “Key Recovery Header for IPSEC,” Computers and Security 19 (1), pp. 86–90 (Jan./Feb. 2000).

[biblio01entry661] 661. M. Marrinan, “In the Chips (Smart Card Applications),” Bank Systems and Technology 32 (5), pp. 46–48 (May 1995).

[biblio01entry662] 662. D. Martin, S. Rajagopalan, and A. Rubin, “Blocking Java Applets at the Firewall,” Proceedings of the 1997 Symposium on Network and Distributed System Security, pp. 16–26 (Feb. 1997).

[biblio01entry663] 663. M. Matsui, “Linear Cryptanalysis Method for DES Cipher,” Advances in Cryptology—Proceedings of EUROCRYPT '93, pp. 386–397 (May 1993).

[biblio01entry664] 664. M. Matsumoto, S. Shimagaki, D. Watanabe, and K. Mori, “Assurance Technologies for Autonomous Train On-Board Computer System,” Proceedings of the 8th IEEE Workshop on Future Trends of Distributed Computing Systems, pp. 170–175 (Oct. 2001).

[biblio01entry665] 665. S. Matyas and C. Meyer, “Generation, Distribution, and Installation of Cryptographic Keys,” IBM Systems Journal 17 (2), pp. 126–137 (1978).

[biblio01entry666] 666. D. Maughan, M. Schertler, M. Schneider, and J. Turner, Internet Security Association and Key Management Protocol (ISAKMP), RFC 2408 (Nov. 1998).

[biblio01entry667] 667. A. Mayer, A. Wool, and E. Ziskind, “Fang: a Firewall Analysis Engine,” Proceedings of the 2000 IEEE Symposium on Security and Privacy, pp. 177–187 (May 2000).

[biblio01entry668] 668. D. Mazières and M. Kaashoek, “The Design, Implementation, and Operation of an Email Pseudonym Server,” Proceedings of the 5th ACM Conference on Computer and Communications Security, pp. 27–36 (Nov. 1998).

[biblio01entry669] 669. S. McCanne and V. Jacobson, “The BSD Packet Filter: A New Architecture for User-Level Packet Capture,” Proceedings of the 1993 Winter USENIX Conference, pp. 259–269 (Jan. 1993).

[biblio01entry670] 670. C. McCollum, J. Messing, and L. Notargiacomo, “Beyond the Pale of MAC and DAC—Defining New Forms of Access Control,” Proceedings of the 1990 IEEE Computer Society Symposium on Research in Security and Privacy, pp. 190–200 (May 1990).

[biblio01entry671] 671. D. McCullagh, “DVD Lawyers Make Secret Public,” Wired News (Jan. 26, 2000); available at,1283,33922,00.html.

[biblio01entry672] 672. D. McCullough, “Specifications for Multi-Level Security and a Hook-Up Theorem,” Proceedings of the 1987 IEEE Symposium on Security and Privacy, pp. 161–166 (Apr. 1987).

[biblio01entry673] 673. D. McCullough, “Non-Interference and the Composability of Security Properties,” Proceedings of the 1988 IEEE Symposium on Security and Privacy, pp. 177–186 (Apr. 1988).

[biblio01entry674] 674. J. McDermid and Q. Shi, “Secure Composition of Systems,” Proceedings of the 8th Annual Computer Security Applications Conference, pp. 112–122 (Dec. 1992).

[biblio01entry675] 675. J. McDermott and C. Fox, “Using Abuse Case Models for Security Requirements Analysis,” Proceedings of the 15th Annual Computer Security Applications Conference, pp. 55–64 (Dec. 1999).

[biblio01entry676] 676. G. McGraw, “Software Assurance for Security,” IEEE Computer 32 (4), pp. 103–105 (Apr. 1999).

[biblio01entry677] 677. J. McHugh, “The 1998 Lincoln Laboratory IDS Evaluation: A Critique,” Proceedings of the 3rd International Workshop on Recent Advances in Intrusion Detection, pp. 145–161 (Oct. 2000).

[biblio01entry678] 678. J. McHugh and D. Good, “An Information Flow Tool for Gypsy,” Proceedings of the 1985 IEEE Symposium on Security and Privacy, pp. 46–48 (Apr. 1985).

[biblio01entry679] 679. M. McIlroy, “Virology 101,” Computing Systems 2 (2), pp. 173–181 (Spring 1989).

[biblio01entry680] 680. M. McKusick, K. Bostic, M. Karels, and J. Quarterman, The Design and Implementation of the 4.4BSD Operating System, Addison-Wesley Publishing Co., Reading, MA (<year>1996</year>).

[biblio01entry681] 681. I. McLean, Windows 2000 Security, The Coriolis Group, LLC., Scottsdale, AZ (<year>2000</year>).

[biblio01entry682] 682. J. McLean, “A Comment on the 'Basic Security Theorem' of Bell and LaPadula,” Information Processing Letters 20 (2), pp. 67–70 (Feb. 1985).

[biblio01entry683] 683. J. McLean, “Reasoning About Security Models,” Proceedings of the 1987 IEEE Symposium on Security and Privacy, pp. 123–131 (Apr. 1987).

[biblio01entry684] 684. J. McLean, “Proving Noninterference and Functional Correctness Using Traces,” Journal of Computer Security 1 (1), pp. 37–57 (1992).

[biblio01entry685] 685. J. McLean, “Is the Trusted Computing Base Concept Fundamentally Flawed?” Proceedings of the 1997 IEEE Symposium on Security and Privacy, p. 2 (May 1997).

[biblio01entry686] 686. J. McLean, “Twenty Years of Formal Methods,” Proceedings of the 1999 IEEE Symposium on Security and Privacy, pp. 115–116 (May 1999).

[biblio01entry687] 687. D. McNutt, “Role-Based System Administration or Who, What, Where, and How,” Proceedings of the 7th System Administration Conference (LISA '93), pp. 107–112 (Nov. 1993).

[biblio01entry688] 688. C. Meadows, “The Integrity Lock Architecture and Its Application to Message Systems: Reducing Covert Channels,” Proceedings of the 1987 IEEE Symposium on Security and Privacy, pp. 212–218 (Apr. 1987).

[biblio01entry689] 689. C. Meadows, “Extending the Brewer-Nash Model to a Multilevel Context,” Proceedings of the 1990 IEEE Symposium on Research in Security and Privacy, pp. 95–102 (May 1990).

[biblio01entry690] 690. C. Meadows, “The NRL Protocol Analyzer: An Overview,” Journal of Logic Programming 26 (2), pp. 113–131 (Feb. 1996).

[biblio01entry691] 691. C. Meadows, “Analyzing the Needham-Schroeder Public Key Protocol: A Comparison of Two Approaches,” Proceedings of the 4th European Symposium on Research in Computer Security, pp. 351–364 (Sep. 1996).

[biblio01entry692] 692. C. Meadows, “Analysis of the Internet Key Exchange Protocol Using the NRL Protocol Analyzer,” Proceedings of the 1999 IEEE Symposium on Security and Privacy, pp. 216–231 (May 1999).

[biblio01entry693] 693. G. Medvinsky and B. Neuman, “NetCash: A Design for Practical Electronic Currency on the Internet,” Proceedings of the 1st ACM Conference on Computer and Communications Security, pp. 102–106 (Oct. 1993).

[biblio01entry694] 694. N. Mehta and K. Sollins, “Expanding and Extending the Security Features of Java,” Proceedings of the 7th USENIX Security Symposium, pp. 159–172 (Jan. 1998).

[biblio01entry695] 695. A. Menezes, P. Van Oorschot, and S. Vanstone, Handbook of Applied Cryptography, CRC Press, Boca Raton, FL (<year>1997</year>).

[biblio01entry696] 696. C. Menk, III, “System Security Engineering Capability Maturity Model and Evaluations: Partners Within the Assurance Framework,” Proceedings of the 19th National Information Systems Security Conference, pp. 76–88 (Oct. 1996).

[biblio01entry697] 697. R. Merkle, “Protocols for Public Key Cryptosystems,” Proceedings of the 1980 Symposium on Privacy and Security, pp. 122–133 (Apr. 1980).

[biblio01entry698] 698. R. Merkle, “A Fast Software One-Way Hash Function,” Journal of Cryptology 3 (1), pp. 43–58 (1990).

[biblio01entry699] 699. R. Merkle, “Fast Software Encryption Functions,” Advances in Cryptology—Proceedings of CRYPTO '90, pp. 476–501 (Aug. 1990).

[biblio01entry700] 700. R. Merkle and M. Hellman, “On the Security of Multiple Encryption,” Communications of the ACM 24 (7), pp. 465–467 (July 1981).

[biblio01entry701] 701. C. Meyer, “Ciphertext/Plaintext and Ciphertext/Key Dependence vs. Number of Rounds for the Data Encryption Standard,” 1978 National Computer Conference, AFIPS Conference Proceedings 47, pp. 1119–1126 (June 1978).

[biblio01entry702] 702. C. Meyer and S. Matyas, Cryptography: A New Dimension in Computer Data Security: A Guide for the Design and Implementation of Secure Systems, John Wiley and Sons, New York, NY (<year>1982</year>).

[biblio01entry703] 703. G. Meyer, The PPP Encryption Control Protocol (ECP), RFC 1968 (June 1996).

[biblio01entry704] 704. S. Mhlaba, “The Efficacy of International Regulation of Transborder Data Flows: The Case for the Clipper Chip,” Government Information Quarterly 12 (4), pp. 353–366 (1995).

[biblio01entry705] 705. C. Michael and A. Ghosh, “Two State-Based Approaches to Program-Based Anomaly Detection,” Proceedings of the 16th Annual Computer Security Applications Conference, pp. 21–30 (Dec. 2000).

[biblio01entry706] 706. G. Michaelson and M. Prior, Naming Guidelines for the AARNet X.500 Directory Service, RFC 1562 (Dec. 1993).

[biblio01entry707] 707. J. Millen, “The Interrogator: A Tool for Cryptographic Protocol Security,” Proceedings of the 1984 IEEE Symposium on Security and Privacy, pp. 134–141 (Apr. 1984).

[biblio01entry708] 708. J. Millen, C. Clark, and S. Freedman, “The Interrogator: Protocol Security Analysis,” IEEE Transactions on Software Engineering 13 (2), pp. 274–288 (Feb. 1987).

[biblio01entry709] 709. J. Millen, “The Cascading Problem for Interconnected Networks,” Proceedings of the 4th Aerospace Computer Security Applications Conference, pp. 269–274 (Dec. 1988).

[biblio01entry710] 710. J. Millen, “Covert Channel Capacity,” Proceedings of the 1993 IEEE Symposium on Research in Security and Privacy, pp. 60–65 (May 1993).

[biblio01entry711] 711. J. Millen, “Unwinding Forward Correctability,” Journal of Computer Security 3 (1), pp. 35–54 (1994/1995).

[biblio01entry712] 712. J. Millen, “20 Years of Covert Channel Modeling and Analysis,” Proceedings of the 1999 IEEE Symposium on Security and Privacy, pp. 113–114 (May 1999).

[biblio01entry713] 713. B. Miller, “Vital Signs of Identity,” IEEE Spectrum 31 (2), pp. 22–30 (Jan. 1994).

[biblio01entry714] 714. B. Miller, L. Fredriksen, and B. So, “An Empirical Study of the Reliability of UNIX Utilities,” Communications of the ACM 33 (12), pp. 32–44 (Dec. 1990).

[biblio01entry715] 715. D. Miller and R. Baldwin, “Access Control by Boolean Expression Evaluation,” Proceedings of the 5th Annual Computer Security Applications Conference, pp. 131–139 (Dec. 1990).

[biblio01entry716] 716. T. Miller and T. De Raadt, “strlcpy and strlcat—Consistent, Safe, String Copy and Concatenation,” Proceedings of the FREENIX Track of the 1999 USENIX Conference, pp. 175–178 (June 1999).

[biblio01entry717] 717. M. Minsky, Computation: Finite and Infinite Machines, Prentice-Hall, Englewood Cliffs, NJ (<year>1967</year>).

[biblio01entry718] 718. N. Minsky, “Selective and Locally Controlled Transport of Privileges,” ACM Transactions on Programming Languages and Systems 6 (4), pp. 573–602 (Oct. 1984).

[biblio01entry719] 719. S. Mister and S. Tavares, “Cryptanalysis of RC4-Like Ciphers,” Proceedings of the 5th Annual International Workshop on Selected Areas in Cryptography, pp. 131–143 (Aug. 1998).

[biblio01entry720] 720. J. Mitchell, V. Shmatikov, and U. Stern, “Finite-State Analysis of SSL 3.0,” Proceedings of the 7th USENIX Security Symposium, pp. 201–215 (Jan. 1998).

[biblio01entry721] 721. S. Miyaguchi, “The FEAL Cipher Family,” Advances in Cryptology—Proceedings of EUROCRYPT '90, pp. 627–638 (<year>1991</year>).

[biblio01entry722] 722. P. Mockapetris, Domain Names Concepts and Facilities, RFC 1034 (Nov. 1987).

[biblio01entry723] 723. P. Mockapetris, Domain Names Implementation and Specification, RFC 1035 (Nov. 1987).

[biblio01entry724] 724. J. Mogul, R. Rashid, and M. Accetta, “The Packet Filter: An Efficient Mechanism for User-Level Network Code,” Proceedings of the 11th Symposium on Operating Systems Principles, pp. 39–51 (Nov. 1987).

[biblio01entry725] 725. V.Molak (ed.), Fundamentals of Risk Analysis and Risk Management, CRC Press, Boca Raton, FL (<year>1996</year>).

[biblio01entry726] 726. F. Monrose, “Biometrics for Automatic Identity Verification,” Technical Report 722, Department of Computer Science, New York University, New York, NY (1998).

[biblio01entry727] 727. F. Monrose and A. Rubin, “Authentication via Keystroke Dynamics,” Proceedings of the 4th ACM Conference on Computer and Communications Security, pp. 48–56 (Nov. 1997).

[biblio01entry728] 728. A. Moore and C. Payne,, Jr., “Increasing Assurance with Literate Programming Techniques,” Proceedings of the 11th Annual Conference on Computer Assurance, pp. 187–198 (June 1996).

[biblio01entry729] 729. J. Moore, “Protocol Failures in Cryptosystems,” Proceedings of the IEEE 76 (5), pp. 594–602 (May 1988).

[biblio01entry730] 730. M. Moriconi, X. Qian, R. Riemenschneider, and L. Gong, “Secure Software Architectures,” Proceedings of the 1997 IEEE Symposium on Security and Privacy, pp. 84–93 (May 1997).

[biblio01entry731] 731. R. Morris and K. Thompson, “Password Security: A Case History,” Communications of the ACM 22 (11), pp. 594–597 (Nov. 1979).

[biblio01entry732] 732. I. Moskowitz, “Variable Noise Effects upon a Simple Timing Channel,” Proceedings of the 1991 IEEE Symposium on Research in Security and Privacy, pp. 362–372 (May 1991).

[biblio01entry733] 733. I. Moskowitz and A. Miller, “The Influence of Delay upon an Idealized Channel's Bandwidth,” Proceedings of the 1992 IEEE Symposium on Security and Privacy, pp. 62–67 (May 1992).

[biblio01entry734] 734. I. Moskowitz, S. Greenwald, and M. Kang, “An Analysis of the Timed Z-Channel,” Proceedings of the 1996 IEEE Symposium on Security and Privacy, pp. 2–9 (May 1996).

[biblio01entry735] 735. G. Mourani, Securing and Optimizing Linux: Red Hat Edition—A Hands-On Guide, OpenDocs, LLC, Salem, OR (Aug. 2000).

[biblio01entry736] 736. A. Muffett, “crack” (unpublished) (1992).

[biblio01entry737] 737. A. Muffett, “WAN-Hacking with AutoHack: Auditing Security Behind the Firewall,” Proceedings of the 5th USENIX UNIX Security Symposium, pp. 21–34 (June 1995).

[biblio01entry738] 738. S. Murphy, “The Cryptanalysis of FEAL-4 with 20 Chosen Plaintexts,” Journal of Cryptology 2 (3), pp. 145–154 (1990).

[biblio01entry739] 739. W. Murray, “The Application of Epidemiology to Computer Viruses,” Computers and Security 7 (1), pp. 139–150 (Feb. 1988).

[biblio01entry740] 740. A. Myers and B. Liskov, “Complete, Safe Information Flow with Decentralized Labels,” Proceedings of the 1998 IEEE Computer Society Symposium on Security and Privacy, pp. 186–197 (May 1998).

[biblio01entry741] 741. M. Nash and R. Kennett, “Security Policy in a Complex Logistics Procurement,” Proceedings of the 9th Annual Computer Security Applications Conference, pp. 46–53 (Dec. 1993).

[biblio01entry742] 742. M. Nash and K. Poland, “Some Conundrums Concerning Separation of Duty,” Proceedings of the 1990 IEEE Computer Society Symposium on Research in Security and Privacy, pp. 201–207 (May 1990).

[biblio01entry743] 743. National Bureau of Standards, Data Encryption Standard, FIPS PUB 46 (Jan. 1977).

[biblio01entry744] 744. National Bureau of Standards, DES Modes of Operation, FIPS PUB 81 (Dec. 1980).

[biblio01entry745] 745. National Institute of Standards and Technology, Secure Hash Standard, FIPS PUB 180 (May 1993).

[biblio01entry746] 746. National Institute of Standards and Technology, Escrowed Encryption Standard (EES), FIPS PUB 185 (Feb. 1994).

[biblio01entry747] 747. National Institute of Standards and Technology, Digital Signature Standard, FIPS PUB 187 (May 1994).

[biblio01entry748] 748. National Institute of Standards and Technology, Secure Hash Standard, FIPS PUB 180-1 (Apr. 1995).

[biblio01entry749] 749. National Institute of Standards and Technology, “SKIPJACK and KEA Algorithm Specifications,” Version 2.0 (May 1998); available at

[biblio01entry750] 750. National Institute of Standards and Technology, Common Criteria for Information Technology Security Evaluation, Part 1: Introduction and General Model, Version 2.1, CCIMB-99-031 (Aug. 1999).

[biblio01entry751] 751. National Institute of Standards and Technology, Common Criteria for Information Technology Security Evaluation, Part 2: Security Function Requirements, Version 2.1, CCIMB-99-031 (Aug. 1999).

[biblio01entry752] 752. National Institute of Standards and Technology, Common Criteria for Information Technology Security Evaluation, Part 3: Security Assurance Requirements, Version 2.1, CCIMB-99-031 (Aug. 1999).

[biblio01entry753] 753. National Institute of Standards and Technology, Security Requirements for Cryptographic Modules, FIPS PUB 140-2 (May 2001).

[biblio01entry754] 754. National Institute of Standards and Technology, Advanced Encryption Standard (AES), FIPS PUB 197 (Nov. 2001).

[biblio01entry755] 755. National Institute of Standards and Technology, “National Information Assurance Partnership: Common Criteria Evaluation and Validation Scheme Web Site,” (Apr. 2002).

[biblio01entry756] 756. National Institute of Standards and Technology, “Cryptographic Module Validation (CMV) Program Web Site,” (May 2002).

[biblio01entry757] 757. National Institute of Standards and Technology and National Security Agency, Federal Criteria for Information Technology Security, Version 1.0 (<year>1992</year>).

[biblio01entry758] 758. National Security Agency, Cryptolog Interface Programmers Guide for the Fortezza Crypto Card, Revision 1.52, Ft. George Meade, MD (Nov. 1995).

[biblio01entry759] 759. National Security Agency, Fortezza Message Security Protocol Software Interface Control Document, Version 3.01, Ft. George Meade, MD (Nov. 1995).

[biblio01entry760] 760. National Security Agency, Press Release: NSA Releases Fortezza Algorithms, Ft. George Meade, MD (June 1998).

[biblio01entry761] 761. National Security Telecommunications and Information Systems Security Committee, National Information Systems Security (INFOSEC) Glossary, NSTISSI No. 4009 (Sep. 2000).

[biblio01entry762] 762. G. Necula, “Proof-Carrying Code,” Proceedings of the 24th ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, pp. 106–119 (Jan. 1997).

[biblio01entry763] 763. G. Necula and P. Lee, “Safe Kernel Extensions Without Run-Time Checking,” Proceedings of the 2nd Symposium on Operating Systems Design and Implementation, pp. 229–243 (Oct. 1996).

[biblio01entry764] 764. R. Needham and M. Schroeder, “Using Encryption for Authentication in Large Networks of Computers,” Communications of the ACM 21 (12), pp. 993–999 (Dec. 1978).

[biblio01entry765] 765. R. Needham and M. Schroeder, “Authentication Revisited,” Operating Systems Review 21 (1), p. 7 (Jan. 1987).

[biblio01entry766] 766. R. Needham and R. Walker, “The Cambridge CAP Computer and Its Protection System,” Proceedings of the 5th Symposium on Operating System Principles, pp. 1–10 (Nov. 1975).

[biblio01entry767] 767. E. Nemeth, G. Snyder, S. Seebass, and T. Hein, UNIX System Administration Handbook, Prentice-Hall, Upper Saddle River, NJ (<year>2000</year>).

[biblio01entry768] 768. B. Neuman and S. Stubblebine, “A Note on the Use of Timestamps as Nonces,” Operating Systems Review 27 (2), pp. 10–14 (Apr. 1993).

[biblio01entry769] 769. P. Neumann, “Computer Security Evaluation,” 1978 National Computer Conference, AFIPS Conference Proceedings 47, pp. 1087–1095 (June 1978).

[biblio01entry770] 770. P. Neumann, R. Feiertag, L. Robinson, and K. Levitt, “Software Development and Proofs of Multi-Level Security,” Proceedings of the 2nd International Conference on Software Engineering, pp. 421–428 (Oct. 1976).

[biblio01entry771] 771. P. Neumann, “Rainbows and Arrows: How the Security Criteria Address Computer Misuse,” Proceedings of the 13th National Computer Security Conference, pp. 414–422 (Oct. 1990).

[biblio01entry772] 772. P. Neumann, Computer-Related Risks, Addison-Wesley, Reading, MA (<year>1995</year>).

[biblio01entry773] 773. P. Neumann, L. Robinson, K. Levitt, R. Boyer, and A. Saxena, “A Provably Secure Operating System: The System, Its Applications, and Proofs,” Technical Report, SRI International, Menlo Park, CA (June 1975).

[biblio01entry774] 774. J. Newman, The World of Mathematics: A Small Library of the Literature of Mathematics from A'h-mosé the Scribe to Albert Einstein, Simon and Schuster, New York, NY (<year>1956</year>).

[biblio01entry775] 775. J. Newman and S. Wander, “The Knowledge Path to Mission Success: Overview of the NASA PBMA-KMS,” Proceedings of the 2002 Annual Reliability and Maintainability Symposium, pp. 601–606 (Jan. 2002).

[biblio01entry776] 776. J. Nieh and O. Leonard, “Examining VMware,” Dr. Dobb's Journal 25 (8), pp. 70–76 (Aug. 2000).

[biblio01entry777] 777. E. Nikolaropoulos, “Testing Safety-Critical Software,” Hewlett-Packard Journal 48 (3), pp. 89–94 (June 1997).

[biblio01entry778] 778. L. Nizer, The Jury Returns, Doubleday, Garden City, NY (<year>1966</year>).

[biblio01entry779] 779. S. Northcutt, Computer Security Incident Handling: Step by Step, Version 1.5, The SANS Institute, Bethesda, MD (May 1998).

[biblio01entry780] 780. S. Northcutt, Network Intrusion Detection: An Analyst's Handbook, 2nd Edition, New Riders Publishing, Indianapolis, IN (<year>2000</year>).

[biblio01entry781] 781. L. Notargiacomo, B. Blaustein, and C. McCollum, “Merging Models: Integrity, Dynamic Separation of Duty, and Trusted Data Management,” Journal of Computer Security 3 (2, 3), pp. 207–230 (1994/1995).

[biblio01entry782] 782. M. Nyanchama and S. Osborn, “Role-Based Security, Object Oriented Databases and Separation of Duty,” SIGMOD Record 22 (4), pp. 45–51 (Dec. 1993).

[biblio01entry783] 783. C. Oakes, “DVD Hackers Hit with Lawsuit,” Wired News (Dec. 28, 1999); available at,1367,33303,00.html.

[biblio01entry784] 784. D. O'Brien, “Recognizing and Recovering from Rootkit Attacks,” SysAdmin 5 (11), pp. 8–20 (Nov. 1996).

[biblio01entry785] 785. R. O'Brien and C. Rogers, “Developing Applications on LOCK,” Proceedings of the 14th National Computer Security Conference, pp. 147–156 (Oct. 1991).

[biblio01entry786] 786. T. Okamoto and K. Ohta, “Universal Electronic Cash,” Advances in Cryptology—Proceedings of CRYPTO '91, pp. 324–337 (Aug. 1992).

[biblio01entry787] 787. R. Oppliger, “Security at the Internet Layer,” IEEE Computer 31 (9), pp. 43–47 (Sep. 1998).

[biblio01entry788] 788. E. Organick, The MULTICS System: An Examination of Its Structure, The MIT Press, Cambridge, MA (<year>1972</year>).

[biblio01entry789] 789. E. Organick, Computer System Organization: The B5700/6700 Series, Academic Press, New York, NY (<year>1973</year>).

[biblio01entry790] 790. H. Orman, The OAKLEY Key Determination Protocol, RFC 2412 (Nov. 1998).

[biblio01entry791] 791. D. Otway and O. Rees, “Efficient and Timely Mutual Authentication,” Operating Systems Review 21 (1), pp. 8–10 (Jan. 1987).

[biblio01entry792] 792. S. Owre, J. Rushby, and N. Shankar, “PVS: A Prototype Verification System,” Proceedings of the 11th International Conference on Automated Deduction, pp. 748–752 (June 1992).

[biblio01entry793] 793. J. Page, “An Assured Pipeline Integrity Scheme for Virus Protection,” Proceedings of the 12th National Computer Security Conference, pp. 369–377 (Oct. 1989).

[biblio01entry794] 794. R. Pandey and B. Hashii, “Providing Fine-Grained Access Control for Java Programs,” Proceedings of the 13th European Conference on Object-Oriented Programming, pp. 449–473 (June 1999).

[biblio01entry795] 795. J. Park, B. Montrose, and J. Froscher, “Tools for Information Security Assurance Arguments,” Proceedings of the DARPA Information Survivability Conference and Exposition II, pp. 287–296 (June 2001).

[biblio01entry796] 796. J. Park and R. Sandhu, “Smart Certificates: Extending X.509 for Secure Attribute Services on the Web,” Proceedings of the 22nd National Information Systems Security Conference, pp. 337–348 (Oct. 1999).

[biblio01entry797] 797. S. Park and K. Miller, “Random Number Generators: Good Ones Are Hard to Find,” Communications of the ACM 31 (10), pp. 1192–1201 (Oct. 1988).

[biblio01entry798] 798. D. Parker, “Cease and DeCSS: DVD's Encryption Code Cracked,” eMedia Industry News (Nov. 4, 1999); available at

[biblio01entry799] 799. D. Parker, Crime by Computer, Macmillan Publishing Co., New York, NY (<year>1978</year>).

[biblio01entry800] 800. R. Perlman, “An Overview of PKI Trust Models,” IEEE Network 13 (6), pp. 38–43 (Nov. 1999).

[biblio01entry801] 801. B. Perlmutter and J. Zarkower, Virtual Private Networking, Prentice-Hall, Upper Saddle River, NJ (<year>2000</year>).

[biblio01entry802] 802. G. Pernul, “Canonical Security Modeling for Federated Databases,” Proceedings of the IFIP WG2.6 Database Semantics Conference, pp. 207–222 (Nov. 1992).

[biblio01entry803] 803. J. Perry and J. Carney, “Human Face Recognition Using a Multilayer Perceptron,” International Conference on Neural Networks 2, p. 413 (1990); cited in “Biometrics for Automated Identity Verification” [726].

[biblio01entry804] 804. I. Peterson, Fatal Defects: Chasing Killer Computer Bugs, Vintage Books, New York, NY 10022 (<year>1996</year>).

[biblio01entry805] 805. J. Peterson and A. Silberschatz, Operating Systems Concepts (6th Edition), John Wiley and Sons, New York, NY (<year>2002</year>).

[biblio01entry806] 806. C. Pfleeger, “Comparison of Trusted Systems Evaluation Criteria,” Proceedings of the 5th Annual Conference on Computer Assurance, Systems Integrity, Software Safety and Process Security, pp. 135–143 (June 1990).

[biblio01entry807] 807. S. Pfleeger, Software Engineering: The Production of Quality Software, 2nd Edition, Macmillan Publishing Co., New York, NY (<year>1991</year>).

[biblio01entry808] 808. J. Picciotto, “The Design of an Effective Auditing Subsystem,” Proceedings of the 1987 IEEE Symposium on Security and Privacy, pp. 13–22 (<year>1987</year>).

[biblio01entry809] 809. W. Polk, “Approximating Clark-Wilson 'Access Triples' with Basic UNIX Controls,” Proceedings of the 4th USENIX UNIX Security Symposium, pp. 145–154 (Oct. 1993).

[biblio01entry810] 810. G. Popek and R. Goldberg, “Formal Requirements for Virtualizable Third Generation Architectures,” Communications of the ACM 17 (7), pp. 412–421 (July 1974).

[biblio01entry811] 811. G. Popek and B. Walker, The LOCUS Distributed System Architecture, The MIT Press, Cambridge, MA (<year>1985</year>).

[biblio01entry812] 812. P. Porras and R. Kemmerer, “Covert Flow Trees: A Technique for Identifying and Analyzing Covert Storage Channels,” Proceedings of the 1991 IEEE Symposium on Security and Privacy, pp. 36–51 (May 1991).

[biblio01entry813] 813. POSIX, Standard for Information Technology Portable Operating System Interface (POSIX) Part I: System Application Program Interface (API), Report 1003.1e (Apr. 1994).

[biblio01entry814] 814. J. Postel, Simple Mail Transfer Protocol, RFC 821 (Aug. 1982).

[biblio01entry815] 815. J. Postel and J. Reynolds, File Transfer Protocol, RFC 959 (Oct. 1985).

[biblio01entry816] 816. E. Powanda and J. Genovese, “Configuring a Trusted System Using the TNI,” Proceedings of the 4th Aerospace Computer Security Applications Conference, pp. 256–261 (Dec. 1988).

[biblio01entry817] 817. M. Pozzo and T. Gray, “A Model for the Containment of Computer Viruses,” Proceedings of the AIAA/ASIS/DODCI 2nd Aerospace Computer Security Conference, pp. 11–18 (Dec. 1986).

[biblio01entry818] 818. M. Pozzo and T. Gray, “An Approach to Containing Computer Viruses,” Computers and Security 6 (4), pp. 321–331 (Aug. 1987).

[biblio01entry819] 819. D. Price, “Pentium FDIV Flaw—Lessons Learned,” IEEE Micro 15 (2), pp. 86–88 (Apr. 1995).

[biblio01entry820] 820. N. Proctor, “The Restricted Access Processor: An Example of Formal Verification,” Proceedings of the 1985 IEEE Symposium on Security and Privacy, pp. 49–53 (Apr. 1985).

[biblio01entry821] 821. P. Proctor, The Practical Intrusion Detection Handbook, Prentice-Hall, Upper Saddle River, NJ (<year>2001</year>).

[biblio01entry822] 822. T. Ptacek and T. Newsham, Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection, Technical Report, Secure Networks, Inc., Calgary, Alberta, Canada (Jan. 1998).

[biblio01entry823] 823. N. Puketza, M. Chung, R. Olsson, and B. Mukherjee, “A Software Platform for Testing Intrusion Detection Systems,” IEEE Software 14 (5), pp. 43–51 (Sep. 1997).

[biblio01entry824] 824. L. Quarantiello, Cyber Crime: How to Protect Yourself from Computer Criminals, Tiare Publications, Lake George, WI (<year>1996</year>).

[biblio01entry825] 825. M. Rabin, “Probabilistic Algorithms for Primality Testing,” Journal of Number Theory 12 (1), pp. 128–138 (Feb. 1980).

[biblio01entry826] 826. S. Rajunas, N. Hardy, A. Bomberger, W. Frantz, and C. Landau, “Security in KeyKOS,” Proceedings of the 1986 IEEE Symposium on Security and Privacy, pp. 78–85 (Apr. 1986).

[biblio01entry827] 827. B. Ramsey,, Jr., “Practical Steps Toward Providing a Cost-Effective Security Architecture Based on the Common Criteria,” Proceedings of the 21st National Information Systems Security Conference, pp. 30–41 (Oct. 1998).

[biblio01entry828] 828. The RAND Corporation, A Million Random Digits with 100,000 Normal Deviates, Free Press Publishers, Glencoe, IL (<year>1955</year>).

[biblio01entry829] 829. M. Ranum and F. Avolio, “A Toolkit and Methods for Internet Firewalls,” Proceedings of the Summer 1994 USENIX Conference, pp. 37–44 (June 1994).

[biblio01entry830] 830. M. Ranum, K. Landfield, M. Stolarchuk, M. Sienkiewicz, A. Lambeth, and E. Wall, “Implementing a Generalized Tool for Network Monitoring,” Proceedings of the 11th Systems Administration Conference (LISA 1997), pp. 26–31 (Dec. 1997).

[biblio01entry831] 831. K. Rao, “Security Audit for Embedded Avionics Systems,” Proceedings of the 5th Annual Computer Security Applications Conference, pp. 78–84 (Dec. 1989).

[biblio01entry832] 832. J. Ray and W. Ray, Mac OS X Unleashed, SAMS Publishing, Indianapolis, IN (<year>2001</year>).

[biblio01entry833] 833. D. Redell and R. Fabry, “Selective Revocation and Capabilities,” Proceedings of the International Workshop on Protection in Operating Systems, pp. 197–209 (Aug. 1974).

[biblio01entry834] 834. J. Reeds, “Cracking a Random Number Generator,” Cryptologia 1 (1), pp. 20–26 (Jan. 1977); cited in Applied Cryptography [888].

[biblio01entry835] 835. B. Reid, “Reflections on Some Recent Widespread Computer Break-Ins,” Communications of the ACM 30 (2), pp. 103–105 (Feb. 1987).

[biblio01entry836] 836. R. Reitman, “A Mechanism for Information Control in Parallel Programs,” Proceedings of the 7th Symposium on Operating Systems Principles, pp. 55–62 (Dec. 1979).

[biblio01entry837] 837. Y. Rekhter, B. Moscowitz, D. Karrenberg, G. de Groot, and E. Lear, Address Allocation for Private Internets, RFC 1918 (Feb. 1996).

[biblio01entry838] 838. T. Riechmann and F. Hauck, “Meta Objects for Access Control: Extending Capability-Based Security,” Proceedings of the 1997 New Security Paradigms Workshop, pp. 17–22 (Sep. 1997).

[biblio01entry839] 839. D. Ritchie, “Joy of Reproduction,” net.lang.c (Nov. 4, 1982).

[biblio01entry840] 840. D. Ritchie, “On the Security of UNIX,” UNIX System Manager's Manual, pp. SM17: 1–3 (<year>1979</year>).

[biblio01entry841] 841. R. Rivest, The MD4 Message Digest Algorithm, RFC 1320 (Apr. 1992).

[biblio01entry842] 842. R. Rivest, The MD5 Message Digest Algorithm, RFC 1321 (Apr. 1992).

[biblio01entry843] 843. R. Rivest, M. Hellman, J. Anderson, and J. Lyons, “Responses to NIST's Proposal,” Communications of the ACM 35 (7), pp. 41–54 (July 1992).

[biblio01entry844] 844. R. Rivest, A. Shamir, and L. Adleman, “A Method for Obtaining Digital Signatures and Public-Key Cryptosystems,” Communications of the ACM 21 (2), pp. 120–126 (Feb. 1978).

[biblio01entry845] 845. J. Rochlis and M. Eichin, “The Internet Worm, with Microscope and Tweezers: the Worm from MIT's Perspective,” Communications of the ACM 32 (6), pp. 689–698 (June 1989).

[biblio01entry846] 846. G. Rodney, “Assuring Safety and Mission Success for Space Station Freedom,” Proceedings of the 1990 International Symposium on Reliability and Maintainability, pp. 7–12 (June 1990).

[biblio01entry847] 847. E. Rodríguez and J. Piquer, “The Persistent Hacker: An Intruder Attacks a New Internet Host,” Proceedings of the 4th USENIX UNIX Security Symposium, pp. 131–138 (Oct. 1993).

[biblio01entry848] 848. A. Roscoe, “Modelling and Verifying Key-Exchange Protocols Using CSP and FDR,” Proceedings of the 8th IEEE Computer Security Foundations Workshop, pp. 98–107 (June 1995).

[biblio01entry849] 849. A. Roscoe, J. Woodcock, and L. Wulf, “Non-Interference Through Determinism,” Journal of Computer Security 4 (1), pp. 27–53 (1996).

[biblio01entry850] 850. D. Rosenthal and F. Fung, “A Test for Non-Disclosure in Security Level Transitions,” Proceedings of the 1999 IEEE Symposium on Security and Privacy, pp. 1–10 (May 1999).

[biblio01entry851] 851. W. Royce, “Managing the Development of Large Software Systems,” 1970 WESTCON Technical Papers 14, p. 8 (Aug. 1970).

[biblio01entry852] 852. M. Rubia, J. Cruellas, and M. Medina, “The DEDICA Project: The Solution to the Interoperability Problems Between the X.509 and EDIFACT Public Key Infrastructures,” Proceedings of Secure Networking—CQRE [Secure] '99 International Exhibition and Congress, pp. 242–250 (Nov. 1999).

[biblio01entry853] 853. L. Romano, A. Mazzeo, and N. Mazzocca, “SECURE: A Simulation Tool for PKI Design,” Proceedings of Secure Networking—CQRE [Secure] '99 International Exhibition and Congress, pp. 17–29 (Nov. 1999).

[biblio01entry854] 854. A. Rubin, “Independent One-Time Passwords,” Computing Systems 9 (1), pp. 15–27 (Winter 1996).

[biblio01entry855] 855. A. Rubin and M. Ranum, Web Security Sourcebook, John Wiley and Sons, New York, NY (<year>1997</year>).

[biblio01entry856] 856. C. Rubin, “UNIX System V with B2 Security,” Proceedings of the 13th National Computer Security Conference, pp. 1–9 (Oct. 1990).

[biblio01entry857] 857. R. Rueppel, “Stream Ciphers,” in Contemporary Cryptology: The Science of Information Integrity [927], pp. 65–134.

[biblio01entry858] 858. J. Rushby, “Noninterference, Transitivity, and Channel-Control Security Policies,” Technical Report CSL-92-02, Computer Science Laboratory, SRI International, Menlo Park, CA (Dec. 1992).

[biblio01entry859] 859. C. Rutstein, Windows NT Security: A Practical Guide to Securing Windows NT Servers and Workstations, McGraw-Hill, New York, NY (<year>1997</year>).

[biblio01entry860] 860. D. Safford, D. Schales, and D. Hess, “The TAMU Security Package: An Ongoing Response to Internet Intruders in an Academic Environment,” Proceedings of the 4th USENIX UNIX Security Symposium, pp. 91–118 (Oct. 1993).

[biblio01entry861] 861. M. St. Johns, Identification Protocol, RFC 1413 (Feb. 1993).

[biblio01entry862] 862. J. Sajaniemi, “Modeling Spreadsheet Audit: A Rigorous Approach to Automatic Visualization,” Journal of Visual Languages and Computing 11 (1), pp. 49–82 (Feb. 2000).

[biblio01entry863] 863. R. Saltman, “Accuracy, Integrity and Security in Computerized Vote-Tallying,” Communications of the ACM 31 (10), pp. 1184–1191 (Oct. 1988).

[biblio01entry864] 864. J. Saltzer, “Protection and the Control of Information Sharing in Multics,” Communications of the ACM 17 (7), pp. 388–402 (July 1974).

[biblio01entry865] 865. J. Saltzer and M. Schroeder, “The Protection of Information in Computer Systems,” Proceedings of the IEEE 63 (9), pp. 1278–1308 (Sep. 1975).

[biblio01entry866] 866. J. Saltzer, On the Naming and Binding of Network Destinations, RFC 1498 (Aug. 1993).

[biblio01entry867] 867. A. Samal and P. Iyengar, “Automatic Recognition and Analysis of Human Faces and Facial Expressions: A Survey,” Pattern Recognition 25, pp. 65–77 (1992); cited in “Biometrics for Automatic Identity Verification” [726].

[biblio01entry868] 868. V. Samar, “Unified Login with Pluggable Authentication Modules (PAM),” Proceedings of the 3rd ACM Conference on Computer and Communications Security, pp. 1–10 (Mar. 1996).

[biblio01entry869] 869. R. Sandhu, “Analysis of Acyclic Attenuating Systems for the SSR Protection Model,” Proceedings of the 1985 IEEE Symposium on Security and Privacy, pp. 197–206 (Apr. 1985).

[biblio01entry870] 870. R. Sandhu, “The Schematic Protection Model: Its Definition and Analysis for Acyclic Attenuating Schemes,” Journal of the ACM 35 (2), pp. 404–432 (Apr. 1988).

[biblio01entry871] 871. R. Sandhu, “The Demand Operation in the Schematic Protection Model,” Information Processing Letters 32 (4), pp. 213–219 (Apr. 1989).

[biblio01entry872] 872. R. Sandhu, “Expressive Power of the Schematic Protection Model,” Journal of Computer Security 1 (1), pp. 59–98 (1992).

[biblio01entry873] 873. R. Sandhu, “Transformation of Access Rights,” Proceedings of the 1989 IEEE Symposium on Security and Privacy, pp. 259–268 (May 1989).

[biblio01entry874] 874. R. Sandhu, “Non-Monotonic Transformation of Access Rights,” Proceedings of the 1992 IEEE Symposium on Research in Security and Privacy, pp. 148–161 (Apr. 1992).

[biblio01entry875] 875. R. Sandhu, “The Typed Access Matrix Model,” Proceedings of the 1992 IEEE Symposium on Security and Privacy, pp. 122–136 (Apr. 1992).

[biblio01entry876] 876. R. Sandhu and G.-J. Ahn, “Decentralized Group Hierarchies in UNIX: An Experiment and Lessons Learned,” Proceedings of the 21st National Information Systems Security Conference, pp. 486–502 (Oct. 1998).

[biblio01entry877] 877. R. Sandhu and S. Ganta, “On Testing for the Absence of Rights in Access Control Models,” Proceedings of the Computer Security Foundations Workshop IV, pp. 109–118 (June 1993).

[biblio01entry878] 878. R. Sandhu and S. Ganta, “On the Minimality of Testing for Rights in Transformation Models,” Proceedings of the 1994 IEEE Symposium on Research in Security and Privacy, pp. 230–241 (Apr. 1994).

[biblio01entry879] 879. P. Sands, “Building an FTP Guard,” Proceedings of the 21st National Information Systems Security Conference, pp. 432–442 (Oct. 1998).

[biblio01entry880] 880. S. Savage, D. Wetherall, A. Karlin, and T. Anderson, “Practical Network Support for IP Traceback,” Computer Communication Review 30 (4) pp. 295–306 (Aug. 2000).

[biblio01entry881] 881. O. Saydjari, J. Beckman, and J. Leaman, “Locking Computers Securely,” Proceedings of the 10th National Computer Security Conference, pp. 129–141 (Sep. 1987).

[biblio01entry882] 882. O. Saydjari, J. Beckman, and J. Leaman, “LOCK Trek: Navigating Uncharted Space,” Proceedings of the 1989 Symposium on Security and Privacy, pp. 167–175 (May 1989).

[biblio01entry883] 883. M. Schaefer, B. Gold, R. Linde, and J. Scheid, “Program Confinement in KVM/370,” Proceedings of the 1977 ACM Annual Conference, pp. 404–410 (Oct. 1977).

[biblio01entry884] 884. P. Schafer, “Is Centralized System Administration the Answer?” Proceedings of the 6th Systems Administration Conference (LISA 1992), pp. 55–61 (Oct. 1992).

[biblio01entry885] 885. R. Shell, T. Tao, and M. Heckman, “Designing the GEMSOS Security Kernel for Security and Performance,” Proceedings of the 8th National Computer Security Conference, pp. 108–119 (Oct. 1985).

[biblio01entry886] 886. K. Scheurer, “The Clipper Chip: Cryptography, Technology and the Constitution—the Government's Answer to Encryption 'Chips' Away at Constitutional Rights,” Rutgers Computer and Technology Law Journal 21 (1), pp. 263–292 (1995).

[biblio01entry887] 887. D. Schnackenberg, K. Djahandari, and D. Sterne, “Infrastructure for Intrusion Detection and Response,” Proceedings of the DARPA Information Survivability Conference and Exposition 2, pp. 3–11 (Jan. 2000).

[biblio01entry888] 888. B. Schneier, Applied Cryptography, 2nd Edition, John Wiley and Sons, New York, NY (<year>1996</year>).

[biblio01entry889] 889. J. Schoch and J. Hupp, “The 'Worm' Programs—Early Experiences with a Distributed Computation,” Communications of the ACM 25 (3), pp. 172–180 (Mar. 1982).

[biblio01entry890] 890. T. Schoriak, “SSL/TLS Protocol Enablement for Key Recovery,” Computers and Security 19 (1), pp. 100–104 (Jan./Feb. 2000).

[biblio01entry891] 891. K. Schroeder and J. Ledger, Life and Death on the Internet, Supple Publishing, Menosha, WI (<year>1998</year>).

[biblio01entry892] 892. C. Schuba, “Addressing Weaknesses in the Domain Name System Protocol,” Master's thesis, Department of Computer Sciences, Purdue University, West Lafayette, IN (Aug. 1993).

[biblio01entry893] 893. C. Schuba, I. Krsul, M. Kuhn, E. Spafford, A. Sundaram, and D. Zamboni, “Analysis of a Denial of Service Attack on TCP,” Proceedings of the 1997 IEEE Symposium on Security and Privacy, pp. 208–223 (May 1997).

[biblio01entry894] 894. C. Schuba and E. Spafford, “A Reference Model for Firewall Technology,” Proceedings of the 13th Annual Computer Security Applications Conference, pp. 133–145 (Dec. 1997).

[biblio01entry895] 895. R. Scott, “Wide Open Encryption Design Offers Flexible Implementations,” Cryptologia 9 (1), pp. 75–90 (Jan. 1985).

[biblio01entry896] 896. C. Scott, P. Wolfe, and M. Erwin, Virtual Private Networks, O'Reilly & Associates, Sebastopol, CA (<year>1998</year>).

[biblio01entry897] 897. J. Seberry and J. Pieprzyk, Cryptography: An Introduction to Computer Security, Prentice-Hall, Englewood Cliffs, NJ (<year>1989</year>).

[biblio01entry898] 898. SSE-CMM Support Organization, “Secure Software Engineering Capability Maturity Model Web Page,” (2001).

[biblio01entry899] 899. K. Seiden and J. Melanson, “The Auditing Facility for a VMM Security Kernel,” Proceedings of the 1990 IEEE Symposium on Research in Security and Privacy, pp. 262–277 (<year>1990</year>).

[biblio01entry900] 900. D. Seeley, “Password Cracking: A Game of Wits,” Communications of the ACM 32 (6), pp. 700–703 (June 1989).

[biblio01entry901] 901. D. Seeley, “A Tour of the Worm,” Proceedings of the 1989 Winter USENIX Conference, pp. 287–304 (Jan. 1989).

[biblio01entry902] 902. R. Sekar, T. Bowen, and M. Segal, “On Preventing Intrusions by Process Behavior Monitoring,” Proceedings of the Workshop on Intrusion Detection and Network Monitoring, pp. 29–40 (Apr. 1999).

[biblio01entry903] 903. G. Serrao, “Rating Network Components,” Proceedings of the 18th National Information Systems Security Conference, pp. 344–355 (Oct. 1995).

[biblio01entry904] 904. SET Secure Electronic Transaction LLC, SET Secure Electronic Transaction Specification, Book 1: Business Description, Version 1.0 (May 1997).

[biblio01entry905] 905. SET Secure Electronic Transaction LLC, SET Secure Electronic Transaction Specification, Book 2: Programmers' Guide, Version 1.0 (May 1997).

[biblio01entry906] 906. SET Secure Electronic Transaction LLC, SET Secure Electronic Transaction Specification, Book 3: Formal Protocol Definition, Version 1.0 (May 1997).

[biblio01entry907] 907. A. Shamir, “How to Share a Secret,” Communication of the ACM 22, pp. 612–613 (1979).

[biblio01entry908] 908. C. E. Shannon, “A Mathematical Theory of Communication,” Bell Systems Technical Journal 27, pp. 379–423, 623–656 (Oct. 1948).

[biblio01entry909] 909. C. E. Shannon, “Communication Theory of Secrecy Systems,” Bell Systems Technical Journal 28, pp. 656–715 (Oct. 1949).

[biblio01entry910] 910. J. Shapiro and N. Hardy, “EROS: A Principle-Driven Operating System from the Ground Up,” IEEE Software 19 (1), pp. 26–33 (Jan./Feb. 2002).

[biblio01entry911] 911. J. Shapiro, J. Smith, and D. Farber, “EROS: A Fast Capability System,” Proceedings of the 17th ACM Symposium on Operating Systems Principles, pp. 170–185 (Dec. 1999).

[biblio01entry912] 912. J. Shapiro and S. Weber, “Verifying the EROS Confinement Mechanism,” Proceedings of the 2000 IEEE Symposium on Security and Privacy, pp. 166–176 (May 2000).

[biblio01entry913] 913. S.-P. Shieh and V. Gligor, “Detecting Illicit Leakage of Information in Operating Systems,” Journal of Computer Security 4 (2, 3), pp. 123–148 (Dec. 1996).

[biblio01entry914] 914. T. Shimomura and J. Markoff, Takedown: The Pursuit and Capture of Kevin Mitnick, America's Most Wanted Computer Outlaw—By the Man Who Did It, Hyperion Books, New York, NY (<year>1996</year>).

[biblio01entry915] 915. A. Shimizu and S. Miyaguchi, “Fast Data Encipherment Algorithm FEAL,” Advances in Cryptology—Proceedings of EUROCRYPT '87, pp. 267–278 (<year>1987</year>).

[biblio01entry916] 916. R. Shirey, Security Architecture for Internet Protocols: A Guide for Protocol Designs and Standards, Internet Draft: draft-irtf-psrg-secarch-sect1-00.txt (Nov. 1994).

[biblio01entry917] 917. B. Shneiderman, Designing the User Interface: Strategies for Effective Human-Computer-Interaction, 3rd Edition, Addison Wesley Longman, Reading, MA (<year>1998</year>).

[biblio01entry918] 918. J. Shoch, “Inter-Network Naming, Addressing, and Routing,” Proceedings of COMPCON '78, pp. 72–79 (<year>1978</year>).

[biblio01entry919] 919. R. Shore, “IGOR: The Intelligence Guard for ONI Replication,” Proceedings of the 19th National Computer Security Conference, pp. 607–619 (Oct. 1996).

[biblio01entry920] 920. W. Sibert, “Auditing in a Distributed System: Secure SunOS Audit Trails,” Proceedings of the 11th National Computer Security Conference, pp. 81–91 (Oct. 1988).

[biblio01entry921] 921. D. Sidhu and M. Gasser, “A Multilevel Secure Local Area Network,” Proceedings of the 1982 IEEE Symposium on Privacy and Security, pp. 137–143 (Apr. 1982).

[biblio01entry922] 922. Silicon Graphics, Inc., sendmail 8.9.3 for IRIX 6.5.7, SGI Security Advisory 20000302-01-P3865 (Mar. 2000).

[biblio01entry923] 923. G. Simmons, “Forward Search as a Cryptanalytic Tool Against a Public Key Privacy Channel,” Proceedings of the 1982 IEEE Symposium on Security and Privacy, pp. 117–128 (Apr. 1982).

[biblio01entry924] 924. G. Simmons, “How to (Really) Share a Secret,” Advances in Cryptology—Proceedings of CRYPTO '88, pp. 390–448 (Aug. 1988).

[biblio01entry925] 925. G. Simmons, “Prepositioned Secret Sharing Schemes and/or Shared Control Schemes,” Advances in Cryptology—Proceedings of EUROCRYPT '89, pp. 436–467 (Apr. 1989).

[biblio01entry926] 926. G. Simmons, “Geometric Shared Secret and/or Shared Control Schemes,” Advances in Cryptology—Proceedings of CRYPTO '90, pp. 216–241 (<year>1990</year>).

[biblio01entry927] 927. G. Simmons, Contemporary Cryptology: The Science of Information Integrity, IEEE Press, Piscataway, NJ (<year>1992</year>).

[biblio01entry928] 928. R. Simon and M. Zurko, “Separation of Duty in Role-Based Environments,” Proceedings of the Computer Security Foundations Workshop, MITRE Technical Report M88-37, MITRE Corporation, Bedford, MA, pp. 183–194 (June 1997).

[biblio01entry929] 929. A. Sinkov, Elementary Cryptanalysis: A Mathematical Approach, Random House, New York, NY (<year>1968</year>).

[biblio01entry930] 930. B. Skingle, S. Valentine, M. Grisoni, A. McLachlan, and J. Fenn, “Trailer—an Inspection and Audit Tool for System-Usage Logs,” Proceedings of the 2nd European Conference, pp. 151–161 (June 1988).

[biblio01entry931] 931. M. Slatalla and J. Quittner, Masters of Deception: The Gang That Ruled Cyberspace, Harperperennial Library, New York, NY (<year>1996</year>).

[biblio01entry932] 932. M. Sloman, “Policy Driven Management for Distributed Systems,” Journal of Network and Systems Management 2 (4), pp. 333–360 (Dec. 1994).

[biblio01entry933] 933. S. Smaha, “Haystack: An Intrusion Detection System,” Proceedings of the 4th Aerospace Computer Security Applications Conference, pp. 37–44 (Dec. 1988).

[biblio01entry934] 934. C. Small, “Misfit: A Tool for Constructing Safe Extensible C++ Systems,” Proceedings of the 3rd USENIX Conference on Object-Oriented Technologies, pp. 38–48 (June 1997).

[biblio01entry935] 935. G. Smith and D. Volpano, “Secure Information Flow in a Multi-Threaded Imperative Language,” Proceedings of the 25th ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, pp. 355–364 (Jan. 1998).

[biblio01entry936] 936. K. Smith and M. Winslett, “Entity Modelling in the MLS Relational Model,” Proceedings of the 18th International Conference Very Large Data Bases, pp. 199–210 (Aug. 1992).

[biblio01entry937] 937. R. Smith, “Constructing a High Assurance Mail Guard,” Proceedings of the 17th National Computer Security Conference, pp. 247–253 (Oct. 1994).

[biblio01entry938] 938. R. Smith, “Cost Profile of a Highly Assured, Secure Operating System,” ACM Transactions on Information and Systems Security 4 (1), pp. 72–101 (Feb. 2001).

[biblio01entry939] 939. T. Smith, “User Definable Domains as a Mechanism for Implementing the Least Privilege Principle,” Proceedings of the 9th National Computer Security Conference, pp. 143–148 (Sep. 1986).

[biblio01entry940] 940. S. Snapp, J. Brentano, G. Dias, T. Goan, L. Heberlein, C. Ho, K. Levitt, B. Mukherjee, S. Smaha, T. Grance, D. Teal, and D. Mansur, “DIDS (Distributed Intrusion Detection System): Motivation, Architecture, and an Early Prototype,” Proceedings of the 14th National Computer Security Conference, pp. 167–176 (Oct. 1991).

[biblio01entry941] 941. B. Snow, “The Future Is Not Assured—But It Should Be,” Proceedings of the 1999 IEEE Symposium on Security and Privacy, pp. 240–241 (May 1999).

[biblio01entry942] 942. L. Snyder, “On the Synthesis and Analysis of Protection Systems,” Proceedings of the Sixth Symposium on Operating Systems Principles, pp. 141–150 (Nov. 1977).

[biblio01entry943] 943. L. Snyder, “Formal Models of Capability-Based Protection Systems,” IEEE Transactions on Computers 30 (3), pp. 172–181 (Mar. 1981).

[biblio01entry944] 944. L. Snyder, “Theft and Conspiracy in the Take-Grant Protection Model,” Journal of Computer and System Science 23 (3), pp. 333–347 (Dec. 1981).

[biblio01entry945] 945. M. Sobirey, S. Fischer-Hübner, and K. Rannenberg, “Pseudonymous Audit for Privacy Enhanced Intrusion Detection,” Information Security in Research and Business—Proceedings of the IFIP TC11 13th International Conference on Information Security, pp. 151–163 (May 1997).

[biblio01entry946] 946. S. von Solms and D. Naccache, “On Blind Signatures and Perfect Crimes,” Computers and Security 11 (6), pp. 581–583 (Oct. 1992).

[biblio01entry947] 947. D. Solomon and M. Russinovich, Inside Microsoft Windows 2000, 3rd Edition, Microsoft Press, Redmond, WA (<year>2000</year>).

[biblio01entry948] 948. A. Somayaji and S. Forrest, “Automated Response Using System-Call Delays,” Proceedings of the 9th USENIX Security Symposium, pp. 185–197 (Aug. 2000).

[biblio01entry949] 949. A. Somayaji, S. Hofmeyr, and S. Forrest, “Principles of a Computer Immune System,” Proceedings of the 1997 New Security Paradigms Workshop, pp. 75–82 (Sep. 1997).

[biblio01entry950] 950. I. Sommerville, Software Engineering, 6th Edition, Addison-Wesley, Boston, MA (<year>2001</year>).

[biblio01entry951] 951. S. Son, C. Chaney, and N. Thomlinson, “Partial Security Policies to Support Timeliness in Secure Real-Time Databases,” Proceedings of the 1998 IEEE Symposium on Security and Privacy, pp. 136–147 (May 1998).

[biblio01entry952] 952. E. Spafford, “The Internet Worm Program: An Analysis,” Computer Communications Review 19 (1), pp. 17–57 (Jan. 1989).

[biblio01entry953] 953. E. Spafford, “Crisis and Aftermath,” Communications of the ACM 32 (6), pp. 678–687 (June 1989).

[biblio01entry954] 954. E. Spafford, “Observing Reusable Password Choices,” Proceedings of the 3rd UNIX Security Symposium, pp. 299–312 (Sep. 1992).

[biblio01entry955] 955. E. Spafford, “OPUS: Preventing Weak Password Choices,” Computers and Security 11 (3), pp. 273–278 (June 1992).

[biblio01entry956] 956. E. Spafford, K. Heaphy, and D. Ferbrache, Computer Viruses: Dealing with Electronic Vandalism and Programmed Threats, ADAPSO, Arlington, VA (<year>1989</year>).

[biblio01entry957] 957. E. Spafford and S. Weeber, “Software Forensics: Can We Track Code to Its Authors?” Proceedings of the 15th National Information Systems Security Conference, pp. 641–650 (Oct. 1992).

[biblio01entry958] 958. E. Spafford and D. Zamboni, “Intrusion Detection Using Autonomous Agents,” Computer Networks 34 (4), pp. 547–570 (Oct. 2000).

[biblio01entry959] 959. P. Srisuresh and K. Egevang, Traditional IP Network Address Translator (Traditional NAT), RFC 3022 (Jan. 2001).

[biblio01entry960] 960. W. Stallings, Network Security Essentials: Applications and Standards, Prentice-Hall, Upper Saddle River, NJ (<year>2000</year>).

[biblio01entry961] 961. R. Stallman, “The Right to Read,” Communications of the ACM 40 (2), pp. 85–87 (Dec. 1997).

[biblio01entry962] 962. R. Stallman and R. Pesch, “Debugging with GDB: The GNU Source-Level Debugger,”, New York, NY (Dec. 2000).

[biblio01entry963] 963. S. Staniford-Chen, S. Cheung, R. Crawford, M. Dilger, J. Frank, J. Hoagland, K. Levitt, C. Wee, R. Yip, and D. Zerkle, “GrIDS—A Graph-Based Intrusion Detection System for Large Networks,” Proceedings of the 19th National Information Systems Security Conference, pp. 361–370 (Oct. 1996).

[biblio01entry964] 964. S. Staniford-Chen and L. Heberlein, “Holding Intruders Accountable on the Internet,” Proceedings of the 1995 IEEE Symposium on Security and Privacy, pp. 39–49 (May 1995).

[biblio01entry965] 965. A. Stavely, Toward Zero-Defect Programming, Addison-Wesley, Reading, MA (<year>1998</year>).

[biblio01entry966] 966. L. Stein, Web Security: A Step-by-Step Reference Guide, Addison-Wesley Publishing Co., Reading, MA (<year>1998</year>).

[biblio01entry967] 967. J. Steiner, C. Neuman, and J. Schiller, “Kerberos: An Authentication Service for Open Network Systems,” Proceedings of the 1988 Winter USENIX Conference, pp. 191–202 (Feb. 1988).

[biblio01entry968] 968. B. Sterling, The Hacker Crackdown: Law and Disorder on the Electronic Frontier, Bantam Books, New York, NY (<year>1993</year>).

[biblio01entry969] 969. H. Stern, M. Eisler, and R. Labiaga, Managing NFS and NIS, 2nd Edition, O'Reilly and Associates, Sebastopol, CA (<year>2001</year>).

[biblio01entry970] 970. D. Sterne, “On the Buzzword 'Security Policy',” Proceedings of the 1991 IEEE Symposium on Security and Privacy, pp. 219–230 (May 1991).

[biblio01entry971] 971. F. Stevenson, “Cryptanalysis of Contents Scrambling System” (Nov. 8, 1999); available at

[biblio01entry972] 972. H. Stiegler, “A Structure for Access Control Lists,” Software—Practice and Experience 9 (10), pp. 813–819 (Oct. 1979).

[biblio01entry973] 973. C. Stoll, “Stalking the Wily Hacker,” Communications of the ACM 31 (5), pp. 484–497 (May 1988).

[biblio01entry974] 974. C. Stoll, “An Epidemiology of Viruses and Network Worms,” Proceedings of the 12th National Computer Security Conference, pp. 369–377 (Oct. 1989).

[biblio01entry975] 975. C. Stoll, The Cuckoo's Egg: Tracking a Spy Through the Maze of Computer Espionage, Pocket Books, New York, NY (<year>1995</year>).

[biblio01entry976] 976. J. Straw, “The Draft Federal Criteria and the ITSEC: Progress Towards Alignment,” Proceedings of the 16th National Computer Security Conference, pp. 311–323 (Sep. 1993).

[biblio01entry977] 977. E. Strother, “Denial of Service Protection—The Nozzle,” Proceedings of the 16th Annual Computer Security Applications Conference, pp. 32–41 (Dec. 2000).

[biblio01entry978] 978. J. Strunk, G. Goodson, M. Scheinholtz, C. Soules, and G. Ganger, “Self-Securing Storage: Protecting Data in Compromised Systems,” Proceedings of the 4th Symposium on Operating Systems Design and Implementation, pp. 165–179 (Oct. 2000).

[biblio01entry979] 979. P. Su and M. Bishop, “How to Encrypt /usr/dict/words in About a Second,” Technical Report PCS-TR92-182, Department of Mathematics and Computer Science, Dartmouth College, Hanover, NH (Jan. 1992).

[biblio01entry980] 980. J. Sugerman, G. Venkitachalam, and B.-H. Lim, “Virtualizing I/O Devices on VMware Workstation's Hosted Virtual Machine Monitor,” Proceedings of the 2001 USENIX Annual Technical Conference, pp. 1–14 (June 2001).

[biblio01entry981] 981. Sun Microsystems, Inc., NFS: Network File System Protocol Specification, RFC 1094 (Mar. 1989).

[biblio01entry982] 982. Sun Microsystems, Inc., Installing, Administering, and Using the Basic Security Module, Sun Microsystems, Inc., Mountain View, CA (April 1992).

[biblio01entry983] 983. Sun Microsystems, Inc., Version 8.8.8 Sendmail for SunOS™ 5.6 and 5.5.1, Security Bulletin #00187 (June 1999).

[biblio01entry984] 984. D. Sutherland, “A Model of Information,” Proceedings of the 9th National Computer Security Conference, pp. 175–183 (Sep. 1986).

[biblio01entry985] 985. Systems Security Engineering Capability Maturity Model Project, Systems Security Engineering Capability Maturity Model, Version 2.0 (Apr. 1999).

[biblio01entry986] 986. P. Syverson, “Limitations on Design Principles for Public Key Protocols,” Proceedings of the 1996 Symposium on Privacy and Security, pp. 62–72 (May 1996).

[biblio01entry987] 987. T. Takada and H. Koike, “Tudumi: Log Information Visualization System for Intrusion Detection,” Technical Report UEC-IS-TR-2000-08, Graduate School of Information Systems, University of Electro-Communications, Chofu, Tokyo, Japan (Sep. 2000).

[biblio01entry988] 988. T. Takada and H. Koike, “MieLog: Visual Log Information Browsing System With their Characteristics,” Transactions of the Information Processing Society of Japan, 41 (12), pp. 3265–3275 (Dec. 2000).

[biblio01entry989] 989. A. Tanenbaum, Modern Operating Systems, Prentice-Hall, Englewood Cliffs, NJ (<year>1992</year>).

[biblio01entry990] 990. A. Tanenbaum, Computer Networks, 3rd Edition, Prentice-Hall, Upper Saddle River, NJ (<year>1996</year>).

[biblio01entry991] 991. J. Tardo and K. Alagappan, “SPX: Global Authentication Using Public Key Certificates,” Proceedings of the 1991 IEEE Symposium on Research in Security and Privacy, pp. 232–244 (May 1991).

[biblio01entry992] 992. T. Taylor, “Comparison Paper Between the Bell and LaPadula Model and the SRI Model,” Proceedings of the 1984 Symposium on Security and Privacy, pp. 195–202 (Apr. 1984).

[biblio01entry993] 993. H. Teng, K. Chen, and S. Lu, “Adaptive Real-Time Anomaly Detection Using Inductively Generated Sequential Patterns,” Proceedings of the 1990 IEEE Symposium on Research in Security and Privacy, pp. 278–284 (May 1990).

[biblio01entry994] 994. C. Testa, B. Wilner, and V. Gligor, “Trusted RUBIX Architecture and Policy Model Interpretation,” Proceedings of the 8th Annual Computer Security Applications Conference, pp. 97–110 (Nov./Dec. 1992).

[biblio01entry995] 995. K. Thompson, “Reflections on Trusting Trust,” Communications of the ACM 27 (8), pp. 761–763 (Aug. 1984).

[biblio01entry996] 996. D. Thomsen, “Sidewinder: Combining Type Enforcement and UNIX,” Proceedings of the 11th Annual Computer Security Applications Conference, pp. 14–20 (Dec. 1995).

[biblio01entry997] 997. M. Tompa and H. Woll, “How to Share a Secret with Cheaters,” Journal of Cryptology 1 (2), pp. 133–138 (1988).

[biblio01entry998] 998. W. Trapp and L. Washington, Introduction to Cryptography with Coding Theory, Prentice-Hall, Upper Saddle River, NJ (<year>2002</year>).

[biblio01entry999] 999. J. Trostle, “Modelling a Fuzzy Time System,” Proceedings of the 1993 IEEE Symposium on Research in Security and Privacy, pp. 82–89 (May 1993).

[biblio01entry1000] 1000. Trusted Computing Platform Alliance, Trusted Computing Platform Alliance (TCPA) Main Specification, Version 1.1a (Dec. 2001).

[biblio01entry1001] 1001. Trusted Information Systems, A Proposed Interpretation of the TCSEC for Virtual Machine Monitor Architectures, Trusted Information Systems, Glenwood, MD (May 1990).

[biblio01entry1002] 1002. C.-R. Tsai, V. Gligor, and C. Chandersekaran, “A Formal Method for the Identification of Covert Storage Channels in Source Code,” Proceedings of the 1987 Symposium on Security and Privacy, pp. 108–121 (Apr. 1987).

[biblio01entry1003] 1003. C.-R. Tsai and V. Gligor, “A Bandwidth Computation Model for Covert Storage Channels and Its Applications,” Proceedings of the 1988 Symposium on Security and Privacy, pp. 74–86 (Apr. 1988).

[biblio01entry1004] 1004. J. Tsai, A. Liu, E. Juan, and A. Sahay, “Knowledge-Based Software Architectures: Acquisition, Specification, and Verification,” IEEE Transactions on Knowledge and Data Engineering 11 (1), pp. 187–201 (Jan./Feb. 1999).

[biblio01entry1005] 1005. W. Tuchman, “Hellman Presents No Shortcut Solutions to DES,” IEEE Spectrum 16 (7), pp. 40–41 (July 1979).

[biblio01entry1006] 1006. W. L. Tuchman and C. Meyer, “Efficacy of the Data Encryption Standard in Data Processing,” Proceedings of Compcon '78, pp. 340–347 (Sep. 1978).

[biblio01entry1007] 1007. K.Turner (ed.), Using Formal Description Techniques: An Introduction to Estelle, LOTOS, and SDL, John Wiley and Sons, Chichester, UK (<year>1993</year>).

[biblio01entry1008] 1008. P. Tyner, iAPX 432 General Data Processor Architecture Reference Manual, Intel Corporation, Aloha, OR (<year>1981</year>).

[biblio01entry1009] 1009. H. Vaccaro and G. Liepins, “Detection of Anomalous Computer Session Activity,” Proceedings of the 1989 IEEE Symposium on Security and Privacy, pp. 280–289 (May 1989).

[biblio01entry1010] 1010. K. van Wyk and R. Forno, Incident Response, O'Reilly and Associates, Inc., Sebastopol, CA 95472 (Aug. 2001).

[biblio01entry1011] 1011. V. Varadharajan, “Security Enhanced Mobile Agents,” Proceedings of the 7th ACM Conference on Computer and Communications Security, pp. 200–209 (Nov. 2000).

[biblio01entry1012] 1012. W. Venema, “TCP Wrapper: Network Monitoring, Access Control, and Booby Traps,” Proceedings of the 3rd USENIX UNIX Security Symposium, pp. 85–92 (Sep. 1992).

[biblio01entry1013] 1013. B. Venkatraman and R. Newman-Wolfe, “Capacity Estimation and Auditability of Network Covert Channels,” Proceedings of the 1995 Symposium on Security and Privacy, pp. 186–198 (May 1995).

[biblio01entry1014] 1014. J. Viega and G. McGraw, Building Secure Software: How to Avoid Security Problems the Right Way, Addison-Wesley, Boston, MA (<year>2002</year>).

[biblio01entry1015] 1015. D. Vincenzetti, S. Taino, and F. Bolognesi, “STEL: Secure TELnet,” Proceedings of the 5th USENIX UNIX Security Symposium, pp. 75–83 (June 1995).

[biblio01entry1016] 1016. Virgil, The Aeneid (translated by R. Fitzgerald), Vintage Books, New York, NY (<year>1983</year>).

[biblio01entry1017] 1017. S. Visram, W. Artner, and P. Marsden, “Safety Case for the NERC Air Traffic Control System,” Proceedings of the 15th International Conference on Computer Safety, Reliability and Security, pp. 345–362 (Oct. 1996).

[biblio01entry1018] 1018. P. Vixie, “DNS and BIND Security Issues,” Proceedings of the 5th USENIX UNIX Security Symposium, pp. 209–216 (June 1995).

[biblio01entry1019] 1019. J. Voas and A. Ghosh, “Software Fault Injection for Survivability,” Proceedings of the DARPA Information Survivability Conference and Exposition, pp. 338–346 (Jan. 2000).

[biblio01entry1020] 1020. J. Voas, A. Ghosh, G. McGraw, P. Charron, and K. Miller, “Defining an Adaptive Software Security Metric from a Dynamic Software Failure Tolerance Measure,” Proceedings of the 11th Annual Conference on Computer Assurance, pp. 250–263 (June 1996).

[biblio01entry1021] 1021. J. Voas, A. Ghosh, F. Charron, and L. Kassab, “Reducing Uncertainty About Common-Mode Failures,” Proceedings of the 8th International Symposium on Software Reliability Engineering, pp. 308–319 (Nov. 1997).

[biblio01entry1022] 1022. C. Vogt, “PUMA: A Capability-Based Architecture to Support Security and Fault Tolerance,” Proceedings of the International Workshop on Computer Architectures to Support Security and Persistence of Information, pp. 217–228 (May 1990).

[biblio01entry1023] 1023. D. Volpano, C. Irvine, and G. Smith, “A Sound Type System for Secure Flow Analysis,” Journal of Computer Security 4 (2, 3), pp. 167–187 (1996).

[biblio01entry1024] 1024. V. Voydock and S. Kent, “Security Mechanisms in High-Level Network Protocols,” Computing Surveys 15 (2), pp. 135–171 (June 1983).

[biblio01entry1025] 1025. J. Wack and L. Carnahan, Computer Viruses and Related Threats: A Management Guide, NIST Special Publication 500–166, National Institute of Standards and Technology, Washington, DC (Aug. 1989).

[biblio01entry1026] 1026. D. Wagner, J. Foster, E. Brewer, and A. Aiken, “A First Step Towards Automated Detection of Buffer Overrun Vulnerabilities,” Proceedings of the 2000 Symposium on Network and Distributed System Security, pp. 1–15 (Feb. 2000).

[biblio01entry1027] 1027. D. Wagner and B. Schneier, “Analysis of the SSL 3.0 Protocol,” Proceedings of the 2nd USENIX Workshop on Electronic Commerce, pp. 29–40 (Nov. 1996).

[biblio01entry1028] 1028. R. Wahbe, S. Lucco, T. Anderson, and S. Graham, “Efficient Software-Based Fault Isolation,” Proceedings of the 14th Symposium on Operating Systems Principles, pp. 202–216 (Dec. 1993).

[biblio01entry1029] 1029. M. Wahl, S. Kille, and T. Howes, Lightweight Directory Access Protocol (v3): UTF-8 String Representation of Distinguished Names, RFC 2253 (Dec. 1997).

[biblio01entry1030] 1030. M. Waidner and B. Pfitzmann, “The Dining Cryptographers in the Disco: Unconditional Sender and Recipient Untraceability with Computationally Secure Serviceability,” Advances in Cryptology—Proceedings of EUROCRYPT '89, pp. 690 (Apr. 1989).

[biblio01entry1031] 1031. K. Walker, L. Badger, M. Petkac, D. Sterne, K. Oostendorp, and D. Sherman, “Confining Root Programs with Domain and Type Enforcement (DTE),” Proceedings of the 6th USENIX Security Symposium, pp. 21–36 (<year>1996</year>).

[biblio01entry1032] 1032. S. Walker, S. Lipner, C. Ellison, and D. Balenson, “Commercial Key Recovery,” Communications of the ACM 39 (3), pp. 41–47 (Mar. 1996).

[biblio01entry1033] 1033. L. Wall, T. Christensen, and R. Schwartz, Programming Perl, 2nd Edition, O'Reilly and Associates, Sebastopol, CA (Sep. 1996).

[biblio01entry1034] 1034. S. Warren and L. Brandeis, “The Right to Privacy,” Harvard Law Review 4, pp. 193ff. (1890).

[biblio01entry1035] 1035. C. Wee, “LAFS: A Logging and Auditing File System,” Proceedings of the 11th Annual Computer Security Applications Conference, pp. 231–240 (Dec. 1995).

[biblio01entry1036] 1036. M. Weiser, “Program Slicing,” IEEE Transactions on Software Engineering, 10 (4), pp. 352–357 (July 1984).

[biblio01entry1037] 1037. C. Weissman, “Security Controls in the ADEPT-50 Time-Sharing System,” Proceedings of the 1969 Fall Joint Computer Conference, pp. 119–133 (Nov. 1969).

[biblio01entry1038] 1038. C. Weismann, “Security Penetration Testing Guideline,” Chapter 10, Handbook for the Computer Security Certification of Trusted Systems, TM 5540:082A, Naval Research Laboratory, Washington, DC (Jan. 1995).

[biblio01entry1039] 1039. C. Weismann, “Penetration Testing,” in Information Security:An Integrated Collection of Essays [6], pp. 269–296.

[biblio01entry1040] 1040. D. Wheeler, “Secure Programming for Linux and UNIX HOWTO”; available at

[biblio01entry1041] 1041. T. Whiteside, Computer Capers: Tales of Electronic Thievery, Embezzlement, and Fraud, Crowell Publishers, New York, NY (<year>1978</year>).

[biblio01entry1042] 1042. A. Whitten and J. Tygar, “Why Johnny Can't Encrypt: A Usability Evaluation of PGP 5.0,” Proceedings of the 8th USENIX Security Symposium (Aug. 1999).

[biblio01entry1043] 1043. D. Wichers, D. Cook, R. Olsson, J. Corssley, P. Kerchen, K. Levitt, and R. Lo, “PACLs: An Access Control List Approach to Anti-Viral Security,” Proceedings of the 13th National Computer Security Conference, pp. 340–349 (Oct. 1990).

[biblio01entry1044] 1044. D. Wiemer and M. Murray, “Wiemer-Murray Domain Security Policy Model for International Interoperability,” Proceedings of the 21st National Information Systems Security Conference, pp. 526–536 (Oct. 1998).

[biblio01entry1045] 1045. R. Wildes and J. Asmuth, “A System for Automatic Iris Recognition,” Pattern Recognition 27, pp. 121–128 (1994).

[biblio01entry1046] 1046. M. Wilkes, Time-Sharing Computing Systems, 3rd Edition, Elsevier McDonald Publishing Co., New York, NY (<year>1975</year>).

[biblio01entry1047] 1047. A. Wilkinson, D. Anderson, D. Chang, L. Hin, A. Mayo, I. Viney, R. Williams, and W. Wright, “A Penetration Analysis of a Burroughs Large System,” Operating Systems Review 15 (1), pp. 14–25 (Jan. 1981).

[biblio01entry1048] 1048. J. Williams and K. Ferraiolo, “P/sup 3/I–Protection Profile Process Improvement,” Proceedings of the 22nd National Information Systems Security Conference, pp. 175–188 (Oct. 1999).

[biblio01entry1049] 1049. W. Willis, D. Watts, and T. Strahan, Windows 2000 System Administration Handbook, Prentice-Hall, Upper Saddle River, NJ (<year>2000</year>).

[biblio01entry1050] 1050. S. Wilson, J. McDermid, P. Kirkham, C. Pygott, and D. Tombs, “Computer Based Support for Standards and Processes in Safety Critical Systems,” Proceedings of the16th International Conference on Computer Safety, Reliability and Security, pp. 197–209 (Sep. 1997).

[biblio01entry1051] 1051. J. Wing, “A Symbiotic Relationship Between Formal Methods and Security,” Proceedings of Computer Security, Dependability, and Assurance: From Needs to Solutions, pp. 26–38 (Nov. 1998).

[biblio01entry1052] 1052. I. Winkler, “The Non-Technical Threat to Computing Systems,” Computing Systems 9 (1), pp. 3–14 (Winter 1996).

[biblio01entry1053] 1053. H. Winkler-Parenty, “SYBASE: The Trusted Subject DBMS,” Proceedings of the 13th National Computer Security Conference, pp. 589–593 (Oct. 1990).

[biblio01entry1054] 1054. S. Wiseman, “A Secure Capability Computer System,” Proceedings of the 1986 IEEE Symposium on Security and Privacy, pp. 86–94 (Apr. 1986).

[biblio01entry1055] 1055. S. Wiseman, “Preventing Viruses in Computer Systems,” Computers and Security 8 (5), pp. 427–432 (Aug. 1989).

[biblio01entry1056] 1056. T. Woo and S. Lam, “Authentication for Distributed Systems,” IEEE Computer 25 (1), pp. 39–52 (Jan. 1992).

[biblio01entry1057] 1057. C. Wood, “Principles of Secure Information Systems Design,” Computers and Security 9 (1), pp. 13–24 (Feb. 1990).

[biblio01entry1058] 1058. C. Wood, “Principles of Secure Information Systems Design with Groupware Examples,” Computers and Security 12 (7), pp. 663–678 (Nov. 1993).

[biblio01entry1059] 1059. C. Wood, Information Security Policies Made Easy: A Comprehensive Set of Information Security Policies, Version 4, Baseline Software, Sausalito, CA (<year>1994</year>).

[biblio01entry1060] 1060. P. Wood and S. Kochan, UNIX System Security, Hayden Books, Indianapolis, IN (<year>1985</year>).

[biblio01entry1061] 1061. J. Wray, “An Analysis of Covert Timing Channels,” Proceedings of the 1991 IEEE Symposium on Research in Security and Privacy, pp. 2–6 (May 1991).

[biblio01entry1062] 1062. W. Wulf, E. Cohen, W. Corwin, A. Jones, R. Levin, C. Pierson, and F. Pollack, “HYDRA: The Kernel of a Multiprocessor System,” Communications of the ACM 17 (6), pp. 337–345 (June 1974).

[biblio01entry1063] 1063. I.-L. Yen and R. Paul, “Key Applications for High-Assurance Systems,” IEEE Computer 31 (4), pp. 35–46 (Apr. 1998).

[biblio01entry1064] 1064. T. Yetiser, “Polymorphic Viruses: Implementation, Detection, and Protection,” VDS Advanced Research Group, Baltimore, MD (Jan. 1993).

[biblio01entry1065] 1065. T. Ylönen, “SSH—Secure Login Connections over the Internet,” Proceedings of the 6th Annual USENIX Security Symposium, pp. 37–42 (June 1996).

[biblio01entry1066] 1066. C. Young, “Taxonomy of Computer Virus Defense Mechanisms,” Proceedings of the 10th National Computer Security Conference, pp. 220–225 (Sep. 1987).

[biblio01entry1067] 1067. J. Yuill, F. Wu, J. Settle, F. Gong, R. Forno, M. Huang, and J. Asbery, “Intrusion-Detection for Incident-Response, Using a Military Battlefield-Intelligence Process,” Computer Networks 34 (4), pp. 671–697 (Oct. 2000).

[biblio01entry1068] 1068. A. Yulie, D. Cohen, and P. Halinan, “Feature Extraction Using a Multilayer Perceptron,” Computer Vision and Pattern Recognition, pp. 104–109 (<year>1989</year>).

[biblio01entry1069] 1069. A. Zakinthinos and E. Lee, “The Composability of Non-Interference,” Proceedings of the 8th IEEE Computer Security Foundations Workshop, pp. 2–8 (June 1995).

[biblio01entry1070] 1070. P. Zave and M. Jackson, “Four Dark Corners of Requirements Engineering,” ACM Transactions on Software Engineering and Methodology 6 (1), pp. 1–30 (Jan. 1997).

[biblio01entry1071] 1071. Y. Zheng, J. Pieprzyk, and J. Seberry, “HAVAL—A One-Way Hashing Algorithm with Variable Length of Output,” Advances in Cryptology—Proceedings of AUSCRYPT '92, pp. 83–104 (Dec. 1992).

[biblio01entry1072] 1072. D. Zimmerman, The Finger User Information Protocol, RFC 1288 (Dec. 1991).

[biblio01entry1073] 1073. P. Zimmermann, PGP Source Code and Internals, MIT Press, Boston, MA (<year>1995</year>).

[biblio01entry1074] 1074. M. Zurko and R. Simon, “User-Centered Security,” Proceedings of the 1996 New Security Paradigms Workshop, pp. 27–33 (Sep. 1996).

[biblio01entry1075] 1075. E. Zwicky, S. Cooper, and D. Chapman, Building Internet Firewalls, 2nd Edition, O'Reilly and Associates, Sebastopol, CA (<year>2000</year>).

[biblio01entry1076] 1076. E. Zwicky, S. Simmons, and R. Dalton, “Policy as a System Administration Tool,” Proceedings of the 4th Systems Administration Conference (LISA 1990), pp. 115–124 (Oct. 1990).

