<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Secure Business Austria</title>
	<atom:link href="http://www.sba-research.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sba-research.org</link>
	<description></description>
	<lastBuildDate>Tue, 27 Jul 2010 16:14:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>IEEE Transactions SMC-C: Special Issue on Availability, Reliability, and Security</title>
		<link>http://www.sba-research.org/2010/07/27/ieee-transactions-smc-c-special-issue-on-availability-reliability-and-security/</link>
		<comments>http://www.sba-research.org/2010/07/27/ieee-transactions-smc-c-special-issue-on-availability-reliability-and-security/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 16:14:46 +0000</pubDate>
		<dc:creator>eweippl</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1275</guid>
		<description><![CDATA[The six papers in this special issue focus on availability, reliability, and security. Some of the topics covered include prevention of identity theft, biometric technology and authentication, and security considerations for RF identification. Guest editors: Ravi Sandhu, A Min Tjoa, Edgar Weippl. (more&#8230;)]]></description>
			<content:encoded><![CDATA[<p>The six papers in this special issue focus on availability, reliability,  and security.  Some of the topics covered include prevention of  identity theft, biometric technology and authentication, and security  considerations for RF identification. Guest editors: Ravi Sandhu, A Min Tjoa, Edgar Weippl. (<a href="http://ieeexplore.ieee.org/xpl/tocresult.jsp?isnumber=5484888">more&#8230;</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/07/27/ieee-transactions-smc-c-special-issue-on-availability-reliability-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verification, Validation, and Evaluation in Information Security Risk Management</title>
		<link>http://www.sba-research.org/2010/07/21/verification-validation-and-evaluation-in-information-security-risk-management/</link>
		<comments>http://www.sba-research.org/2010/07/21/verification-validation-and-evaluation-in-information-security-risk-management/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 07:19:12 +0000</pubDate>
		<dc:creator>sfenz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1269</guid>
		<description><![CDATA[Our article &#8220;Verification, Validation, and Evaluation in Information Security Risk Management&#8221; (Authors: Stefan Fenz and Andreas Ekelhart) got accepted at IEEE Security &#038; Privacy. Check out the preprint at the IEEE Digital Library. Abstract: Over the last four decades, various information security risk management (ISRM) approaches have emerged. However, there is a lack of sound [...]]]></description>
			<content:encoded><![CDATA[<p>Our article &#8220;Verification, Validation, and Evaluation in Information Security Risk Management&#8221; (Authors: Stefan Fenz and Andreas Ekelhart) got accepted at IEEE Security &#038; Privacy. Check out the <a href="http://www.computer.org/portal/web/csdl/doi/10.1109/MSP.2010.117">preprint</a> at the IEEE Digital Library.</p>
<p>Abstract:<br />
Over the last four decades, various information security risk management (ISRM) approaches have emerged. However, there is a lack of sound verification, validation, and evaluation methods for these approaches. While restrictions, such as the impossibility of measuring exact values for probabilities and follow-up costs, obviously exist, verification, validation, and evaluation of research is essential in any field, and ISRM is no exception. Individual approaches exist, but so far there is no systematic overview of the available methods. In this article we survey verification, validation and evaluation methods referenced in ISRM literature and discuss in which ISRM phases the methods should be applied. The selection of appropriate methods is demonstrated with a potential real-world example. This systematic analysis draws conclusions on the current status of ISRM verification, validation and evaluation and can serve as a reference for researchers and users of ISRM approaches who aim to establish trust in their results.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/07/21/verification-validation-and-evaluation-in-information-security-risk-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Markus Huber at CMU</title>
		<link>http://www.sba-research.org/2010/07/20/markus-huber-at-cmu/</link>
		<comments>http://www.sba-research.org/2010/07/20/markus-huber-at-cmu/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 16:12:55 +0000</pubDate>
		<dc:creator>mhuber</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1267</guid>
		<description><![CDATA[Markus Huber will work this summer on his research in Social Networking Privacy and Security at Carnegie Mellon University with Alessandro Acquisti.]]></description>
			<content:encoded><![CDATA[<p>Markus Huber will work this summer on his research in Social Networking Privacy and Security at Carnegie Mellon University with Alessandro Acquisti.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/07/20/markus-huber-at-cmu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Technical report: Friend-In-The-Middle (FITM) Attacks</title>
		<link>http://www.sba-research.org/2010/07/14/technical-report-friend-in-the-middle-fitm-attacks/</link>
		<comments>http://www.sba-research.org/2010/07/14/technical-report-friend-in-the-middle-fitm-attacks/#comments</comments>
		<pubDate>Wed, 14 Jul 2010 09:10:41 +0000</pubDate>
		<dc:creator>mhuber</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1257</guid>
		<description><![CDATA[Abstract. In the ongoing arms race between spammers and the multi-million dollar anti-spam industry, the number of unsolicited e-mail messages (better known as &#8220;spam&#8221;) and phishing has increased heavily in the last decade. In this paper, we show that our novel friend-in-the-middle attack on social networking sites (SNSs) can be used to harvest social data [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Abstract.</strong> In the ongoing arms race between spammers and the multi-million dollar anti-spam industry, the number of unsolicited e-mail messages (better known as &#8220;spam&#8221;) and phishing has increased heavily in the last decade. In this paper, we show that our novel friend-in-the-middle attack on social networking sites (SNSs) can be used to harvest social data in an automated fashion. This social data can then be exploited for large-scale attacks such as context-aware spam and social-phishing. We prove the feasibility of our attack exemplarily on Facebook and identify possible consequences based on a mathematical model and simulations. Alarmingly, all major SNSs are vulnerable to our attack as they fail to secure the network layer appropriately.</p>
<p><strong><a href="http://www.sba-research.org/wp-content/uploads/publications/FITM_TR-SBA-Research-0710-01.pdf">FITM_TR-SBA-Research-0710-01.pdf</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/07/14/technical-report-friend-in-the-middle-fitm-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;INFORM&#8221; awarded 2nd place</title>
		<link>http://www.sba-research.org/2010/06/23/inform-awarded-2nd-place/</link>
		<comments>http://www.sba-research.org/2010/06/23/inform-awarded-2nd-place/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 10:15:40 +0000</pubDate>
		<dc:creator>mmulazzani</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1196</guid>
		<description><![CDATA[﻿﻿The SBA FIT-IT proposal &#8220;INFORM&#8221; (Internet Forensic Framework) has been awarded the 2nd place in the competition for the best proposal among all proposals for &#8220;Trust in IT-Systems&#8221; in 2009. The goal of &#8220;INFORM&#8221; is to study current challenges in computer forensics and to produce tools that enricht the toolset of a forensic analysist. In [...]]]></description>
			<content:encoded><![CDATA[<p>﻿﻿The SBA FIT-IT proposal &#8220;INFORM&#8221; (Internet Forensic Framework) has been awarded the 2nd place in the competition for the best proposal among all proposals for &#8220;Trust in IT-Systems&#8221; in 2009.</p>
<p>The goal of &#8220;INFORM&#8221; is to study current challenges in computer forensics and to produce tools that enricht the toolset of a forensic analysist. In the traditional approach, the seizure of the suspects hard drives is used to analyse traces of malicious activities. With the widesread availability of hard drive encryption tools, online file storate systems and bootable Linux distributions that leave no traces on the hard drive, new tools and procedures are needed to support the evidence collection process. Social networks and anonymization networks pose further challenges for online forensics that will be adressed by &#8220;INFORM&#8221;.</p>
<p>The news report on <a href="http://futurezone.orf.at/stories/1651626/" target="_blank">futurezone</a> and <a href="http://derstandard.at/1276413772355/Onlineverbrecher-automatisch-verstehen" target="_blank">derstandard</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/06/23/inform-awarded-2nd-place/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Engineering Bot and Porn Sites</title>
		<link>http://www.sba-research.org/2010/06/13/social-engineering-bot-and-porn-sites/</link>
		<comments>http://www.sba-research.org/2010/06/13/social-engineering-bot-and-porn-sites/#comments</comments>
		<pubDate>Sun, 13 Jun 2010 19:01:25 +0000</pubDate>
		<dc:creator>eweippl</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1180</guid>
		<description><![CDATA[Our researchers of ISecLab have recently released some nice papers that are quoted on slashdot (see 1 and 2). More news reports on PCWorld, BBC and darkreading.]]></description>
			<content:encoded><![CDATA[<p>Our researchers of ISecLab have recently released some nice papers that are quoted on slashdot (see <a href="http://tech.slashdot.org/story/10/06/12/1655240/Researchers-Create-Social-Engineering-IRC-Bot?art_pos=3 ">1</a> and <a href="http://it.slashdot.org/story/10/06/12/1712223/Porn-Sites-More-Infected-Than-Thought">2</a>). More news reports on <a href="http://www.pcworld.com/businesscenter/article/198596/adult_web_sites_lure_cybercrime_victims.html">PCWorld</a>, <a href="http://news.bbc.co.uk/2/hi/technology/10289009.stm">BBC</a> and <a href="http://www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=225600304">darkreading</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/06/13/social-engineering-bot-and-porn-sites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IMPACT 2010: May 6</title>
		<link>http://www.sba-research.org/2010/05/22/impact-2010-may-6/</link>
		<comments>http://www.sba-research.org/2010/05/22/impact-2010-may-6/#comments</comments>
		<pubDate>Sat, 22 May 2010 19:30:35 +0000</pubDate>
		<dc:creator>eweippl</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1176</guid>
		<description><![CDATA[We celebrate the new grant COMET-K1 (more&#8230;)]]></description>
			<content:encoded><![CDATA[<p>We celebrate the new grant COMET-K1 (<a href="http://www.sba-research.org/impact2010">more&#8230;</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/05/22/impact-2010-may-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Digital Genome&#8221; Safeguards Dying Data Formats</title>
		<link>http://www.sba-research.org/2010/05/20/digital-genome-safeguards-dying-data-formats/</link>
		<comments>http://www.sba-research.org/2010/05/20/digital-genome-safeguards-dying-data-formats/#comments</comments>
		<pubDate>Thu, 20 May 2010 09:50:00 +0000</pubDate>
		<dc:creator>eweippl</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1157</guid>
		<description><![CDATA[quoted from ACM  Queue: &#8220;European researchers have deposited a &#8220;digital genome&#8221; time capsule inside a data storage facility known as the Swiss Fort Knox, which contains a blueprint that future generations can use to read data stored using obsolete technology. The capsule is the result of the four-year Planets project, which was launched to preserve [...]]]></description>
			<content:encoded><![CDATA[<p>quoted from <a href="http://queue.acm.org/technews.cfm">ACM  Queue</a>: &#8220;<em>European researchers have deposited a  &#8220;digital genome&#8221; time capsule inside a data storage facility known as  the Swiss Fort Knox, which contains a blueprint that future generations  can use to read data stored using obsolete technology. The capsule is  the result of the four-year Planets project, which was launched to  preserve the world&#8217;s digital assets as technology changes. &#8220;The time  capsule being deposited inside Swiss Fort Knox contains the digital  equivalent of the genetic code of different data formats,&#8221; says British  Library archivist Adam Farquhar. Planets project researchers note that  the European Union alone loses at least three billion euros worth of  digital information every year. &#8220;Unlike hieroglyphics carved in stone or  ink on parchment, digital data has a shelf life of years, not  millennia,&#8221; says University of Technology of Vienna professor <strong>Andreas  Rauber</strong>. The project aims to preserve data DNA, the information and tools  to access and read historical digital material and prevent digital  memory loss into the next century. &#8220;If we can nail the next 100 years,  we figure we will be able to nail the next 100 years as well,&#8221; Farquhar  says.</em> &#8221;</p>
<p>(<a href="http://www.reuters.com/article/idUSTRE64H4GE20100519">more&#8230;</a>) (<a href="http://www.sba-research.org/team/key-researcher/andreas-rauber/">Andreas Rauber @ SBA</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/05/20/digital-genome-safeguards-dying-data-formats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guest talks and visiting researchers from the university of Deusto.</title>
		<link>http://www.sba-research.org/2010/05/19/guest-talks-and-visiting-researchers-from-the-university-of-deusto/</link>
		<comments>http://www.sba-research.org/2010/05/19/guest-talks-and-visiting-researchers-from-the-university-of-deusto/#comments</comments>
		<pubDate>Wed, 19 May 2010 18:18:19 +0000</pubDate>
		<dc:creator>eweippl</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1151</guid>
		<description><![CDATA[Pablo García Bringas and Igor Santos Grueiro visited SBA Research and we plan to collaborate in the area of privacy and forensics in social networks.]]></description>
			<content:encoded><![CDATA[<p>Pablo García Bringas and Igor Santos Grueiro visited SBA Research and we plan to collaborate in the area of privacy and forensics in social networks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/05/19/guest-talks-and-visiting-researchers-from-the-university-of-deusto/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Key Researcher: Prof. Stefanie Rinderle-Ma</title>
		<link>http://www.sba-research.org/2010/05/12/new-key-researcher-prof-stefanie-rinderle-ma/</link>
		<comments>http://www.sba-research.org/2010/05/12/new-key-researcher-prof-stefanie-rinderle-ma/#comments</comments>
		<pubDate>Wed, 12 May 2010 17:38:20 +0000</pubDate>
		<dc:creator>eweippl</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1129</guid>
		<description><![CDATA[We are happy to have a new key research who focuses on workflow systems and security: Prof. Stefanie Rinderle-Ma (at the University of Vienna)]]></description>
			<content:encoded><![CDATA[<p>We are happy to have a new key research who focuses on workflow systems and security: Prof. Stefanie Rinderle-Ma (at <a href="http://www.cs.univie.ac.at/employee.php?eid=1890">the University of Vienna</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/05/12/new-key-researcher-prof-stefanie-rinderle-ma/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
