Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA Information Security Publications

My security book is out!

More information about me
List of my public appearances
My security book reviews

My recent blog posts (see old content below):

Subscribe to RSS headline updates from:
Powered by FeedBurner

(09/26/2006) For more of my recent writing check out my three (!) blogs: Anton Chuvakin Personal Blog, Anton on Security Blog and my O'Reilly Author Blog.

(06/01/2005) Finally, it happens! I will be teaching a SANS class on intrusion detection (GCIA track) next month in DC. Really cool!!

(05/31/2005) Not sure if anybody cares, but I passed another benchmark in my security career - I was asked to serve on the Advisory Board of a new security company.

(03/15/2005) This excellent book ("Inside Network Perimeter Security (2nd Edition)"), where I happen to be one of the technical reviewers is a must-read for a security professional and a system/network admin. I finally got my copy today.

(12/13/2004) I am quoted in this article in "Information Security Magazine", talking about future threats.

(12/01/2004) I am quoted in this article in "Network Magazine" and in this one in "Network World".

(07/21/2004) Interview with me is posted at TechTarget.

(05/31/2004) "Know Your Enemy II" is here, this book is light years beyond the first edition and contains much more practical info on creating and running honeypots, as well as analyzing their data. And, yes, I did write a chapter on Generation I honeynets ;-)

(04/18/2004) You can now find me on Orkut and LinkedIn.

(03/01/2004) The new and cool Project Honeynet Scan of the Month challenge #30 that I organized. A new type of challenge involves the analysis of honeynet firewalll logs.

(03/01/2004) Here is a fun interview with me about my book "Security Warrior". I talk about Linux security.

(01/15/2004) But wait, there is more! I also contributed to this book - Information Security Management Handbook (Fifth Edition). I wrote a fun section on covert channels.

(01/12/2004) My book is finally OUT. Check it out here. It is called "Security Warrior".

(11/25/2003) My current Internet Worm profiles from the honeynet: MSBlaster, CodeRed, Slammer, Welchia. How much worm is out there :-)

(11/20/2003) Fun attack statistics from my honeynet (running for more than a year now) are up. I plan to organize and add some new ones, but for now check the attacksed ports and common Snort network IDS alarms at my honeynet page.

(10/10/2003) Check out my entry included in the newest 2003 SANS/FBI Top 20.

(05/01/2003) I now have a security weblog at O'Reilly. Check it out here. First entries are already appearing.

(04/22/2003) My GCIH Practical "Honeykiddies vs OpenSSL: The Battle at Port 443" is finally posted on SANS GIAC site. My GCIA practical is here.

(01/29/2003) My contributions to Snort network IDS signature documentation are posted (one example is here and the complete list can be seen on the Snort CVS access page)

(01/02/2003) Another page with translations of my information security papers (Spanish)

(12/26/2002) My bash shell keystroke monitoring tool is posted on the Honeynet Project tools page

(10/15/2002) I am quoted by Lance Spitzner in his book "Honeypots: Tracking Hackers" on chroot() security issues. My paper is included on the book CD as well.

(10/02/2002) Check out my entry included in SANS/FBI Top 20.

(08/15/2002) Check out the latest Honeynet Project Scan of the Month Challenge #22 that I designed. It deals with investigating further activity of the evil binary owner.

(08/08/2002) I am quoted on cybercrime in "SC Magazine"!

(06/10/2002) Look at this fun press release on honeynets and honeypots that I helped to write!

(05/03/2002) Check out the famous Honeynet Project Scan of the Month Challenge Scan of The Month #20. I have written an official solution for the Honeynet project, available here. New challenges are coming

UNIX/Linux Security
Vulnerability Analysis

Hack-of-the-Week series  takes a recent vulnerability in some popular operating system or other software and studies it. Realistic exploit scenarios are developed, and suggested ways of mitigating risks are considered and new ones proposed [published at SecurityWatch]

Other vulnerability and penetration testing articles
  • (05/01/2002) "Standardizing Penetration Testing" Gives an outlines of popular penetration testing methodology (OSSPTMM) and challenges with standartizing penetration testing. [published at SC Magazine web portal]
  • (04/22/2003) "Covert Channels" A modern review of network covert channeling methods which compares them with classic "Rainbow Series" covert channles on secure operating systems [submitted for publication]
Application security
VPN, IPSec and encryption
  • (08/2001) "Future IP Security" outlines the future of IP addressing (IPv6) and focuses on the security components of next generation IP services (IPsec) [published at SecurityWatch]
Malicious hacker attacks
Policy and people issues of information security
  • (03/20/2001) "NLP-powered Social Engineering Attacks" describes a scary way of performing Social Engineering attacks based on powerful NLP persuasion technology [published at SecurityFocus]
  • (08/2001) "Internal attacks: Doom of Information Security" Research report on internal security breaches, attacker motivations, various countermeasures and their relative efficiency [published in the Journal of Information Security (CRC)]
Security Tools and Intrusion Detection
Honeypots and honeynets
Security Data Analysis
Enterprise Security Management
Infosec book reviews
All my Amazon reviews.
Other IT issues (non-security)
Security Basics and FAQs

Information Security FAQs
Digital risks
  • (09/2001) "Digital risks taxonomy" A diagram that structures digital risks (such as hacking, Do, etc) in the form useful for impact assessment for the purposes of insurance [local copy] 
  • (09/2001) "Impacts of digital risks on enterprise" [under development]
  • (12/05/2001) "Infrastructure Protection: Infosec Perspective" The paper covers issues in critical infrastructure protection and information security, lists several focus areas that need efforts and summarizes the results of recent meeting in New England on infrastructure protection. [published at SC Magazine web portal]
  • (11/11/2001) "Protecting New England: A Call to Action" The paper summarizes the results of joint meeting on critical infrastructure protection in New England and infosecurity community role in increasing information sharing [published at ISSA web site in PDF format]


To contact me with questions or comments, use email. For other contact methods, look at the home page. For my information security book page go here.


Last modified: Thu Mar 02 22:00:28 Eastern Standard Time 2006