<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dragan on Security &#187; Security Research</title>
	<atom:link href="http://www.conwex.info/blog/index.php/category/security-research/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.conwex.info/blog</link>
	<description>Security Blog: Computers, Information and Communication Technology</description>
	<lastBuildDate>Thu, 05 Jan 2012 13:23:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.4</generator>
		<item>
		<title>Security Risk Management for Critical Infrastructures</title>
		<link>http://www.conwex.info/blog/index.php/2011/10/12/security-risk-management-for-critical-infrastructures/</link>
		<comments>http://www.conwex.info/blog/index.php/2011/10/12/security-risk-management-for-critical-infrastructures/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 10:07:43 +0000</pubDate>
		<dc:creator>Dragan Pleskonjic</dc:creator>
				<category><![CDATA[Conferences, Events]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[Critical Infrastructures]]></category>
		<category><![CDATA[itAIS]]></category>
		<category><![CDATA[Security Risk Management]]></category>

		<guid isPermaLink="false">http://www.conwex.info/blog/?p=717</guid>
		<description><![CDATA[Paper “Security Risk Management for Critical Infrastructures” prepared by two colleagues and me has been presented on itAIS 2011 conference at Rome Italy on October 8th, 2011.

Citation data for the paper:

    Dragan Pleskonjic, Fabrizio Virtuani, Oscar Zoggia: "Security Risk Management for Critical Infrastructures", ItAIS 2011, Rome, Italy, October 7-8, 2011

Here is conference program.

Abstract:  <a href="http://www.conwex.info/blog/index.php/2011/10/12/security-risk-management-for-critical-infrastructures/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.conwex.info/blog/index.php/2011/10/12/security-risk-management-for-critical-infrastructures/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cellphone location tracking – are you worried?</title>
		<link>http://www.conwex.info/blog/index.php/2011/09/04/cellphone-location-tracking-are-you-worried/</link>
		<comments>http://www.conwex.info/blog/index.php/2011/09/04/cellphone-location-tracking-are-you-worried/#comments</comments>
		<pubDate>Sun, 04 Sep 2011 08:46:38 +0000</pubDate>
		<dc:creator>Dragan Pleskonjic</dc:creator>
				<category><![CDATA[Mobile / Cellular / Bluetooth]]></category>
		<category><![CDATA[Polls]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[Wireless Security]]></category>

		<guid isPermaLink="false">http://www.conwex.info/blog/?p=703</guid>
		<description><![CDATA[As part of ad-hoc research and preparation of presentation to security related conference, I put new poll on this blog. Question is &#8220;Cellphone location tracking – are you worried?&#8221;, and possible answers: • Yes • No • Don’t know Poll &#8230; <a href="http://www.conwex.info/blog/index.php/2011/09/04/cellphone-location-tracking-are-you-worried/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.conwex.info/blog/index.php/2011/09/04/cellphone-location-tracking-are-you-worried/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NIST has selected the Third (Final) Round Candidates of the SHA-3 Competition</title>
		<link>http://www.conwex.info/blog/index.php/2011/01/04/nist-has-selected-the-third-final-round-candidates-of-the-sha-3-competition/</link>
		<comments>http://www.conwex.info/blog/index.php/2011/01/04/nist-has-selected-the-third-final-round-candidates-of-the-sha-3-competition/#comments</comments>
		<pubDate>Tue, 04 Jan 2011 22:34:34 +0000</pubDate>
		<dc:creator>Dragan Pleskonjic</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Polls]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[algorithms]]></category>
		<category><![CDATA[BLAKE]]></category>
		<category><![CDATA[competition]]></category>
		<category><![CDATA[Grøstl]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[JH]]></category>
		<category><![CDATA[Keccak]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[SHA-3]]></category>
		<category><![CDATA[Skein]]></category>

		<guid isPermaLink="false">http://www.conwex.info/blog/?p=647</guid>
		<description><![CDATA[NIST has selected five SHA-3 candidate algorithms to advance to the third (and final) round: BLAKE, Grøstl, JH, Keccak, Skein. Selection was announced during December 2010. What do you think, which algorithm will win competition and become new SHA-3 standard? You can vote in poll on this blog (right upper corner).
Here is citation for NIST announcement of 3rd (final) round candidates selection: <a href="http://www.conwex.info/blog/index.php/2011/01/04/nist-has-selected-the-third-final-round-candidates-of-the-sha-3-competition/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.conwex.info/blog/index.php/2011/01/04/nist-has-selected-the-third-final-round-candidates-of-the-sha-3-competition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Impact of Cloud Computing</title>
		<link>http://www.conwex.info/blog/index.php/2010/06/20/security-impact-of-cloud-computing/</link>
		<comments>http://www.conwex.info/blog/index.php/2010/06/20/security-impact-of-cloud-computing/#comments</comments>
		<pubDate>Sun, 20 Jun 2010 15:18:15 +0000</pubDate>
		<dc:creator>Dragan Pleskonjic</dc:creator>
				<category><![CDATA[Operating Systems and Application Security]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[Cloud computing]]></category>
		<category><![CDATA[IEEE Security and Privacy Magazine]]></category>

		<guid isPermaLink="false">http://www.conwex.info/blog/?p=597</guid>
		<description><![CDATA[Interesting paper titled "Understanding Cloud-Computing Vulnerabilities" appears in IEEE Security and Privacy Magazine (June 2010 issue). Authors of article are Bernd Grobauer, Tobias Walloschek, Elmar Stöcker, from Siemens (Munich, Germany). It touches topic which is very hot topic nowadays because of increased importance of cloud computing and many discussions and different views of its security advantages and drawbacks. <a href="http://www.conwex.info/blog/index.php/2010/06/20/security-impact-of-cloud-computing/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.conwex.info/blog/index.php/2010/06/20/security-impact-of-cloud-computing/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Citation at Fourth Balkan Conference in Informatics</title>
		<link>http://www.conwex.info/blog/index.php/2010/05/23/citation-at-fourth-balkan-conference-in-informatics/</link>
		<comments>http://www.conwex.info/blog/index.php/2010/05/23/citation-at-fourth-balkan-conference-in-informatics/#comments</comments>
		<pubDate>Sun, 23 May 2010 08:06:07 +0000</pubDate>
		<dc:creator>Dragan Pleskonjic</dc:creator>
				<category><![CDATA[Conferences, Events]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[Book]]></category>
		<category><![CDATA[citation]]></category>
		<category><![CDATA[IEEE Computer]]></category>
		<category><![CDATA[IEEE conference]]></category>
		<category><![CDATA[journal]]></category>
		<category><![CDATA[Sigurnost računarskih sistema i mreža]]></category>

		<guid isPermaLink="false">http://www.conwex.info/blog/?p=579</guid>
		<description><![CDATA[One statement from our earlier book, which has been published 2007, was cited at IEEE Conference Journal. It is interesting and actual for many organizations at moment: "Security is a process of keeping necessary level of risk in acceptable boundaries. That means security is a continual process and not a final state. Organization or institution can’t consider itself “secured” after last security check. That process needs to be continual."
DOI link: http://doi.ieeecomputersociety.org/10.1109/BCI.2009.20. <a href="http://www.conwex.info/blog/index.php/2010/05/23/citation-at-fourth-balkan-conference-in-informatics/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.conwex.info/blog/index.php/2010/05/23/citation-at-fourth-balkan-conference-in-informatics/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Citation and Quotes</title>
		<link>http://www.conwex.info/blog/index.php/2010/05/13/citation-and-quotes/</link>
		<comments>http://www.conwex.info/blog/index.php/2010/05/13/citation-and-quotes/#comments</comments>
		<pubDate>Thu, 13 May 2010 14:20:12 +0000</pubDate>
		<dc:creator>Dragan Pleskonjic</dc:creator>
				<category><![CDATA[Books, Magazines and Journals]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[Wireless Security]]></category>
		<category><![CDATA[citation]]></category>
		<category><![CDATA[IEEE Computer Magazine]]></category>
		<category><![CDATA[quotes]]></category>
		<category><![CDATA[Springer Link]]></category>
		<category><![CDATA[Telektronikk Journal]]></category>
		<category><![CDATA[WIDS]]></category>
		<category><![CDATA[WIPS]]></category>
		<category><![CDATA[Wireless Intrusion Detection Systems]]></category>
		<category><![CDATA[Wireless Intrusion Prevention Systems]]></category>

		<guid isPermaLink="false">http://www.conwex.info/blog/?p=577</guid>
		<description><![CDATA[I was cited and quoted couple of times in IEEE Computer Magazine article "Fighting Intrusions into Wireless Networks", Springer Link Book “Novel Algorithms and Techniques in Telecommunications and Networking” and Telektronikk Journal. <a href="http://www.conwex.info/blog/index.php/2010/05/13/citation-and-quotes/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.conwex.info/blog/index.php/2010/05/13/citation-and-quotes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Poll: Do You Store Your Credit Card PIN Into Mobile Phone?</title>
		<link>http://www.conwex.info/blog/index.php/2010/04/09/poll-do-you-store-your-credit-card-pin-into-mobile-phone/</link>
		<comments>http://www.conwex.info/blog/index.php/2010/04/09/poll-do-you-store-your-credit-card-pin-into-mobile-phone/#comments</comments>
		<pubDate>Fri, 09 Apr 2010 13:31:31 +0000</pubDate>
		<dc:creator>Dragan Pleskonjic</dc:creator>
				<category><![CDATA[Polls]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[credit card]]></category>
		<category><![CDATA[mobile phone]]></category>
		<category><![CDATA[pin]]></category>
		<category><![CDATA[poll]]></category>
		<category><![CDATA[vote]]></category>

		<guid isPermaLink="false">http://www.conwex.info/blog/?p=574</guid>
		<description><![CDATA[I invite you to answer poll question “Do you store your credit card PIN into mobile phone?” <a href="http://www.conwex.info/blog/index.php/2010/04/09/poll-do-you-store-your-credit-card-pin-into-mobile-phone/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.conwex.info/blog/index.php/2010/04/09/poll-do-you-store-your-credit-card-pin-into-mobile-phone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interception of GSM Calls</title>
		<link>http://www.conwex.info/blog/index.php/2010/01/07/interception-of-gsm-calls/</link>
		<comments>http://www.conwex.info/blog/index.php/2010/01/07/interception-of-gsm-calls/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 16:33:36 +0000</pubDate>
		<dc:creator>Dragan Pleskonjic</dc:creator>
				<category><![CDATA[Conferences, Events]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Mobile / Cellular / Bluetooth]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[Wireless Security]]></category>
		<category><![CDATA[A5/1]]></category>
		<category><![CDATA[CCC]]></category>
		<category><![CDATA[Chris Paget]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[Interception]]></category>
		<category><![CDATA[Karsten Nohl]]></category>

		<guid isPermaLink="false">http://www.conwex.info/blog/?p=569</guid>
		<description><![CDATA[There is serious vulnerability with A5/1 encryption scheme used in GSM networks. It can lead to interception of GSM calls. This vulnerability has been presented by Karsten Nohl and Chris Paget at the 26th Chaos Communication Congress (26C3). <a href="http://www.conwex.info/blog/index.php/2010/01/07/interception-of-gsm-calls/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.conwex.info/blog/index.php/2010/01/07/interception-of-gsm-calls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPS, Whom to believe: Gartner or NSS Labs?</title>
		<link>http://www.conwex.info/blog/index.php/2009/12/10/ips-whom-to-believe-gartner-or-nss-labs/</link>
		<comments>http://www.conwex.info/blog/index.php/2009/12/10/ips-whom-to-believe-gartner-or-nss-labs/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 11:48:11 +0000</pubDate>
		<dc:creator>Dragan Pleskonjic</dc:creator>
				<category><![CDATA[Hardware Security]]></category>
		<category><![CDATA[Intrusion Detection / Prevention Systems]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Intrusion Prevention Systems]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Juniper Networks]]></category>
		<category><![CDATA[Magic Quadrant]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[NetworkWorld]]></category>
		<category><![CDATA[NSS Labs]]></category>
		<category><![CDATA[SecurityFocus]]></category>
		<category><![CDATA[TippingPoint]]></category>

		<guid isPermaLink="false">http://www.conwex.info/blog/?p=558</guid>
		<description><![CDATA[An independent test and evaluation of 15 different network intrusion-protection system products from seven vendors showed none were fully effective in warding off attacks against Microsoft, Adobe and other programs. NSS Labs, which conducted the test without vendor sponsorship of any kind, also evaluated the 15 network IPS offerings for their capability in responding to "evasions," attacks delivered in an obfuscated and stealthy manner in order to hide. In that arena, Juniper Networks and TippingPoint didn't perform particularly well. Juniper IPS scored lowest at only 17% effectiveness. In that arena, the McAfee and IBM IPS held up particularly well. <a href="http://www.conwex.info/blog/index.php/2009/12/10/ips-whom-to-believe-gartner-or-nss-labs/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.conwex.info/blog/index.php/2009/12/10/ips-whom-to-believe-gartner-or-nss-labs/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Second Round Candidates of the Cryptographic Hash Algorithm Competition Selected</title>
		<link>http://www.conwex.info/blog/index.php/2009/09/02/second-round-candidates-of-the-cryptographic-hash-algorithm-competition-selected/</link>
		<comments>http://www.conwex.info/blog/index.php/2009/09/02/second-round-candidates-of-the-cryptographic-hash-algorithm-competition-selected/#comments</comments>
		<pubDate>Wed, 02 Sep 2009 14:54:23 +0000</pubDate>
		<dc:creator>Dragan Pleskonjic</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[competition]]></category>
		<category><![CDATA[Cryptographic Hash Algorithm]]></category>
		<category><![CDATA[Keccak]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Round 2]]></category>
		<category><![CDATA[SHA-3]]></category>
		<category><![CDATA[Skein]]></category>

		<guid isPermaLink="false">http://www.conwex.info/blog/?p=552</guid>
		<description><![CDATA[NIST has selected the Second Round Candidates of the SHA-3 Competition recently. Following 14 second round candidates to continue in the competition: <a href="http://www.conwex.info/blog/index.php/2009/09/02/second-round-candidates-of-the-cryptographic-hash-algorithm-competition-selected/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.conwex.info/blog/index.php/2009/09/02/second-round-candidates-of-the-cryptographic-hash-algorithm-competition-selected/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

