Comments & Discussion

Boston University moderates comments to facilitate an informed, substantive, civil conversation. Abusive, profane, self-promotional, misleading, incoherent or off-topic comments will be rejected. Moderators are staffed during regular business hours (EST) and can only accept comments written in English. Statistics or facts must include a citation or a link to the citation.

There are 3 comments on Amassing a Small Army Against a Growing Enemy

  1. Few reports on the problem of compromised computers come right out and say that the issue is principally with Windows PCs, largely due to Microsoft’s historic failings to robustly architect and program their software. The problem is exacerbated by PC users failing to apply software updates regularly, using weak passwords, using the same password for multiple accounts, responding to phishing, and allowing dubious software to install on their computers. Security experts warn that “virus protection” is no protection because it is always behind the curve, and closes the gate after the invaders have entered. Professor Crovella’s techniques for identifying anomalous activity can go a long way toward finding compromised PCs and making a site more secure, at the same time making the site a better netizen.

  2. I work as a technical writer in an ethical hacker company that does penetration testing. It has also developed a product that checks the behavior of a web application in response to probing and points out the vulnerable code.
    What Mark Crovella is doing is remarkable and effective, but we still have to keep on building defenses to stay ahead of the cyber criminals. IMO, not one single tool can suffice. Let us say that Mark’s multivariate method is successful, what next? We still have to beef up defenses as each new threat appears. Unfortunately, attackers will keep on thinking of new ways to penetrate defenses, and we, the good guys, will have to keep one, or more, steps ahead.

    Jack Shasha, Technical Writer

Post a comment.

Your email address will not be published. Required fields are marked *