JANUARY 2004
Taking Aim
INTRUSION DETECTION Target-based IDSes squelch network noise to pinpoint the alerts you really care about. We review three solutions to see if they hit the bull's-eye.
by JOEL SNYDER

Passive Scanning: Let It Happen
SIDEBAR

Comparison Chart






FEATURES
Microsoft's Paradox
EXPOSE Two years into Trustworthy Computing, the software giant faces the daunting challenge of winning and keeping customers while grappling with periodic setbacks.
by LAWRENCE M. WALSH

Are You Prepared?
INCIDENT MANAGEMENT IT personnel may be front-line responders, but if they "own" incident management, your enterprise is at risk. Here's a business blueprint for an effective incident management program.
by FRED TRICKEY

Incident Response Matrix

The Next RSA
PEOPLE Legendary cryptographer Ron Rivest has a reputation for tackling "hard" security problems. Up next: Micropayments.
by ANDREW BRINEY

Secure SSO for Web Services
TEST CENTER RSA ClearTrust 5.5 eases the administration of securing Web services identity management across business partners' systems.
by GEORGE WRENN




COLUMNS
Secure Coding? Bah!
EDITOR'S NOTE
by ANDREW BRINEY

Criminal Rewards
ON THE LIGHTER SIDE Bounties could create a new benchmark for hackers to measure themselves.
by LAWRENCE M. WALSH

Layer Eight
PROFESSION It's time to take the OSI model up a notch to the human layer.
by JAY HEISER

Balkanizing the Internet
LOGOFF Spammers and hackers are driving organizations -- and nations -- to the wholesale blocking of traffic.
by DANA W. PAXSON




DEPARTMENTS
Viewpoint


New Year's Mixed Blessings
SECURITY MANAGEMENT As the economy heats up, so do security managers' opportunities and challenges to win more budget.
by NIALL MCKAY

Calculating ROI for Security
by ANNE SAITA

Where's the Breach?
SECURITY LEGISLATION California's highly touted security incident disclosure law isn't living up to its hype.
by MICHAEL FITZGERALD

A 'Hard' Line on Malware
ANTIVIRUS SOLUTIONS Washington University team creates a new platform to overcome software filter limitations.
by SANDRA KAY MILLER

No Compliance, No Access
NETWORK SECURITY IT giants develop new ways to reject poorly protected devices.
by NIALL MCKAY

"Personal Firewall Day" Drives Security Home
by ANNE SAITA

Ridge: Security Cooperation Could Be Compulsory
HOMELAND SECURITY


Instant Messaging Security
HOT PICK
by SUZANNE GASPAR

Products
REVIEWS
NetScreen Technologies' 5GT
Network Associates' McAfee Entercept Desktop Edition
SSH Communications' SSH Tectia Manager
Borderware Technologies' SteelGate
Courion's Identity Management Suite 6.5
InfoExpress' CyberGatekeeper LAN


Hack Notes Portable Reference Series
SECURE READS
by DAVID BIANCO