<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>Technical Reports</title><link>http://www.sei.cmu.edu//library/reportspapers.cfm</link><description>Library - Reports and Papers</description><lastBuildDate>Tue, 18 Jun 2013 22:14:25 +0000</lastBuildDate><generator>CommonSpot Content Server</generator><copyright>Software Engineering Institute</copyright><item><title>Isolating Patterns of Failure in Department of Defense Acquisition</title><description>This report documents an investigation into issues related to aligning acquisition strategies with business and mission goals.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13tn014.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13tn014.cfm</link><pubDate>Tue, 11 Jun 2013 17:49:49 +0000</pubDate></item><item><title>Socio-Adaptive Systems Challenge Problems Workshop Report</title><description>Presents a summary of the findings that emerged from the Socio-Adaptive Systems Challenge Problem Workshop in Pittsburgh, held in April 2012. The workshop’s goal was to identify the challenges associated with resource allocation for warfighters operating at the tactical edge, where networks are often unreliable, and bandwidth limited and inconsistent.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13sr010.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13sr010.cfm</link><pubDate>Mon, 10 Jun 2013 16:45:54 +0000</pubDate></item><item><title>Application Virtualizaton as a Strategy for Cyber Foraging in Resource-Constrained Environments</title><description>This technical note explores the applicability of application virtualization as a strategy for cyber foraging in resource-constrained environments. Cyber foraging is a technique to enable resource-poor, mobile devices to leverage external computing power. Application virtualization emulates operating system services for applications. While it involves some challenges, it provides a promising strategy for cyber foraging in resource-constrained environments because of it is a lightweight approach that offers high portability.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13tn007.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13tn007.cfm</link><pubDate>Wed, 22 May 2013 17:00:43 +0000</pubDate></item><item><title>Spotlight On: Insider Theft of Intellectual Property Inside the United States Involving Foreign Governments or Organizations</title><description>This technical note defines intellectual property (IP) and insider theft of IP, gives a snapshot of the insiders involved in these cases, summarizes some of the cases, and provides recommendations for mitigating the risk of similar incidents of insider threat.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13tn009.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13tn009.cfm</link><pubDate>Mon, 20 May 2013 17:20:28 +0000</pubDate></item><item><title>Software Assurance Competency Model</title><description>This Software Assurance Competency Model helps create a foundation for assessing and advancing the capability of software assurance professionals.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13tn004.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13tn004.cfm</link><pubDate>Thu, 09 May 2013 14:01:46 +0000</pubDate></item><item><title>PSP-VDC: An Adaptation of the PSP that Incorporates Verified Design by Contract</title><description>This paper describes a proposal for integrating Verified Design by Contract into PSP in order to reduce the amount of defects present at the Unit Testing phase, while preserving or improving productivity.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13tr005.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13tr005.cfm</link><pubDate>Tue, 07 May 2013 17:54:37 +0000</pubDate></item><item><title>Quantifying Uncertainty in Expert Judgment: Initial Results</title><description>The work described in this report, part of a larger SEI research effort on Quantifying Uncertainty in Early Lifecycle Cost Estimation (QUELCE), aims to develop and validate methods for calibrating expert judgment. Reliable expert judgment is crucial across the program acquisition lifecycle for cost estimation, and perhaps most critically for tasks related to risk analysis and program management. This research is based on three field studies that compare and validate training techniques aimed at improving the participants’ skills to enable more realistic judgments commensurate with their knowledge.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13tr001.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13tr001.cfm</link><pubDate>Tue, 19 Mar 2013 14:50:27 +0000</pubDate></item><item><title>Justification of a Pattern for Detecting Intellectual Property Theft by Departing Insiders</title><description>This analysis justifies applying the pattern “Increased Review for Intellectual Property (IP) Theft by Departing Insiders,” which helps organizations plan, prepare, and implement a strategy to mitigate the risk of insider theft of IP.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13tn013.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13tn013.cfm</link><pubDate>Tue, 19 Mar 2013 13:52:41 +0000</pubDate></item><item><title>Detecting and Preventing Data Exfiltration Through Encrypted Web Sessions via Traffic Inspection</title><description>This report presents methods that can be used to detect and prevent data exfiltration using a Linux-based proxy server in a Microsoft Windows environment.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13tn012.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13tn012.cfm</link><pubDate>Tue, 12 Mar 2013 18:48:52 +0000</pubDate></item><item><title>The MAL: A Malware Analysis Lexicon</title><description>This report presents the results of the Malware Analysis Lexicon (MAL) initiative, a small project to develop the first common vocabulary for malware analysis.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13tn010.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13tn010.cfm</link><pubDate>Wed, 27 Feb 2013 18:35:05 +0000</pubDate></item><item><title>Insider Threat Control: Using Universal Serial Bus (USB) Device Auditing to Detect Possible Data Exfiltration by Malicious Insiders</title><description>This report presents methods to audit USB device use within a Microsoft Windows environment.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13tn003.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13tn003.cfm</link><pubDate>Mon, 21 Jan 2013 17:44:47 +0000</pubDate></item><item><title>Insider Threat Control: Understanding Data Loss Prevention (DLP) and Detection by Correlating Events from Multiple Sources</title><description>This report focuses on the theft of intellectual property using removable media, in particular, USB devices. We present methods to control removable media devices in a Microsoft Windows environment using Group Policy within an Active Directory environment. We also explore OpenDLP, an open source tool for identifying where sensitive data resides on organizational systems.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/13tn002.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/13tn002.cfm</link><pubDate>Wed, 16 Jan 2013 17:24:27 +0000</pubDate></item><item><title>Common Sense Guide to Mitigating Insider Threats, 4th Edition</title><description>This fourth edition of the Common Sense Guide to Mitigating Insider Threats introduces the topic of insider threats, explains its intended audience and how this guide differs from previous editions, defines insider threats, outlines current patterns and trends, and describes 19 practices that organizations should implement across the enterprise to prevent and detect insider threats, as well as case studies of organizations that failed to do so.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tr012.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tr012.cfm</link><pubDate>Wed, 12 Dec 2012 17:28:38 +0000</pubDate></item><item><title>Analyzing Cases of Resilience Success and Failure—A Research Study</title><description>This report describes the SEI research study aimed at helping organizations to know the business value of implementing resilience processes and practices, and determine which ones to implement.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn025.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn025.cfm</link><pubDate>Tue, 11 Dec 2012 15:27:48 +0000</pubDate></item><item><title>The Business Case for Systems Engineering Study: Assessing Project Performance from Sparse Data</title><description>This report describes the data collection and analysis process used to support the assessment of project performance for the systems engineering (SE) effectiveness study.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12sr010.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12sr010.cfm</link><pubDate>Tue, 11 Dec 2012 15:11:15 +0000</pubDate></item><item><title>The Business Case for Systems Engineering Study: Results of the Systems Engineering Effectiveness Survey</title><description>This report summarizes the results of a survey that had the goal of quantifying the connection between the application of systems engineering (SE) best practices to projects and programs and the performance of those projects and programs.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12sr009.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12sr009.cfm</link><pubDate>Fri, 30 Nov 2012 13:30:17 +0000</pubDate></item><item><title>Reliability Improvement and Validation Framework</title><description>This report discusses the reliability validation and improvement framework developed by the SEI. The purpose of this framework is to provide a foundation for addressing the challenges of qualifying increasingly software-reliant, safety-critical systems. It aims to overcome the limitations of current reliability engineering approaches, leverage the best emerging engineering technologies and practices to complement the process focus of current practice, find acceptance in industry, and lead to a new set of reliability improvement metrics.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12sr013.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12sr013.cfm</link><pubDate>Tue, 27 Nov 2012 19:39:16 +0000</pubDate></item><item><title>DoD Information Assurance and Agile: Challenges and Recommendations Gathered Through Interviews with Agile Program Managers and DoD Accreditation Reviewers</title><description>This paper discusses the natural tension between rapid fielding and response to change (characterized as agility) and DoD information assurance policy.  Data for the paper was gathered through interviews with DoD project managers and IA representatives.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn024.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn024.cfm</link><pubDate>Fri, 16 Nov 2012 15:01:46 +0000</pubDate></item><item><title>TSP Symposium 2012 Proceedings</title><description>The 2012 TSP Symposium was organized by the Software Engineering Institute (SEI) and took place September 18–20 in St. Petersburg, FL. The goal of the TSP Symposium is to bring together practitioners and academics who share a common passion to change the world of software engineering for the better through disciplined practice. The conference theme was “Delivering Agility with Discipline.” This report contains the six papers selected by the TSP Symposium Technical Program Committee.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12sr015.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12sr015.cfm</link><pubDate>Thu, 08 Nov 2012 17:48:36 +0000</pubDate></item><item><title>Supporting the Use of CERT® Secure Coding Standards in DoD Acquisitions</title><description>This technical note provides guidance to help DoD acquisition programs address software security in acquisitions. It provides background on the development of secure coding standards, sample request for proposal (RFP) language, and a mapping of the Application Security and Development STIG to the CERT(R) C Secure Coding Standard.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn016.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn016.cfm</link><pubDate>Thu, 25 Oct 2012 19:53:06 +0000</pubDate></item><item><title>Resource Allocation in Dynamic Environments</title><description>When warfighting missions are conducted in a dynamic environment, the allocation of resources needed for mission operation can change from moment to moment. This report addresses two challenges of resource allocation in dynamic environments: overstatement of resource needs and unpredictable network availability.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tr011.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tr011.cfm</link><pubDate>Thu, 25 Oct 2012 15:28:33 +0000</pubDate></item><item><title>Well There’s Your Problem: Isolating the Crash-Inducing Bits in a Fuzzed File</title><description>This report describes an algorithm that efficiently reverts bits from the fuzzed file to those found in the original seed file, keeping only the minimal bits required to recreate the crash under investigation.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn018.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn018.cfm</link><pubDate>Fri, 19 Oct 2012 18:08:14 +0000</pubDate></item><item><title>The Role of Standards in Cloud-Computing Interoperability</title><description>This report explores the role of standards in cloud-computing interoperability. It covers cloud-computing basics and standard-related efforts, discusses several use cases, and provides recommendations for cloud-computing adoption.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn012.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn012.cfm</link><pubDate>Fri, 19 Oct 2012 18:07:13 +0000</pubDate></item><item><title>Cloud Computing at the Tactical Edge</title><description>This technical note presents a strategy to overcome the challenges of obtaining sufficient computation power to run applications needed for warfighting and disaster relief missions. It discusses the use of cloudlets--  localized, stateless servers running one or more virtual machines--on which soldiers can offload resource-intensive computations from their handheld mobile devices.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn015.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn015.cfm</link><pubDate>Fri, 05 Oct 2012 22:09:51 +0000</pubDate></item><item><title>Communication Among Incident Responders - A Study</title><description>This technical note describes three factors that can help or hinder the cooperation of incident responders.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn028.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn028.cfm</link><pubDate>Tue, 16 Oct 2012 17:12:23 +0000</pubDate></item><item><title>Toward a Theory of Assurance Case Confidence</title><description>Assurance cases provide an argument and evidence explaining why a claim about some system property holds. This report presents a framework for thinking about (and determining) confidence in assurance case arguments. The framework uses argumentation theory as developed in philosophy, jurisprudence, mathematics, and artificial intelligence to provide a justified basis for asserting some level of confidence in the truth of assurance case claims.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tr002.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tr002.cfm</link><pubDate>Wed, 26 Sep 2012 14:50:52 +0000</pubDate></item><item><title>SEPG Europe 2012 Conference Proceedings</title><description>This report compiles seven papers based on presentations given at SEPG Europe 2012.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12sr005.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12sr005.cfm</link><pubDate>Fri, 21 Sep 2012 21:10:21 +0000</pubDate></item><item><title>Competency Lifecycle Roadmap: Toward Performance Readiness</title><description>This technical note describes the Competency Lifecycle Roadmap (CLR), a preliminary roadmap for understanding and building workforce readiness.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn020.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn020.cfm</link><pubDate>Tue, 11 Sep 2012 16:58:20 +0000</pubDate></item><item><title>Probability-Based Parameter Selection for Black-Box Fuzz Testing</title><description>This report describes an algorithm to automate selection of seed files and other parameters used in black-box fuzz testing.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn019.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn019.cfm</link><pubDate>Thu, 30 Aug 2012 13:29:48 +0000</pubDate></item><item><title>Network Profiling Using Flow</title><description>This report provides a step-by-step guide for profiling—discovering public-facing assets on a network—using network flow (netflow) data.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tr006.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tr006.cfm</link><pubDate>Thu, 23 Aug 2012 19:58:06 +0000</pubDate></item><item><title>Results of SEI Line-Funded Exploratory New Starts Projects</title><description>This report describes the line-funded exploratory new starts (LENS) projects that were undertaken during fiscal year 2011. For each project, the report presents a brief description and a recounting of the research that was done, as well as a synopsis of the results of the project.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tr004.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tr004.cfm</link><pubDate>Thu, 23 Aug 2012 19:43:50 +0000</pubDate></item><item><title>Insider Threat Study: Illicit Cyber Activity Involving Fraud in the U.S. Financial Services Sector</title><description>This report describes a new insider threat study in which researchers extracted technical and behavioral patterns from fraud cases and developed insights and risk indicators of malicious insider activity within the banking and finance sector.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12sr004.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12sr004.cfm</link><pubDate>Thu, 26 Jul 2012 15:33:14 +0000</pubDate></item><item><title>The Evolution of a Science Project: A Preliminary System Dynamics Model of a Recurring Software-Reliant Acquisition Behavior</title><description>This report uses a preliminary system dynamics model to analyze a specific adverse acquisition dynamic concerning the poorly controlled evolution of small prototype efforts into full-scale systems.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tr001.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tr001.cfm</link><pubDate>Thu, 12 Jul 2012 11:37:20 +0000</pubDate></item><item><title>A Virtual Upgrade Validation Method for Software-Reliant Systems</title><description>Presents the Virtual Upgrade Validation (VUV) method, an approach that uses architecture-centric, model-based analysis to identify system-level problems early in the upgrade process to complement established test qualification techniques.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tr005.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tr005.cfm</link><pubDate>Thu, 14 Jun 2012 16:33:25 +0000</pubDate></item><item><title>Report from the First CERT-RMM Users Group Workshop Series</title><description>This report describes the first CERT RMM Users Group (RUG) Workshop Series and relays the experiences of participating members and CERT staff.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn008.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn008.cfm</link><pubDate>Wed, 30 May 2012 13:08:24 +0000</pubDate></item><item><title>A Pattern for Increased Monitoring for Intellectual Property Theft by Departing Insiders</title><description>This report presents an example of an enterprise architectural pattern, Increased Monitoring for Intellectual Property (IP) Theft by Departing Insiders, to help organizations plan, prepare, and implement a means to mitigate the risk of insider theft of IP.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tr008.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tr008.cfm</link><pubDate>Thu, 03 May 2012 14:35:45 +0000</pubDate></item><item><title>Source Code Analysis Laboratory (SCALe)</title><description>This report details the CERT Program's Source Code Analysis Laboratory (SCALe), a proof-of-concept demonstration that software systems can be conformance tested against secure coding standards, and provides an analysis of selected software systems.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn013.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn013.cfm</link><pubDate>Tue, 01 May 2012 20:19:48 +0000</pubDate></item><item><title>Insider Threat Security Reference Architecture</title><description>This technical report describes the Insider Threat Security Reference Architecture (ITSRA), an enterprise-wide solution to the threat to organizations from its own insiders. The ITSRA draws from existing best practices and standards as well as from analysis of real insider threat cases to provide actionable guidance for organizations to improve their posture against the insider threat.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tr007.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tr007.cfm</link><pubDate>Tue, 01 May 2012 14:21:10 +0000</pubDate></item><item><title>CERT® Resilience Management Model (CERT®-RMM) V1.1: NIST Special Publication Crosswalk Version 1</title><description>This technical note maps CERT® Resilience Management Model (CERT®-RMM) process areas to certain National Institute of Standards and Technology (NIST) special publications in the 800 series.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tn028.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tn028.cfm</link><pubDate>Tue, 27 Mar 2012 12:25:58 +0000</pubDate></item><item><title>What’s New in V2 of the Architecture Analysis &amp;amp; Design Language Standard?</title><description>This report provides an overview of changes and improvements to the Architecture Analysis &amp;amp; Design Language (AADL) standard for describing both the software architecture and the execution platform architectures of performance-critical, embedded, real-time systems.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11sr011.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11sr011.cfm</link><pubDate>Thu, 22 Mar 2012 19:42:02 +0000</pubDate></item></channel></rss>