digplanet beta 1: Athena
Share digplanet:

Agriculture

Applied sciences

Arts

Belief

Business

Chronology

Culture

Education

Environment

Geography

Health

History

Humanities

Language

Law

Life

Mathematics

Nature

People

Politics

Science

Society

Technology

Eugene Spafford talks about computer security at LinuxForum 2000 in Copenhagen, Denmark.

Eugene Howard Spafford (born 1956), commonly known as Spaf,[1] is a professor of computer science at Purdue University and a leading computer security expert.

A historically significant Internet figure, he is renowned for first analyzing the Morris Worm, one of the earliest computer worms, and his prominent role in the Usenet backbone cabal. Spafford was a member of the President's Information Technology Advisory Committee 2003-2005,[2] has been an advisor to the National Science Foundation (NSF), and serves as an advisor to over a dozen other government agencies and major corporations.

Contents

Biography [edit]

Education and early career [edit]

Spafford attended State University of New York at Brockport completing a double B.A. in both Mathematics and Computer Science in 3 years. He then attended the School of Information and Computer Sciences (now the College of Computing) at the Georgia Institute of Technology. He received his M.S. in 1981, and Ph.D. in 1986 for his design and implementation of the original Clouds distributed operating system kernel.

During the early formative years of the Internet, Spafford made significant contributions to establishing semi-formal processes to organize and manage Usenet, then the primary channel of communication between users, as well as being influential in defining the standards of behavior governing its use.

Recent work [edit]

At Purdue, Spafford has a joint appointment as a professor of computer science and as professor of electrical and computer engineering, where he has served on the faculty since 1987. He is also a professor of philosophy (courtesy), and a professor of communication (courtesy). He is also Executive Director of the Purdue CERIAS (Center for Education and Research in Information Assurance and Security) and was the founder and director of COAST Laboratory, which preceded CERIAS.

He is involved in a number of professional societies and activities outside Purdue including serving on the Board of Directors of the Computing Research Association and as co-chair of the ACM's US Public Policy Committee. He serves on a number of advisory and editorial boards and is internationally known for his writing, research, and speaking on issues of security and ethics. Spafford has authored or co-authored four books on computer and computer security, including Practical Unix and Internet Security for O'Reilly, as well as over a hundred research papers, chapters and monographs.

Spafford has stated that his research interests have focused on "the prevention, detection, and remediation of information system failures and misuse, with an emphasis on applied information security. This has included research in fault tolerance, software testing and debugging, intrusion detection, software forensics, and security policies."

Among notable software designed and/or supervised by Spafford include the freeware Tripwire tool coded by his student Gene Kim (Spafford was later the chief external technical advisor to the Tripwire company during their first few years), and the freeware COPS tool coded by his student Dan Farmer. He initiated the Phage List as a response to the Morris Worm. Some of his research also helped inspire the creation of the MITRE CVE service and the NIST ICAT database. Research by other graduate students of his has resulted in tools for software testing and debugging, distributed processing, cyber forensics, firewalls, intrusion detection, auditing, and network traceback.

Spafford discusses a recent piece in the New York Times that looked at how the current Internet is a conduit for all types of "cybercrime" on C-SPAN.[3][4]

Teaching [edit]

Courses taught at Purdue [edit]

Spaf teaches (or has taught) many different courses in the CS department. These are listed below:

  • CS 626, Advanced Topics in Security

This is the Advanced Information Assurance class. The course is about the "big picture" of information security.

  • CS 426, Computer Security

First offered Spring 1999. This is the undergraduate course in computer security, with some network security added in.

  • CS 526, Introduction to Information Security

First offered as 590-I in Fall 1998. Taught as CS 526 in spring 2000.

  • CS 590 T, Penetration Analysis

Offered Spring 1997 and Spring 1998.

  • CS 555, Cryptography and Data Security

Regularly offered by various faculty. Spaf taught it in Spring 1996 and Spring 1997.

  • CS 690 E, Computer Incident Detection and Response

Offered Spring 1995. I hope to teach it again in 2004 or 2005.

  • CS 590 S, Ethics, Liability, Responsibility & the Computer Professional

A special seminar was offered in Fall 1988, Spring 1990, and Spring 1991.

PhD Students [edit]

  • Hiralal Agrawal

Hira received his PhD in 1991. He is now working at Telcordia. His dissertation, Towards Automatic Debugging of Computer Programs, was done as part of the Spyder project in the SERC. Hira's co-advisor was Richard DeMillo.

  • Florian Buchholz

Received his PhD in August 2005 and is now on the faculty of James Madison University. His dissertation was on embedding forensic support in a general-purpose OS file system, and was entitled Pervasive Binding of Labels to System Processes.

  • Brian Carrier

Brian received his PhD in spring 2006 for his dissertation on a formal framework for digital forensic investigations. He is now a member of the research staff at Basis Technology.

  • Steve Chapin

Steve received his PhD in 1993.He did his dissertation, entitled Scheduling Support for an Internetwork of Heterogeneous, Autonomous Processors, as the core of the Messiahs Project. Steve is now an Associate Professor at Syracuse University. He is the first of my former students to produce Ph.D. graduates of his own.

  • Thomas Daniels

Tom received his Ph.D. in December 2002 after completing his dissertation, Reference Models for the Concealment and Observation of Origin Identity in Store and Forward Networks. He is on the faculty of Iowa State University.

  • Kevin Du

Kevin received his PhD in 2001. He is now on the faculty at Syracuse University. His thesis was entitled A Study Of Several Specific Secure Two-Party Computation Problems. His co-advisor was Mike Atallah.

Gene completed his BS degree in 1993 and his MSCS at the University of Arizona. He worked with spaf on the Tripwire project through COAST, released on November 2, 1992. Gene is now CTO of Tripwire, Inc. Since 1999, Gene has been capturing and codifying how "best in class" organizations have IT operations, security, audit, management, and governance working together to solve common business objectives. This was codified in 2004, he co-wrote the Visible Ops Handbook, showing how IT organizations successfully transformed from good to great. Gene was named as a 2007 Outstanding Alumnus by Purdue CS.

  • Ivan Krsul

Ivan completed his PhD on the topic of Software Vulnerability Analysis in 1998. He constructed a large-scale database of system vulnerabilities, and then used this to explore their characteristics. His research was part of the COAST Project. He is now working at a start-up company, Arte Xacta, in his native Bolivia. Ivan also did his MS thesis under spaf direction, entitled Authorship Analysis: Identifying the Author of a Program. Ivan is the only repeat winner of the Maurice Halsted Software Engineering Award, given at Purdue each year.

  • Sandeep Kumar

Sandeep received his Ph.D. in August, 1995. His dissertation, Classification and Detection of Computer Intrusions developed a new approach to intrusion detection. His research was part of the COAST Project. He is currently working for RSA Security in Bangalore, India.

  • Benjamin Kuperman

Ben graduated in August 2004 and then joined the faculty of Swarthmore College as a visiting assistant professor. Starting in the fall of 2006 he will be on the CS faculty of Oberlin College. His dissertation was entitled A Categorization of Computer Security Monitoring Systems and the Impact on the Design of Audit Sources.

  • Pascal Meunier

Pascal came to Purdue with a Ph.D. in biological sciences. He completed his M.S. under my direction, and is now working as a research scientist with CERIAS.

Selected honors and awards [edit]

See also [edit]

References [edit]

  1. ^ Gene Spafford's home page at Purdue
  2. ^ "President's Information Technology Advisory Committee - Archive". Retrieved 2011-10-03. 
  3. ^ "The Internet and Cyber-Security". Purdue University: C-SPAN. 2009-02-21. 
  4. ^ John Markoff (2009-02-14). "Do We Need a New Internet?". NY Times. 
  5. ^ Gene Spafford (2011-09-25). "Abridged Vita: Eugene H. Spafford". Retrieved 2011-10-03. 

External links [edit]


Original courtesy of Wikipedia: http://en.wikipedia.org/wiki/Gene_Spafford — Please support Wikipedia.
A portion of the proceeds from advertising on Digplanet goes to supporting Wikipedia.
587 videos foundNext > 

Gene Spafford: Insanity Rules: The Growing Cyber Security Crisis

Another lecture in IHMC's award winning lecture series. http://www.ihmc.us Computer crime has been a growing concern for well over two decades. Computer viru...

Episode 318 - Interview with Dr. Gene Spafford

Episode 318 - Interview with Dr. Gene Spafford from PaulDotCom Security Weekly TV. Like this? Watch the latest episode of PaulDotCom Security Weekly TV on Bl...

Eugene Spafford GWU Presentation

2010-01-13 CERIAS - Thinking Outside the Box

Recorded: 01/13/2010 CERIAS Security Seminar at Purdue University Thinking Outside the Box Eugene Spafford, Purdue University (Visit: www.cerias.purude.edu)

Why Fixing Cybersecurity Is So Difficult

SEAS recently hosted Purdue University's Professor Eugene Spafford for the 2012 Frank Howard Distinguished Lecture. Professor Spafford has served as a senior...

Security and Liberty Forum Panel Discussion

Featuring Katherine Bryant, Barry Steinhardt, Melissa Ngo, Gene Spafford, Annie Anton, and Bruce Schneier. The purpose of this event was to bring in experts ...

Zardoz (computer security) - Computer Security

http://www.resumesanta.com... Zardoz (computer security) - Computer Security. In computer security, the Zardoz list , more formally known as the Security-Dig...

CS & IT Symposium 2010: Opening Keynote - From Soup to Nuts

Computer Science Teachers Association Computer Science & Information Technology Symposium 2010 July 13, 2010 Opening Keynote: Soup to Nuts Presented by Gene ...

Infosecurity Magazine Analyst Update Panel at Infosecurity Europe 2013

Editor of Infosecurity Magazine, Eleanor Dallaway, quizzes three of the information security industry's top UK analysts on the current trends in the industry...

Information security - Computer Security - Part 13

http://www.resumesanta.com... Information security - Computer Security - Part 13. Sources of standards International Organization for Standardization ISO is ...

587 videos foundNext > 

2 news items

 
Purdue Exponent
Fri, 24 May 2013 07:01:12 -0700

Cybersecurity expert adds CNN contributor to his resume. Story · Comments. Print: Create a hardcopy of this page; Font Size: Default font size: Larger font size. Previous Next. 5/23/13 Gene Spafford. Matthew Thomas | Editor-in-chief ...

Revista Cloud Computing

Revista Cloud Computing
Tue, 21 May 2013 15:09:50 -0700

Corría el año 1989 cuando el profesor y reputado experto en seguridad informática Gene Spafford realizó esta llamativa reflexión. Se trata de una exageración, con la que probablemente pretendía lanzar un toque de atención a la sociedad en general sobre ...
Loading

Oops, we seem to be having trouble contacting Twitter

Talk About Gene Spafford

You can talk about Gene Spafford with people all over the world in our discussions.

Support Wikipedia

A portion of the proceeds from advertising on Digplanet goes to supporting Wikipedia. Please add your support for Wikipedia!