Risk
5/10/2013
10:55 AM
50%
50%

British Universities Given Funds For Cyber Security Program

U.K. government provides grants to University of Oxford and Royal Holloway, University of London to fund doctoral programs in cyber security.

The U.K. government plans to offer a grant of £7.5 million ($11.5 million) to two British universities in order to train a new cohort of cyber security Ph.Ds.

The Royal Holloway college of the University of London and the University of Oxford -- which both already enjoy international reputations as centers of security research -- have been asked to recruit extra postgraduates to develop new ways of resisting cyber attacks.

Both institutions plan to set up new centers for doctoral training, or CDTs, in cyber security problems. At Oxford, the CDT will focus on big data-related security problems, exploring the best way to link physical and information security. Meanwhile, the Royal Holloway center will research cryptographic systems and protocols, telecommunication networks and critical infrastructure, and organizational processes and socio-technical systems.

[ Are apprenticeships the solution to addressing the IT talent gap? Read U.K. Eyes Apprenticeships To Grow IT Talent. ]

At Holloway, 10 Ph.D. scholarships over three annual intakes for a four-year program will be funded. Students will attend a year of courses in advance of a three-year research program and will be placed during their study at firms including BM, McAfee and Thales. The initiative is expected to supply 66 highly trained doctorate-level experts by 2020.

"We are looking forward to taking on the great responsibility of delivering graduates who will directly benefit the country," said Royal Holloway information security group director and professor Keith Martin.

The investment is another step in the U.K.'s attempts to improve its cyber security efforts. The new research places are in addition to 30 previously announced doctorates being underwritten by GCHQ, the country's official center for monitoring signals, which are part of the government's £650 million ($1 billion) National Cyber Security Program. For the Oxford and Royal Holloway investments, cash is coming in the form of a £5 million ($7.7 million) donation from the government Ministry for Business, Innovation and Skills, along with £2.5 million ($3.8 million) from the Engineering and Physical Sciences Research Council.

"These new centers will produce a new generation of cyber security specialists, able to use their skills and research expertise to improve cyber security and drive growth," said Minister for Universities and Science David Willetts.

The news was generally welcomed by the British IT security industry, although with some caveats. John Yeo, EMEA director at Trustwave, which supplies on-demand and subscription-based information security and PCI DSS compliance management solutions, noted, "It would be prudent to ensure that for within this type of very focused and specialized academic course, a sufficient level of practical, hands-on and industry experience is built in -- primarily to ensure students maximize their employability and value to hiring organizations upon completing their course."

Antivirus systems alone can't fight a growing category of malware whose strength lies in the fact that we have never seen it before. The How To Detect Zero-Day Malware And Limit Its Impact report examines the ways in which zero-day malware is being developed and spread, and the strategies and products enterprises can leverage to battle it. (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2010-5075
Published: 2014-12-27
Integer overflow in aswFW.sys 5.0.594.0 in Avast! Internet Security 5.0 Korean Trial allows local users to cause a denial of service (memory corruption and panic) via a crafted IOCTL_ASWFW_COMM_PIDINFO_RESULTS DeviceIoControl request to \\.\aswFW.

CVE-2011-4720
Published: 2014-12-27
Hillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2) WRQ operation.

CVE-2011-4722
Published: 2014-12-27
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation.

CVE-2012-1203
Published: 2014-12-27
Cross-site request forgery (CSRF) vulnerability in starnet/index.php in SyndeoCMS 3.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts via a save_user action.

CVE-2012-1302
Published: 2014-12-27
Multiple cross-site scripting (XSS) vulnerabilities in amMap 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data_file or (2) settings_file parameter to ammap.swf, or (3) the data_file parameter to amtimeline.swf.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.