Tim Newsham is a
computer security professional. He has been contributing to the security community for more than a decade. He has performed research while working at security companies including
@stake, Guardent, ISS, and
Network Associates (originally Secure Networks).
Contributions
Newsham is best known for co-authoring the paper ''Insertion, Evasion and Denial of Service: Eluding Network Intrusion Detection'' with Thomas Ptacek, a paper that has been cited by more than 150 academic works on Network Intrusion Detection since.
He has published other prominent white papers:
* ''The Problem With Random Increments''
* ''Format String Attacks''
* ''Cracking WEP Keys: Applying Known Techniques to WEP Keys''
In addition to his research, Newsham is also known for his pioneering work on security products, including:
* Internet Security Scanner
* Ballista (Cybercop) Scanner
* The software that would later drive
Veracode
WEP Security
Newsham partially discovered the Newsham 21-bit WEP attack. The Newsham 21-bit attack is a method used primarily by
KisMAC to brute force WEP keys. It is effective on routers such as
Linksys,
Netgear,
Belkin, and
D-Link but does not affect
Apple or
3Com
3Com Corporation was an American digital electronics manufacturer best known for its computer network products. The company was co-founded in 1979 by Robert Metcalfe, Howard Charney and others. Bill Krause joined as President in 1981. Metcalfe ex ...
, as they use their own
algorithms for generating
WEP keys. Using this method allows for the WEP key to be retrieved in less than a minute. When the WEP keys are generated, they use a text based key that is generated using a 21-bit algorithm instead of the more secure 40-bit encryption algorithm, but the router presents the key to the user as a 40-bit key. This method is 2^19 times faster to brute force than a 40-bit key would be, allowing modern processors to break the encryption rapidly.
In 2008, Newsham was awarded a Lifetime Achievement
Pwnie award
The Pwnie Awards recognize both excellence and incompetence in the field of information security. Winners are selected by a committee of security industry professionals from nominations collected from the information security community. Nomine ...
.
References
{{DEFAULTSORT:Newsham, Tim
Year of birth missing (living people)
Living people
Computer security specialists